Afloat Cyber Security Analyst

Socket.dev

Norfolk (VA)

On-site

USD 100,000 - 110,000

Full time

13 days ago
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Job summary

Falconwood is seeking a Cyber Security Analyst to support the USFF N6 Directorate Fleet Enterprise Support Team in RMF Assessment & Authorization for Ashore and Afloat, applying DoD and Navy policy expertise to ensure system security and proper documentation.

You will coordinate remediation, assist in developing procedures, produce meeting minutes, support STIG reviews, vulnerability management, and inspections across naval networks, with occasional CONUS travel.

Qualifications

  • Active SECRET clearance required.
  • Minimum 3 years of DoW/DoN cybersecurity, RMF, or information assurance experience.
  • Minimum 2 years working with US Navy shipboard systems and applications.
  • Experience using Navy RMF tools (DADMS/DITPR-DON, VRAM, eMASS).
  • Knowledge of NIST RMF Special Publications.
  • Ability to assess DoD RMF documentation and artifacts.
  • Ability to perform QA on A&A packages.

Responsibilities

  • Review A&A package submissions to ensure system/network security and policy compliance.
  • Conduct CS compliance and A&A documentation validation assessments.
  • Coordinate corrections and communicate feedback within five business days.
  • Assist in developing SOPs, checklists, and other A&A/CS documentation.
  • Track and report compliance during CSI/CCRI/CCORI inspections and post-inspection actions.
  • Provide meeting representation and minutes for discussions and follow-ups.
  • Travel CONUS 5–10% as needed.

Skills

Active SECRET Clearance
RMF/DoD Cybersecurity
A&A Documentation
Navy RMF Tools (DADMS/DITPR-DON, VRAM,
eMASS
Analytical & Reporting
Communication Skills

Education

BS in Computer Science/Cyber Security

Tools

DADMS/DITPR-DON
VRAM
eMASS

Job description

Overview

Falconwood is a small woman-owned company providing consultation and programmatic support to Department of Defense Information Technology (IT) initiatives and programs. We provide expert advice and consultation on a diverse range of IT subjects, focusing on acquisition, policy, cybersecurity, engineering, and process development. The Cyber Security Analyst will support the USFF N6 Directorate Fleet Enterprise Support Team, Package Submitting Office (PSO) in the end-to-end Risk Management Framework (RMF) Assessment & Authorization (A&A) process for Ashore and Afloat, providing overarching expertise for the A&A process. This effort will highlight and track significant physical, policy and or network security issues, improving network security and awareness on Naval networks world-wide.

Responsibilities
  • Review A&A package submissions to ensure system/network architectures and technical / non-technical operating features adequately protect and defend against unauthorized access, ensure systems availability, and meet DoD/Navy Cybersecurity (CS) implementation policy requirements and data protection safeguards.
  • Conduct CS compliance and A&A documentation validation assessments for Naval networks, legacy applications,and systems.
  • Assistin the development or updates to existing, A&A and CS documentation to ensure complete documentation in accordance with DoD A&A and CS policy.
  • Coordinate corrections for errors, information omissions, and shortfalls in A&A documentation packages.
  • Communicate feedback and coordinate corrections with subordinate commands within five business days andvalidate prior to processing.
  • Assistin the development procedures to support A&A workflow processes, criteria needed to facilitate processes and Navy Authorizing Official (NAO) accreditation decision milestones.
  • Providerepresentation in meetings to include providing meeting minutes and supporting follow-up tasks.
  • Assistin the development of point papers, naval messages, presentations, briefings, and other forms of written documentation on an as needed basis to support A&A and CS functions.
  • Assistin the development of Standard Operating Procedures (SOPs), checklists, workflow process charts, forms, POC lists, and other documentation needed to support NAO processes and related A&A and CS functions and keep it up to date.
  • Compile and analyze data for USFF leadership review for CS readiness and compliance.
  • Identify areas where commands should focus CS efforts as result of or in support of inspections.
  • Provide support for all stages involved during inspections, assessments, and certification events issues to include inspection finding adjudication in Vulnerability Management System (VMS), VRAM, and eMASS, assessing statistical data/metrics of post inspection adjudication status, and Security Technical Implementation Guide (STIG) review and interpretation.
  • Track and report compliance for all stages involved during Cyber Security Inspections (CSI), Command Cyber Readiness Inspections (CCRI) and Command Cyber Operational Readiness Inspections (CCORI); develop follow on reports by assessing inspection statistical data/metrics of post inspections adjudications status.
  • Conduct analysis of trends in inspection findings/results.
  • Support USFF subordinate commands with inspection related tasks such as tracking inspection findings; documenting vulnerability status; providing guidance and training relating to various ashore and afloat commands, relating to, but not limited to, Public Key Infrastructure (PKI), installed Information Systems/Program of Records (IS/PORs) (i.e., ACAS, NESSUS, HBSS, DNS, Continuous Monitoring and Risk Scoring (CMRS) site, and similar technologies) configuration, implementation, operation, and policy compliance; all relative STIGs, Tasking Orders (TASKORD), Operational Orders (OPORDS), scanning/patching/remediation process; with trends and analysis provided.
  • Potential Travel - CONUS 5-10%
Qualifications

Required:

  • Active SECRET Clearance
  • Minimum 3 years of experience in DoW/DoN Cybersecurity, RMF, or Information Assurance
  • Minimum 2 years of experience working with US Navy Shipboard Systems and Applications
  • Experience using Navy RMF tools, including DADMS/DITPR-DON, VRAM, and eMASS to process and update A&A packages
  • Knowledge of the National Institute of Standards and Technology (NIST) RMF Special Publications
  • Ability to Provide technical support and apply expertise in assessing information system compliance with DoD and Navy RMF standards and review, verify, and validate required DoD RMF documentation and artifacts in accordance with DoD Instruction 8510.01, RMF for DoD IT, and the Navy RMF Process Guide (RPG)
  • Ability to perform quality assurance reviews for required content in all packages in the A&A process in accordance with a client checklist
  • Ability to conduct RMF checkpoint and collaboration activities
  • Ability to perform RMF and FISMA data collection, analysis, reporting, and metrics generation
  • Ability to use vulnerability assessment scanning tools and provide related reporting
  • Proficient with Microsoft Office (Word, Excel, and PowerPoint)
  • Good Communication Skills
  • DoDM 8140 Systems Intermediate Security Analyst

Preferred:

  • BS Degree in Computer Science, Cyber Security, or related technical field
  • CCSP, Cloud+, CySA+, or GICSP
  • Familiarity with Afloat and Ashore Naval Networks
Pay Range

$100,000-$110,000

Get your free, confidential resume review.
or drag and drop your file here.