Senior Project MGR / Information Assurance Engineer, (SME)

  • Full-time

Company Description

A3T, a fast growing firm, specializes in Defensive Cyber Security Services, Enterprise Information Technology (IT) Solutions, and Professional Services driven by our customer's mission, and providing superb 'A' level talented personnel.

Join A3T and watch your career soar! A3T is an agile and mature company looking for incredible talent to support our U.S. Federal customers in many important national security roles.  A3T is looking to bring on an experienced cyberseucirty professional as a Senior Project MGR / Information Assurance Engineer providing Subject Matter Expertise with “Next-Level Thinking” who is ready to take their career to a new level with A3T.

This position is eligible for a Sign-On Bonus!

Job Description

The successful Sr. PM/IA Engineer will provide senior technical analysis for Information Assurance / Cybersecurity (IA/CS) support and integration efforts.  Performs in-depth analysis in various areas and technologies within DIACAP C&A and RMF A&A documentation. Determines enterprise information assurance and security standards. Performs in-depth analysis in various areas and technologies IAW NIST Federal Information Processing Standards and Special Publications, OMB guidance and Policies, and Federal Information Security Management Act (FISMA).  Oversees all aspects of cyber security projects including: developing requirements, setting deadlines, assigning responsibilities, monitoring and summarizing progress, preparing reports and monitoring all aspects of project constraints: time- scope-cost.  Provide subject matter technical knowledge and analysis of policies to support functional technical areas of a project. Apply principles, methods and knowledge of the functional area to specific task requirements to develop solutions to complex problems. Supports cyber security project teams in the delivery of program and task order requirements. Create and deliver cyber security reports, documents and briefings and advises on industry best practices. Conducts research to resolve complex issues or problems.  Conducts cybersecurity data calls, monitors requirements of data requests, analyzes data, and articulates results in both detailed and high-level formats for a diverse group of internal and external stakeholders, in response to Federally mandated, Senior leadership, and mission-required drivers for continued cyber defense strategies.  Conducts research necessary to develop and/or revise cybersecurity training courses; prepares appropriate training materials, and/or conducts formal classroom courses and workshops.

Duties/Responsibilities:

  • Responsible for overall planning, management, coordination and completion of cyber security projects and activities.

  • Supervises contractor personnel and Assigns contractor duties and schedules

  • Communicates policies, purposes, and goals of the NCI to subordinates.

  • Analyzes new project-related problems that may involve technology, methodology, tools or applications.

  • Analyzes and/or establishes processes and technologies to ensure comprehensive protection exists on computer systems to prevent unauthorized entry to computer systems or compromise of data integrity or secrecy.

  • Performs Security development for computer systems which includes designing, prototyping, implementing, conducting independent verification and validation, and maintaining security for enterprise systems.

  • Performs support activities for security assessment and accreditation activities on IT systems and applications, including review or preparation of required documents (FIPS 199, Risk Acceptance Memos, etc.) security audits (i.e., FISMA), risk assessments, security plans, and system test and evaluations.

  • Develops or reviews security policies, standards and procedures.

  • Provides up-to-date working knowledge in areas such as computer viruses, intrusion detection systems, encryption systems, firewalls, access and authentication technologies, etc.

  • Responsible for vulnerability analysis, and contingency/disaster recovery planning and testing.

  • Provides training to project managers and system owners in FISMA compliance.

  • Develop procedures and standards for effective implementation of the NCI Information Security Plan;

  • Assist in incorporating security policies and control processes in the CBIIT IT environment;

  • Determine security models in terms of confidentiality, integrity and availability;

  • Assist in the incorporation of security policies and control processes into the software development life cycle (SDLC);

  • Assist in the design, development, documentation and implementation of security guidance, standards, and procedures to implement and validate the security policy;

  • Assist the security program in defining new security related technologies and processes to advance the existing trust framework. (e.g., defining security as services, defining access control policies and models, etc.);

  • Assist in the tracking of Plan of Actions and Milestone (PO&AM) items;

  • Provide process development and documentation for contingency planning, disaster recovery, and business continuity planning;

  • Provide documentation for configuration management program;

  • Provide documentation for vulnerability management program;

  • Assist in the implementation of security policies as directed by the ISSO;

  • Prepare or assist in the preparation of security-related documents such as policy waivers and Risk Acceptance Memos.

  • Conduct Security Outreach and Awareness

  • Develops, plans, coordinates, and evaluates cyber training/education courses, methods, and techniques based on instructional needs.

  • Works with Federal PM to develop cyberspace workforce plans, strategies, and guidance to support cyberspace workforce manpower, personnel, training and education requirements and to address changes to cyberspace policy, doctrine, materiel, force structure, and education and training requirements.

  • Enhance the Web Security Presence (e.g., development of web content to promote security awareness and training materials as well as general security relate information);

  • Develop communications from Program Office/CIO/ISSO; and

  • Develop security awareness material and outreach sessions for both internal users and the extramural community

Qualifications

Clearance:  Public Trust (MBI or LBI); Secret (preferred)

Professional Certifications:  

  • Bachelor's Degree in Computer Science, Information Systems, Electrical Engineering, or other related scientific or technical discipline.

  • Possesses an active Project Management Professional (PMP) certification from the Project Management Institute (PMI)
  • Information Assurance Management (IAM) level III.  Certified Information Systems Security Professional (CISSP) or other Equivalent (CISM or GLSC) DoD 8570.01-M

  • Certified Ethical Hacker (CEH)

Experience:

  • Ten (10) years’ experience managing projects including eight (8) years managing IT security-related projects with similar scope and complexity.

  • Twelve (12) years of progressive technical experience in the area of Information Systems, with at least ten years (10) of specialized experience in the area of Federal Information Systems Security.

  • Experience creating, updating and maintaining project plans, WBS, communications plans, risk management plans, quality control plans and other project-related documentation.

  • Must have strong critical thinking/analytical skills, creativity, a proven drive for quality, and excellent oral and written communication skills.

  • Must have strong technical writing skills.

Additional Information

We offer a competitive benefits package to include: paid holidays, paid time off, medical, dental, vision, company paid long and short term disability and life insurance, referral bonuses, certification reimbursement program, etc.

It is the policy of A3T to provide equal opportunity in recruiting, hiring, training, and promoting individuals in all job categories without regard to race, color, religion, national origin, gender, age, disability, genetic information, veteran status, sexual orientation, gender identity, or any other protected class or category as may be defined by federal, state, or local laws or regulations.

We maintain a drug-free workplace and perform pre-employment substance abuse testing to include background checks  and eVerify validation.