System Security Analyst

GBTI Solutions Inc

United States

On-site

USD 120,000 - 150,000

Full time

14 days+
Application generator

Stand out for this role — generate a tailored resume and cover letter in about a minute.

Get past ATS filters

Job summary

NAVFAC Marianas CIO is seeking a Systems Security Analyst / ISSE to provide cybersecurity engineering support across FRCS, networks, and data, guiding RMF lifecycle, vulnerability management, continuous monitoring, policy development, and incident response. This role may require on-call rotation with MAR CERT and emergency essential status.

The candidate must hold U.S. citizenship, a TS clearance, and DoD 8140 qualifications, with hands-on experience using ACAS, eMASS, VRAM, and STIG tools;

Qualifications

  • U.S. Citizenship required.
  • Active Top Secret clearance.
  • 5+ years RMF experience; 1+ year FRCS RMF/cybersecurity tasks preferred.
  • Excellent written and verbal English; ability to author technical reports and procedures.
  • Ability to work independently with minimal supervision.
  • Physical ability for field duties and lifting up to 25 lbs.
  • Maintain CPD hours annually.

Responsibilities

  • Drive end-to-end RMF lifecycle (Steps 1–6) per DoN/NAVFAC guidance; verify inventories and artifacts; upload packages into eMASS.
  • Achieve, maintain, and track Authorities to Operate (ATOs); facilitate annual security reviews; draft MFRs for baseline changes.
  • Develop and maintain security policies, SOPs, and implementation plans mapped to NIST SP 800-53 controls.
  • Develop and execute Vulnerability Management using DoN tools; generate reports; upload results to VRAM.
  • Sustain System-Level Continuous Monitoring; conduct scans, log analysis, remediation, and quarterly POA&M updates.
  • Provide on-site RMF validation/testing for RMF Step 4; coordinate with system owners and validators.
  • Serve as CM Officer on the Configuration Control Board; provide risk analyses for FRCS baseline changes.
  • Perform incident response with MAR CERT; participate in on-call rotations.
  • Coordinate technical support across FRCS; deliver RMF status reports and maintain records in Maximo/eProjects; prepare MSRs.

Skills

RMF lifecycle
ATOs management
NIST SP 800-53
Vulnerability management
Incident response
Security policy writing
DoN tools (ACAS)
eMASS/NAVFAC tools
Configuration management
Technical reporting

Education

DoD 8140 Work Role 461
CCSP
Cloud+
GICSP
CISSP

Tools

ACAS
Nessus
VRAM
Security Center
STIG Viewer
Maximo/eProjects
eMASS

Job description

Job Description
Job Description
Position Overview

The Systems Security Analyst / Information Systems Security Engineer (ISSE) provides cybersecurity engineering support to the Naval Facilities Engineering Systems Command (NAVFAC) Marianas Command Information Office (CIO). The role focuses on protecting the confidentiality, integrity, and availability of Facility-Related Control Systems (FRCS), networks, and data through the full Risk Management Framework (RMF) lifecycle, vulnerability management, continuous monitoring, policy development, and incident response.Personnel are considered Emergency Essential / Mission Essential and may be required to support the MAR Cyber Emergency Response Team (CERT) on-call rotation (with schedule flexing to stay within 40 hours/week).

Key Responsibilities
  • Drive end-to-end RMF lifecycle execution (Steps 1–6) in accordance with Department of the Navy (DoN) and NAVFAC Echelon II guidance; verify system inventories and artifacts for compliance, completeness, and quality; format and upload packages into eMASS.
  • Achieve, maintain, and track Authorities to Operate (ATOs) for FRCS; facilitate annual security reviews and draft/submit Memorandums for Record (MFRs) for baseline changes.
  • Develop, author, and maintain security policies, Standard Operating Procedures (SOPs), and implementation plans mapped to NIST SP 800-53 control families, tailored to the FRCS environment.
  • Develop and execute a comprehensive Vulnerability Management Strategy; perform vulnerability and compliance assessments using approved DoN tools (ACAS, SCAP, Evaluate STIG); complete manual STIG/SRG validations (.ckl/.cklb); generate Security Center and eMASSter reports; upload results to VRAM.
  • Sustain System-Level Continuous Monitoring (SLCM): conduct routine scans, audit log analysis, drive remediation/mitigation, and provide accurate quarterly Plan of Action and Milestones (POA&M) updates.
  • Deliver on-site validation and testing support for RMF Step 4, coordinating with system owners and independent validators.
  • Serve as technical representative / Configuration Management (CM) Officer on the Configuration Control Board (CCB); provide security impact analyses and risk assessments for proposed FRCS baseline changes.
  • Execute incident response operations as a member of the MAR CERT, including participation in on-call rotations.
  • Prioritize and coordinate technical support across FRCS environments; deliver bi-weekly RMF status reports to the ISSM and maintain project status records in Maximo and/or eProjects; prepare Monthly Status Reports (MSRs).
Required Qualifications
  • U.S. Citizenship.
  • Active Top Secret security clearance.
  • DoDM 8140.03 foundational qualification for Work Role 461 (Systems Security Analyst) at Intermediate (or Advanced) proficiency level.
    • Intermediate-level certifications (one required): CCSP, Cloud+, GICSP, GISF, GSEC, or Security+.
    • Advanced-level certifications also accepted (e.g., CISSP, CySA+, etc.).
  • Minimum of 5 years of RMF experience and 1 year of specialized experience with Facility-Related Control Systems (FRCS) performing RMF and cybersecurity engineering tasks (strongly preferred).
  • Demonstrated ability to work independently with minimal supervision.
  • Excellent written and verbal communication skills in English; proven ability to author technical reports, security policies, and procedures and interface effectively with system owners, ISSMs, and other government personnel.
  • Physical capability to perform the duties, including prolonged standing/walking over uneven surfaces, bending, climbing ladders, and lifting IT equipment up to 25 lbs.
  • Maintain certification currency and complete required Continuous Professional Development (CPD) hours annually.
Preferred / Highly Desired
  • Prior experience supporting NAVFAC, DoN, or DoD FRCS environments.
  • Hands-on experience with eMASS, ACAS/Nessus, VRAM, Security Center, STIG Viewer, and Maximo/eProjects.
  • Familiarity with NAVFAC Echelon II RMF Business Rules.
Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Cybersecurity Analyst | On-site | Santa Rita, Guam | Top Secret Clearance
Cybersecurity Analyst | On-site | Santa Rita, Guam | Top Secret Clearance

Ares Enterprise • Santa Rita (GU)

On-site
USD 110,000 - 160,000
Cybersecurity Analyst | On-site | Santa Rita, Guam | Top Secret Clearance
Cybersecurity Analyst | On-site | Santa Rita, Guam | Top Secret Clearance

Ares Enterprise • Northern (KY)

On-site
USD 120,000 - 190,000
Systems Security Analyst
Systems Security Analyst

Magnus Management Group LLC • Guam

On-site
USD 110,000 - 140,000
401(k)
Dental insurance
Health insurance
+2
Systems Security Analyst
Systems Security Analyst

Magnus Management Group LLC • United States

On-site
USD 90,000 - 115,000
401(k)
Dental insurance
Health insurance
+2
Information Systems Security Engineer (ISSE) / Systems Security Analyst - Federal Client
Information Systems Security Engineer (ISSE) / Systems Security Analyst - Federal Client

Vinsys Information Technology Inc • Santa Rita (GU)

On-site
USD 110,000 - 160,000
RMF & FRCS Cyber Engineer — Systems Security Analyst
RMF & FRCS Cyber Engineer — Systems Security Analyst

GBTI Solutions Inc • United States

On-site
USD 120,000 - 150,000
Information Systems Security Engineer (RMF)
Information Systems Security Engineer (RMF)

Saalex • Newport (RI)

On-site
USD 60,000 - 70,000
Health insurance
401k plan
Life insurance
+4
System Security Engineer
System Security Engineer

New Directions Technologies, Inc • Port Hueneme (CA)

On-site
USD 75,000 - 94,000
Senior Cybersecurity Analyst
Senior Cybersecurity Analyst

Astrion • Washington

On-site
USD 117,000 - 143,000
Information System Security Manager III
Information System Security Manager III

International Executive Service Corps • San Diego (CA)

On-site
USD 150,000 - 210,000