
Navy Qualified Validator (Information Security Analyst)
- Portsmouth
- Permanent
- Full-time
- Review A&A package submissions to ensure system/network architectures and technical/non- technical operating features adequately protect and defend against unauthorized access, ensure systems availability, and meet Cyber Security (CS) implementation policy requirements and data protection safeguards.
- Conduct CS compliance and A&A documentation validation assessments for legacy applications, systems and networks.
- Develop, or expand existing A&A and CS documentation to ensure complete documentation exists in accordance with DoD A&A and IA/CS policy.
- Perform Cyber Compliance (CC) risk assessments to evaluate system risks and provide written risk assessment reports including overall risk analysis reviews and recommendations to the Authorizing Official (AO) and Functional Authorizing Official (FAO).
- Respond to feedback from the AO and FAO in the form of comments and instructions to ensure coordination of efforts and to correct errors, information omissions and shortfalls in A&A documentation packages.
- Communicate feedback to customers, coordinate corrections collect responses and validate prior to forward for processing.
- Develop procedures to support A&A workflow processes, criteria needed to facilitate authorization processes and AO/FAO authorization decision milestones.
- Streamline A&A package efforts based on RMF status and complexity, unless operational requirements necessitate a waiver.
- Attend meetings on behalf of the A&A team, take notes and prepare written feedback on the content and outcome of meetings, and follow-on tasks including recommendation and suggestions.
- Support implementation of CS/IA policy requirements (i.e. Business Rules, Standard Operating Procedures (SOP). Assist users with CS related issues and provide other CS support as the need arises (e.g., auditing, contingency planning, CS awareness training, risk assessments, etc.).
- Review quarterly STIG to ensure proper configuration and settings are still met and up to date (both systems and policies).
- Develop and maintain metrics / dashboards to provide visibility and context needed by internal and external stakeholders.
- Minimum of 7 years of experience in in CS/A&A analysis support in IA controls analysis, conducting risk assessments, risk mitigation analysis, or developing plans
- BS Degree in IT or related discipline
- Active DoD Top Secret Clearance
- Personnel qualified and registered as a Navy Qualified Validator (NQV)
- Experience in certifying and accrediting DON information systems and networks, as well as Platform IT.
- Expert knowledge of and experience with CS/RMF requirements as defined by Public Laws, National, DoD, and DON guidance [e.g., Federal Information Security Management Act (FISMA), DoDD 8100.02, DODI 8500.01, DoDI 8520, DoDI 8530, DoDI 8531, SECNAV 5239 Series and OPNAV 5239 Series, NIST Special Publications Series 800, etc.]
- Fully qualified in accordance with DoD 8570.01M.
- Security + or higher certification