INFORMATION SYSTEMS ARCHITECT MID
Location: Quantico, VA - MCSC - Lester St - Woodbridge Team
Clearance: TS/SCI
Education Level: High School Diploma or General Equivalency Diploma (GED)
Years of Experience: 5
Salary Range: 115,000 - 125,000
Required Certification:
Job Description
Assist the Government Lead in daily tasks to ensure all systems have current Authorizations to Operate (ATOs). Facilitate Assessment and Authorization (A&A) for Information Systems to ensure data availability, integrity, authentication, confidentiality, and non-repudiation. Through A&A review processes, ensure security measures are implemented for communication systems and networks, and provide guidance to ensure systems and personnel adhere to established security standards and Governmental requirements for security on these systems.
Develop and execute security policies, plans, and procedures. Initiate creation of A&A packages to support receipt of Authorizations to Operate (ATOs), collaborate with Engineers to gather required information for A&A packages, and update A&A packages as required. Perform lifecycle maintenance of A&A packages ensuring ATOs do not expire without proper updates.
Update Department of the Navy (DON) Application and Database Management System (DADMS) and Department of Defense Information Technology Portfolio Repository – Department of the Navy (DITPR-DON). Submit Ports and Protocols with all supplemental documentation to DISA for approval. Submit tickets to initiate action from Headquarters Marine Corps (HQMC) Command, Control, Communications, and Computers (C4) Cybersecurity Division (CY) for approval and ensure appropriate action is taken by designated points of contact.
Assist with validation of A&A packages as required by the Government. Review and provide input for Operational Plans of Action and Milestones (POA&Ms) for submission to Action Officers. Conduct vulnerability scans using Assured Compliance Assessment Solution (ACAS) and assist Engineers in documenting system vulnerabilities.
Perform vulnerability management using Tenable SecurityCenter, Nessus, RedSeal, BigFix, Security Content Automation Protocol (SCAP) Compliance Checker (SCC), HP Fortify, other automated tools, and manual inspection techniques. Document vulnerabilities in the RSA Archer eGRC system and report vulnerability statistics. Apply experience with the Department of Defense Information Assurance Program (DIACAP) and Risk Management Framework (RMF).
Responsibilities
Qualifications
Education & Certifications