Loading jobs…
Loading jobs…
NHS
S. GOVERNMENT. S.
CITIZENSHIP. Role Description: As a cybersecurity SME within Delivery at Defense Unicorns, you will be responsible for owning all aspects of the RMF process from accreditation of the platform for our mission heroes. You will be expected to champion modern, continuous security implementations within DoD environments and systems (approval processes).
Your perpetual goal will be to accelerate the FedRamp and ATO process while simultaneously improving our security posture, thus pushing for cultural change away from security theater and towards responsive and resilient systems. While working within the existing DoD processes, you will also work with other engineers to find the best paths forward and contribute to Unicorn mission capabilities and open source solutions to further streamline ongoing and future efforts.
Responsibilities
: Leading and pathfinding the effort to achieve accreditation in accordance with NIST-800 series
are not exhaustive and additional
may be assigned based on the evolving needs of the organization.
as they arise.
Requirements
Developing and implementing cybersecurity policies, procedures, and controls necessary to meet FedRamp and DoD accreditation standards . Conducting comprehensive risk assessments and vulnerability analyses to identify potential security threats and mitigate risks. Collaborating with cross-functional teams including software developers, system architects, and other Government stakeholders to integrate cybersecurity measures into the software development lifecycle.
) Providing guidance and support to ensure continuous monitoring and maintenance of cybersecurity controls. Preparing and maintaining documentation required for the accreditation process, including System Security Plans (SSPs), Security Assessment Reports (SARs), and other relevant artifacts.
Serving as a subject matter expert on cybersecurity best practices, standards, and procedures within the organization.
Qualifications
: Proven experience in cybersecurity engineering, with a focus on achieving accreditation for software systems within the DoD environment. Proven track record of thinking outside the box and pushing the boundaries of the RMF/FedRamp/ATO status quo. In-depth knowledge of NIST-800 series standards, particularly NIST-800-53, and experience applying these standards to achieve accreditation.
Skilled at translating technical implementation (infrastructure as code and configuration as code) into verifiable eMASS security control responses that Approving Officials (AOs), and their staffs, can understand. Strong understanding of cybersecurity principles, technologies, and best practices, including encryption, authentication, access control, and secure coding practices. Hands-on experience with security assessment tools and techniques, such as vulnerability scanning and security analysis.
Familiarity with software development methodologies and practices, particularly Agile and DevSecOps. Excellent analytical and problem-solving skills, with the ability to assess complex systems and identify security risks. Effective communication and interpersonal skills, with the ability to collaborate with cross-functional teams and communicate technical concepts to non-technical stakeholders.
Eligibility to obtain and maintain a DoD security clearance.