Cybersecurity, A&A Specialist

  • Full-time

Company Description

A3T, a fast growing firm, specializes in Defensive Cyber Security Services, Enterprise Information Technology (IT) Solutions, and Professional Services driven by our customer requirements. Our customers, company mission, and personnel are the focal points of all decisions and actions.  Join A3T and watch your career soar! A3T is a small, agile, company looking for incredible talent to support the United States Government in many important national security roles.

Join A3T and watch your career soar! A3T is a small, agile, company looking for incredible talent to support the United States Government in many important national security roles. A3T is looking to bring on an experienced Secret cleared Cybersecurity, A&A Specialist with “Next-Level Thinking” who is ready to take their career to a new level with A3T and support our customer at the Joint Service Provider, Pentagon.


Job Description

The successful dandidate will support the JSP Cyber Center Assessment and Authorization division to support new and existing customer connections to Common Information Technology (CIT) managed unclassified and classified backbone/transport networks, including the Pentagon Unclassified Installation Campus Area Network (PENT-U-ICAN), Pentagon Secret Backbone (PSB), Pentagon Top Secret Backbone (PTSB), Coral Transport Network (CTN), Mark Center Unclassified Backbone (MC-U), and Mark Center Classified Backbone (MC-S). Upon completion and approval of the assess only/CAP package by the AO, a final authorization memorandum will be maintained and distributed to customers. The successful Candidate shall be a Team Lead responsible for: 

Duties and Responsibilities:

  • Leverage Risk Management Framework (RMF) process, review and determine if system/application documentation is accurate, up to date, and displays thorough details that provide a clear security
    posture of the system/application being assessed.
  • Maintain a repository of all documentation collected for all Assess Only packages to include
    decommissioned systems/applications. 
  • Communicate proactively with the customer throughout the assessment and authorization of the Assess Only/ CAP process/procedures
  • Follow the escalation process until authorization, disconnection, or decommission is achieved. 
  • Assemble all documentation established by organization guidelines and supporting materials for review to the Government for approval. 
  • Consider recommendations and or directions communicated during the approval process to correct deficiencies in documentation or to eliminate vulnerabilities.
  • Provide recommendations on how to efficiently develop methods, procedures, technical requirements regarding assess only or CAP procedures. 
  • Provide a completed Assess Only/ CAP package for all system/applications approaching re-authorization
  • Provide Reports on all Assess Only and CAP packages approaching 90/ 60/ 30 days and expired to include status, way-forward, and escalations.
  • Provide notification to the system owners to complete all system application documentation 
  • Request access to the eMASS for the system under review following onsite procedures
  • Coordinate and track to ensure JSP customers complete and return the following documentation prior to expiration of the Authority To Connect (ATC)
    • Registration in eMASS Module
    • RMF Security Authorization Package (Security Plan)
    • Security Assessment Report [SAR]
    • Complete and Accurate POA&M
    • Signed Authorizing Official (AO)
      Authorization Decision or Authorization to Operate (ATO)
    • Authorization to Connect Contact List
    • Request for Authority to Connect
    • Vulnerability Management Branch checklist
    • Hardware/software lists, Network Diagrams, and Privacy Impact Assessment (PIA)
    • Review the completed CAP package and determine if the system application documentation is accurate and detailed, and provides an accurate depiction of security posture
    • coordinate and collaborate with stakeholders to ensure completion and return a POA&M addressing the vulnerabilities and non-compliant STIG configurations
    • Review submitted POA&Ms to help the system owners eliminate vulnerabilities, using the following escalation process for authorization, disconnection, or decommission
    • Deliver CAP reports, and update Connection Approval Packages SOP
    • Generate a weekly CAP Report to provide the status of all Assess Only and CAP Packages approaching 90/60/30 days to expiration that includes a way forward and escalations IAW the escalation procedures
    • Maintain required SOP activities and artifacts include, but are not limited to the CAP process and development of authorization memos.

Qualifications

Requirements:

  • Security Clearance: Secret (Top Secret preferred)
  • 5+ years of experience in certification and accreditation in RMF or DIACAP
  • The position requires8570.01-M IAM DoD Level 2 certification (CAP, GSLC, CISM, CISSP [which includes CASP])
  • Proficient with RMF process, NIST SP 800-37, NIST SP 800-53, CNSSI 1253
  • Demonstrate leadership skills
  • Has customer service experience/skills
  • Bachelors degree

Qualifications:

  • Expert ability to communicate in both oral and written forms, demonstrating an ability to communicate effectively with all levels of staff as well as clients
  • Demonstrate experience in implementing Army, DOD, or IC specific IT policies, processes and procedures with reference to their area of expertise
  • Demonstrate knowledge of DOD Information Assurance Certification Accreditation Process, DODd 8500.1 and DODI 8500.2
  • Knowledge of Plan of Actions and Milestones, Executive Vulnerability Summary Reports
  • Demonstrate experience in a DOD or IT environment
  • Demonstrate experience with researching and connection issues
  • Experience with eMass.
  • Demonstrate experience interacting with and briefing senior government leaders

Additional Information

Agil3Tech (A3T) offers a competitive benefits package to include: paid holidays, paid time off, medical, dental, vision, company paid long and short term disability and life insurance, referral bonuses, certification reimbursement program, etc.

It is the policy of A3T to provide equal opportunity in recruiting, hiring, training, and promoting individuals in all job categories without regard to race, color, religion, national origin, gender, age, disability, genetic information, veteran status, sexual orientation, gender identity, or any other protected class or category as may be defined by federal, state, or local laws or regulations.

We maintain a drug-free workplace and perform pre-employment substance abuse testing to include background checks.