Strong Roots. Bright Futures.
Cybersecurity Assessment and Authorization Subject Matter Expert
Location
District Of Columbia
Posted
2 days ago
Salary
Not specified
Seniority
Senior
Job Description
Title: Cybersecurity Assessment and Authorization SME
Location: Washington, D.C.
Job Description:
Overview
Please note that this position is contingent upon the successful award of a contract currently under bid.
Global in service but local in approach, Nisga'a Tek is committed to high-quality service to those who defend us. Nisga'a Tek ensures mission assurance and execution for customers and warfighters. Providing intelligence, IT, cyber security, training, logistics, administrative, acquisition, and background investigation services.
Summary:
The Cybersecurity Assessment and Authorization SME will serve as a cybersecurity Subject Matter Expert (SME) with regards to Assessment and Authorization (A&A) of information systems and all associated cybersecurity policies and procedures.
This position is off-site/hybrid and based in the Washington, DC metropolitan area. The incumbent must be able to travel to Fort Belvoir, VA for meetings as required.
Responsibilities
Essential Job Functions:
- Performs a DOD cybersecurity process while either authorizing an information system or serving as a SME for an information system undergoing authorization.
- Possess an understanding of how the security controls identified in the NIST 800-53 apply to the process of assessing and authorizing a large organization’s IT infrastructure such as DLA’s, in which there is a compilation of large and small enclaves, AIS applications and outsourced IT processes.
- Determines the applicable severity value for an identified vulnerability (e.g., non-compliant security control) and determines the possible ramifications on the system’s current or future authorization.
- Briefs senior management on the progress or results of an information system undergoing the Risk Management Framework (RMF) process.
Qualifications
Necessary Skills and Knowledge:
- Knowledgeable in the cybersecurity of emerging technology areas such as Cloud and Industrial Control Systems (ICSs), warehouse execution systems and Operational Technology (OT) infrastructures.
- Must have experience with the following programs of Microsoft Office Suite: Word, Excel, Access, PowerPoint, Project Management.
- Attention to Detail
- Ability to work independently and maintain tight deadlines.
- Excellent communication skills.
Minimum Qualifications:
- Minimum five years of relevant Risk Management Framework (RMF) and NIST A&A experience.
- DOD cybersecurity experience
- Experience in assessing security controls and conducting authorization reviews for large, complex organizations.
- Experienced in the general tenets supporting the overall DOD implementation of its authorization process, to include supporting cybersecurity policy, procedures, and processes.
- DOD Secret Clearance and must possess IT-II Non-Critical Sensitive security clearance or Tier 3 (T3) at time of proposal submission.
- CERT Personnel: Any team member assigned duties at DLA CERT shall possess a DOD TOP SECRET Clearance and must possess IT-I Critical Sensitive security clearance or Tier 5 (T5) at time of proposal submission.
- Any team member assigned duties as DLA CERT Analyst will maintain CSSP Analyst certification.
Preferred Qualifications:
- Bachelor's degree in a related field.
Pay and Benefits
At Goldbelt, we value and reward our team's dedication and hard work. We provide a competitive base salary commensurate with your qualifications and experience. As an employee, you'll enjoy a comprehensive benefits package, including medical, dental, and vision insurance, a 401(k) plan with company matching, tax-deferred savings options, supplementary benefits, paid time off, and professional development opportunities.
Related Guides
Related Categories
Related Job Pages
More Security Analyst Jobs
Senior Analyst - Threat Response and Preparedness
Ally FinancialAlly Financial is an award-winning global financial services company established in 1919. Founded to provide automotive financial services and products to Gener
Monitor and assess threats in the financial services environment, support incident response coordination, produce comprehensive threat assessments for leadership, and maintain crisis response documentation to enhance organizational preparedness.
Analyst, Cyber Security Operations
Carnival Cruise LinesTouted as the "World's Most Popular Cruise Line," Carnival Cruise Line is a publicly held company in the leisure, travel, and tourism industry offering exciting
Monitor security practices across the organization, assist in implementing corporate security policies, and configure security products to protect information systems. Proactively identify vulnerabilities to maintain a secure digital environment.
SAP R3 Security Analyst
Surge Systems India Pvt. Ltd.Distributor of Toro Turf maintenance machinery and advanced Irrigation systems in North & Eastern territories of India.
SAP Security Analyst supporting Toro’s global SAP operations
Cyber GRC, Senior Analyst (Remote)
CrowdStrikeCrowdStrike has redefined security with the world’s most advanced cloud-native platform that protects and enables the people, processes and technologies that drive modern enterprise. Tested and proven, the world's largest organizations trust CrowdStrike to stop breaches with unparalleled protection against the most sophisticated cyberattacks. The CrowdStrike culture has been built upon our Core Values since the day we began. We are Fanatical About the Customer, Relentlessly Focused on Innovation and believe that our Limitless Passion drives Unlimited Potential for every CrowdStriker. As a purpose-built remote-first company, we believe cultivating a connected culture for every employee, no matter where they are in the world, is a key ingredient in building a high-performing, diverse team. We don’t have a mission statement. We’re on a mission—to stop breaches. Ready to join a mission that matters?
The Cyber GRC Senior Analyst role at CrowdStrike involves managing security policies, conducting risk assessments, collaborating with teams on security issues, and optimizing processes within the Cyber GRC framework.




