Cyber & A&A Security Specialist - Hybrid Remote

Attainx Inc.

Silver Spring (MD)

Hybrid

USD 98,000 - 110,000

Full time

2 days ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Paid vacation
Medical, dental, and vision coverage
Matching 401(k) plan
Long & Short-Term Disability

Job summary

AttainX, Inc. is seeking a Cyber & A&A Security Specialist to join our cyber security program supporting a US federal government client in a hybrid remote role, based near Silver Spring, MD. You will apply RMF, conduct A&A activities, and coordinate with stakeholders.

Required are 5+ years in IT security, experience with NIST RMF, and tools like Tenable Nessus, ArcSight, and IBM BigFix. A bachelor's degree is preferred; professional certs such as CISSP/CISA/GCIH are highly valued.

Qualifications

  • 5+ years applying IT security concepts and using standard tools.
  • 5+ years with enterprise architecture methodologies, concepts, and tools.
  • 5+ years in contingency planning and backup/recovery per NIST guidance.
  • 5+ years using technical testing tools such as Tenable Nessus, ArcSight, IBM Big Fix.
  • 5+ years performing assessments of Federal Information Systems using RMF.
  • Ability to work in a cohesive team environment.
  • Hold or obtain within six months one of: CISSP, CISA, GCIH, GSNA, CEH, CGRC, SCNP, SCNA.

Responsibilities

  • Conduct full lifecycle Security Control Assessments and A&A for NWS systems per RMF, policy, and directives.
  • Validate SSPs, FIPS 200 controls, and NIST SP 800-53 compliance.
  • Execute security control tests via documentation review, validation, and stakeholder interviews.
  • Collect and document evidentiary artifacts to verify control implementation.
  • Utilize CSAM to retrieve POAMs and artifacts for A&A documentation accuracy.
  • Analyze vulnerability scans to identify gaps and validate remediation.
  • Develop pre-assessment and assessment deliverables (SAPs, SCA workbooks, kickoff decks).
  • Document assessment results and risk determinations in SARs, VARs, and ATO briefing decks.

Skills

Cyber Security
Information Security
A&A

Education

Bachelor’s Degree (or higher) in a related field

Tools

Tenable Nessus
ArcSight
IBM BigFix
CSAM

Job description

If you are unable to complete this application due to a disability, contact this employer to ask for an accommodation or an alternative application process.

Cyber & A&A Security Specialist - Hybrid Remote

Professional Silver Spring, MD, US

2 days ago Requisition ID: 1970

Salary Range: $98,000.00 To $110,000.00 Annually

Job Title: Cyber & A&A Security Specialist

Location:Hybrid (Reside within a commutable distance of Silver Spring, MD to work onsite as required)

Security Clearance:Must have or the ability to obtain a Moderate Public Trust

AttainX, Inc. is in search of a highly energetic Cyber & A&A Security Specialistto join our team on a cyber security program supporting our US federal government client.

Basic Minimum Qualifications:

  • Knowledge of DOC, NOAA, and NWS IT security policies and implementation standards or those of similar sized organizations AND comprehensive understanding of NIST guidance to include, but not limited to, NIST Special Publications and Federal Information Processing Standards.
  • At least 5 years of recent experience (within the last 6 years) in applying IT security concepts, methodologies, principles, procedures and using industry-standard IT security tools.
  • At least 5 years of recent experience (within the last 6 years) with enterprise architecture methodologies, concepts, procedures, principles, and tools.
  • At least 5 years of recent experience (within the last 6 years) in contingency planning and backup and recovery best practices and application of NIST guidance in this area.
  • At least 5 years of recent experience (within the last 6 years) in using technical testing tools (Tenable Security Center, ArcSight, IBM Big Fix, etc.).
  • At least 5 years of performing assessments of Federal Information Systems using the Risk Management Framework.
  • Ability to work in a cohesive team-oriented environment.
  • Possess at least one of the following Certifications or be able to Obtain within six (6) months of hire:
    • Certified Information Systems Security Professional (CISSP).
    • Certified Information Systems Auditor (CISA).
    • GIAC Certified Incident Handler (GCIH).
    • GIAC Systems and Network Auditor (GSNA).
    • Electronic Commerce Council Certified Ethical Hacker (CEH).
    • ISC2 Certified in Governance, Risk and Compliance (CGRC).
    • Security Certified Network Professional (SCNP).
    • Security Certified Network Architect (SCNA).

Preferred Qualifications:

  • Bachelor’s Degree (or higher) in a related field
  • Knowledge of assessing and securing cloud-hosted systems in accordance with federal security requirements
  • Self-starter, highly motivated individual who adapts to a dynamic work environment
  • Strong attention to detail with an ability to operate effectively across multiple priorities.
Key Responsibilities:
  • Conduct full lifecycle Security Control Assessments and Authorization (A&A) activities for NWS FIPS 199 Low, Moderate, High, HVA, and hybrid systems in accordance with the NIST Risk Management Framework (RMF), NWS policy, NOAA, and DOC directives
  • Validate information System Security Plans (SSPs), FIPS 200, control implementations, and supporting policies and procedures for accuracy, completeness, and NIST SP 800-53 compliance.
  • Execute security control test procedures through documentation review, technical validation, and interviews with system stakeholders to determine control implementation status and effectiveness
  • Collect, analyze, and document evidentiary artifacts (screenshots, test logs, interview notes) to validate control implementation and effectiveness.
  • Utilize CSAM to retrieve POAMs, artifacts, and other pertinent documentation to assist with the A&A process and ensure accuracy of the A&A documentation uploaded in the tool
  • Analyze and interpret vulnerability and configuration compliance scan results from tools like Tenable Nessus to identify control gaps, assess risk, and validate remediation actions.
  • Develop and maintain pre-assessment and assessment deliverables, including Security Assessment Plans (SAPs), Security Control Assessment (SCA) workbooks, and kickoff deck briefings
  • Document assessment results and risk determinations in Security Assessment Reports (SARs), Vulnerability Assessment Reports (VARs), and Authorization to Operate (ATO) briefing deck.

Skills:

Cyber Security, Information Security, A&A

Non-Essential Functions:

  • General Duty Requirements

About Us AttainX Inc. is CMMI Level 3, ISO 9001:2015 certified QMS, and a Gold Level SAFe Partner. For over 14 years, AttainX has delivered innovative IT and cloud-based solutions for a broad portfolio of federal clients, including USDA, NOAA, DOE, DHS, and DIA.

  • Paid vacation
  • Medical, dental, and vision coverage
  • Matching 401(k) plan
  • Long & Short-Term Disability

Accommodations:
Individuals with disabilities may request reasonable workplace accommodations by contacting AttainX Human Resources directly and specifying the nature of the support needed.

EEO Commitment:
AttainX is an Equal Employment Opportunity employer and prohibits discrimination in the workplace based on Title VII of the Civil Rights Act, VEVRAA, Section 503, and other applicable laws. These protections extend to all applicants and employees.

Physical Demands:
This position requires extended periods of sitting, computer use, and communication via phone or email. Occasional lifting of up to 10 pounds may be necessary. Vision abilities required include close, distance, and peripheral vision as well as depth perception

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Cyber & A&A Security Specialist - Hybrid Remote
Cyber & A&A Security Specialist - Hybrid Remote

ATTAINX INC • Silver Spring (MD)

Hybrid
USD 98,000 - 110,000
Paid vacation
Medical, dental, and vision coverage
Matching 401(k) plan
+1
IT Security Specialist - Penetration Tester
IT Security Specialist - Penetration Tester

Attainx Inc. • Silver Spring (MD)

On-site
USD 125,000 - 150,000
Competitive compensation package
Benefits package
Hybrid work arrangement
Cybersecurity Analyst
Cybersecurity Analyst

Amentum • McLean (VA)

On-site
USD 130,000 - 160,000
Health Insurance
Dental Insurance
Vision Insurance
+2
Senior Cybersecurity Analyst - CONTINGENT - 26-022 - Hybrid
Senior Cybersecurity Analyst - CONTINGENT - 26-022 - Hybrid

AUSGAR Technologies Inc • San Diego (CA)

Hybrid
USD 140,000 - 165,000
Hybrid work model
Cybersecurity Systems Analyst, Sr.
Cybersecurity Systems Analyst, Sr.

TJ Consulting Group • Coronado (CA)

On-site
USD 120,000 - 170,000
PTO
Holiday Pay
401K with a 4% Match
+13
Cybersecurity Lead
Cybersecurity Lead

Client Solution Architects • Washington

On-site
USD 120,000 - 160,000
Cybersecurity Architect – Senior Technical Advisor
Cybersecurity Architect – Senior Technical Advisor

Nava • Fort Meade (MD)

On-site
USD 215,000 - 230,000
Generous medical insurance
Dental insurance
Disability insurance
+4
Cyber Security Officer, Senior
Cyber Security Officer, Senior

AnaVation LLC • Reston (VA)

On-site
USD 150,000 - 190,000
Medical insurance
Dental insurance
Disability insurance
+3
Cybersecurity Assessment and Authorization (A&A) Specialist
Cybersecurity Assessment and Authorization (A&A) Specialist

Mission Technologies, a division of HII • Lincoln (MA)

On-site
USD 86,000 - 175,000
Medical, dental, and vision plan
401(k) Savings Plan
Tuition reimbursement
+2
Cybersecurity Architect – Senior Technical Advisor
Cybersecurity Architect – Senior Technical Advisor

AnaVation LLC • Fort Meade (MD)

On-site
USD 140,000 - 190,000
Medical insurance
Dental insurance
Vision insurance
+2