Career Moonshot pulls this listing straight from the employer's hiring system — no recruiter middleman, no reposts. Applying takes you directly to Scientific Research Corporation.
Salary Statement Estimated Starting Salary Range: USD $96,600.00/Yr. - USD $160,850.00/Yr. Salary to be determined by the education, experience, knowledge, skills, and abilities of the applicant, internal equity, and alignment with market data.
Description
Developing and updating assessment and authorization documentation (Body of Evidence) for management and continuous monitoring of information systems
Performing ongoing compliance assessments using tools, such as Assured Compliance Assessment Solution (ACAS), Secure Content Automation Protocol (SCAP), and Trellix Virus Scan Enterprise while reviewing, documenting, and maintaining all results
Verifying patches and virus definitions to the systems using existing automated tools
Adhering to pre-defined configuration management and change management policies and procedures for authorizing software prior to its implementation on systems
Performing security audits using to track multiple events including any signs of inappropriate or unusual activity, intrusion events, data transfers, etc.
Performing security assessments of NCS Family of Systems in accordance with NIST, Navy, NSA, and NAVINTEL IA guidance
Working with system engineers to take corrective action to resolve identified problems
Performing Site Based Security Assessments (SBSAs) of systems and recommending authorization to the Designated Authorizing Official (DAO) as a certified Trusted Agent
Reporting security incidents in accordance with the Command Incident Response Plan (CIRP)
Ensuring systems are operated, used, maintained, and disposed of in accordance with all applicable security policies and practices
#LI-AM1
Requirements
5-8 years of cybersecurity experience
Must currently hold a DoD 8140-compliant IAT II certification ( Security+CE with appropriate CE/OS certificate), or IAT level II certification within six months
Knowledge of Risk Management Framework (RMF) v3 and v5 (Processes, workflow, etc.)
Experience with System Security Plans (SSPs), POA&Ms, ACAS/Nessus, SCAP, DISA STIGs, and all ATO package artifacts
Ability to work collaboratively with sys admins/ISSE's, communicate effectively, and coordinate STIG remediation with system administrators and developers
Experience with continuous monitoring tools such as LATTEART, BISCOTTI, and CYBORGBUNNY
Ability to manage tasks with little to no oversight or support as well as manage multiple, and at times, competing priorities without loss of productivity
Ability to use eMASS to execute, RMF v5, to include document and update system status, identify, document, and manage implementation of operational and technical security controls, implementation and risk assessment tabs, non-compliant and non-validated controls, POAM management (entry, evidence, close-out), produce report and track Plan of Action and Milestone (POA&M) due dates, etc.
Be open to new and innovative ideas
Must be able to be appointed ISSO for NCS systems within 6 months of employment
Desired Skills
Experience with Windows and UNIX based information systems standards with a working knowledge of networking devices
Knowledge of configuration and manual STIG reviews of various SQL databases, including MS SQL, PostgreSQL, MongoDB, MariaDB, MySQL, and Elasticsearch
Knowledge of web servers, including Apache Web Server, and Apache Tomcat
Experience with container security and DevSecOps
Knowledge of data flows and the ability to work up readable network topology and data flow diagrams
Experience with NAVINTEL IA and NSA enterprise services: Continuous Monitoring
Experience with the following systems/platforms/tools: XACTA, XACTA 360 (preferred), eMASS, HBSS, ACAS, Nessus, and SPLUNK
Experience implementing and/or monitoring for zero trust compliance
Clearance Information
SRC IS A CONTRACTOR FOR THE U.S. GOVERNMENT. THIS POSITION WILL REQUIRE U.S. CITIZENSHIP AS WELL AS A U.S. GOVERNMENT SECURITY CLEARANCE AT THE TOP SECRET / SCI LEVEL with CI POLY ELIGIBILITY
Travel Requirements
1-2 annual trips possible
About Us
Scientific Research Corporation is an advanced information technology and engineering company that provides innovative products and services to government and private industry, as well as independent institutions. At the core of our capabilities is a seasoned team of highly skilled engineers and scientists with multidisciplinary backgrounds. This team is challenged daily to provide cutting edge technology solutions to our clients.
SRC offers a generous benefit package, including medical, dental, and vision plans, 401(k) with a company match, life insurance, vacation and sick paid time off accruals with amounts increasing based on role and years of service, 11 paid holidays, tuition reimbursement, and a work environment that encourages excellence and more. For positions requiring a security clearance, selected applicants will be subject to a government security investigation and must meet eligibility requirements for access to classified information.
EEO
Scientific Research Corporation is an equal opportunity employer that does not discriminate in employment.
All qualified applicants will receive consideration for employment without regard to their race, color, religion, sex, age, sexual orientation, gender identity, national origin, disability, protected veteran status, or any other protected characteristic under federal, state or local law.
Scientific Research Corporation endeavors to make www.scires.com accessible to any and all users. If you would like to contact us regarding the accessibility of our website or need assistance completing the application process, please contact
[email protected] for assistance. This contact information is for accommodation requests only and cannot be used to inquire about the status of applications.