SAIC is looking for a Cyber GRC Analyst in Charleston, SC.
This individual will be responsible for supporting vendor and assigned ISSM efforts to develop RMF packages and providing relevant cybersecurity expertise. They will help take a Defense Health Agency (DHA) package through a full accreditation assessment and achieve an ATO.
Support and coordinate workflow, activity, and documentation necessary to achieve successful RMF Assessment & Authorization (A&A) efforts for various DoD environments. This includes:
Coordination among myriad stakeholders, e.g., Security Engineers, Network Administrators, System Administrators, Information Assurance Managers (IAMs) / Information Systems Security Managers (ISSMs), certification authorities (and representatives), accreditation authorities (and representatives), program managers, vendors, etc., necessary to properly identify, document, mitigate, and manage risk attributed to the target system, network, and/or application;
Identify, develop (either directly, or in coordination with applicable experts), and incorporate common artifacts found in a RMF accreditation package, e.g., system architecture and boundaries, hardware and software inventories, risk assessment reports, POA&Ms, data flows, PPSM accounting, and other necessary system, network, and application documentation;
Knowledge and experience identifying, assessing, and documenting compliance against applicable DoD IA security controls (technical, management, operational), Service (e.g., Army) regulations, etc., within the RMF package;
Familiarity with the use of vulnerability scanning and assessment tools (e.g., ACAS/Nessus) necessary to identify and document compliance;
Knowledge of and ability to use applicable compliance reporting tools (e.g., eMASS, CMRS, COAMS, Tanium, Phoenix) to document the progress to A&A.
BS and 3 years or HS and 7 years.
3 years of RMF experience
Capable of providing thought leadership to the ISSM in his/her efforts to maintain an organizational or system-level cybersecurity program, consistent with DoD appointment memorandum focal points (e.g., cybersecurity architecture, compliance requirements, objectives and policies, personnel, and processes and procedures).
Experience with Amazon Web Services is desired.
Ability to identify, interpret and evaluate major applications, infrastructure, enclaves, and Enterprise system environments based on proposed accreditation boundaries.
Ability to manage multiple projects simultaneously.
Strong verbal and written communications and interpersonal skills.
Active Secret Clearance
Minimum of an IAT level II certification. IAT/IAM level III certification is preferred