Cyber Technical Analyst
6314 Remote/Teleworker US
The DoD Healthcare Management System Modernization (DHMSM) Program is looking for a Cyber Authorization and Sustainment SME to join our cyber team in support of the continued development, sustainment, and deployment of the Military Health System (MHS) GENESIS system. MHS GENESIS is deployed globally to over 3700 locations at 138 Medical Treatment Facilities (MTFs), serving 190K users, providing 1100+ clinical workflows delivering medical electronic health record (EHR) capabilities for nearly 10M beneficiaries.
The Cyber Authorization and Sustainment SME will support the Cyber Authorization and Sustainment Lead (Authorization Lead) with all Risk Management Framework (RMF), Interim Authorization to Test (IATT), Authority to Operate (ATO), and Risk Assessment functions. Responsibilities include, but are not limited to, the following:
Provide cyber security support to the DHMSM EHR system and effectively support the review of systems architecture and technical documents from a cybersecurity perspective.
Provide technical planning, development, integration, verification, and validation support of systems.
Serve as key Information Assurance (IA) decision maker and responsible for the management and technical administration of the Information System (IS) per DHA/FISMA RMF.
Oversee the day-to-day information system security operations, provide solution to complex problems, and develop innovative solution to meet changing security requirements
Document compliance actions and develop Plan of Actions and Milestones (POA&M) to address non-compliance within the allotted timeframe. Regularly evaluate proposed changes or additions to the information system, and advise senior site leadership of security relevance to change.
Participate in internal/external security audits/inspections; perform risk assessments and Continuous Monitoring leading towards systems ATO/ATC.
Responsible for the management and enforcement of information security policies, conducting security and risk assessments using security frameworks (e.g., NIST-800-53, RMF, Common Criteria, etc.), mitigating risk via security controls, testing and evaluation to certify and accredit commercial security products.
As ISSO, Support the development of cyber documentation (SP, CM, SAP, POA&M, SAR) for submission to the DHMSM PMO and DoD Department of Health Agency (DHA) to attain system ATO/ATC.
Effectively engage with a variety of government stakeholders including the DoD-DHA Cyber Security Senior staff, including the AO, and ISSM, engineers in development of cyber security policies.
Provide support to the other DHMSM ISSOs supporting the Authorization Branch to ensure Authorization activities are properly coordinated inside of eMASS and on the program.
Support the Authorization Lead with all required RMF related tasks to support new and sustaining ATOs, Common Control Authorizations (CCA), and IATTs.
Assist with the development of templates and recommendation of tools to support risk management and ATO activities.
Assist Authorization Lead in working with the Automation SME to determine manual processes that could be automated.
Provide pre-assessments for all Authorization and Assessments (A&A) systems in DHMSM utilizing DHA policy and eMASS as authoritative source for A&A.
Identify requirements that are security critical and establish corresponding controls for these requirements
Periodically evaluate the effectiveness of information security controls and ensure operational security posture is maintained.
Support cybersecurity compliance assessment efforts by providing systems engineering and documentation support.
Ensure all DoD cybersecurity-related documentation is current and accessible to properly authorized individuals.
Ensure all users have requisite security clearances and access authorization.
Qualifications
BS degree and 8-12 years of prior relevant experience
US Citizen with Active Secret Clearance or higher – required. Contract requirement.
DoD 8570 Certification
Experience conducting network and network security assessments and documenting the results using NIST SP 800-53A, completing security plans and recommending Security Controls for Federal Information Systems
Experience documenting recommendations to correct security weaknesses resulting from security assessments and tracking implementation of corrective actions
Experience developing network security policies, system security documentation and procedures
Prior experience with DOD Accreditation and tools such as ACAS, eMASS, CMRS and HBSS
Knowledge of networks, cyber defense toolsets and processes. Strong understanding of related technologies such as: networking technologies, operating systems, and security related tactics, techniques, and procedures.
Excellent written and verbal communication skills and the ability to effectively interact and work with internal team members, vendors and clients.
Experience with DoD Information Assurance Vulnerability Management (IAVM) Program
Extensive experience as ISSO with DOD DHA Enterprise Mission Assurance Support Service (eMASS) tool and POAM management.
Experience with DISA scan tools such as HBSS and ACAS, STIG, in ensuring the sound security posture and configuration of DoD’s systems.
Preferred Qualifications
Minimum of 5 years’ hands-on experience on Defense Health Agency projects in a cybersecurity role.
Experience with DoD Military Health preferred
Scripting knowledge: PowerShell, Python, Shell Scripting
Experience with Oracle Cloud Infrastructure
Experience with Cloud Authorizations
Original Posting Date:
2024-10-16While subject to change based on business needs, Leidos reasonably anticipates that this job requisition will remain open for at least 3 days with an anticipated close date of no earlier than 3 days after the original posting date as listed above.
Pay Range:
Pay Range $101,400.00 - $183,300.00The Leidos pay range for this job level is a general guideline only and not a guarantee of compensation or salary. Additional factors considered in extending an offer include (but are not limited to) responsibilities of the job, education, experience, knowledge, skills, and abilities, as well as internal equity, alignment with market data, applicable bargaining agreement (if any), or other law.
ApplyJob Profile
RestrictionsRemote/Teleworker US
Benefits/Perks Tasks- Conduct risk assessments
- Configuration
- Develop
- Develop compliance documentation
- Documentation
- Documenting
- Manage information system security operations
- Perform risk assessments
- Planning
- Review systems architecture
- Risk Assessment
- Risk Management
- Support cyber security for EHR system
- Technical planning
- Test
- Testing
- Tracking
ACAS Administration Architecture Automation CCA Clinical Workflows Cloud Cloud Infrastructure Common Criteria Communication Compensation Compliance Compliance Documentation Configuration Corrective Actions Cyber Cybersecurity Cyber Security Data Deployment DISA Documentation Documentation Support DOD DoD 8570 Education EHR EMASS Engineering Evaluation FISMA Healthcare Management Implementation Information Assurance Information security Infrastructure Integration Leadership Management Monitoring Network Networking Network security NIST NIST 800-53 Operating Systems Operations Oracle Planning POA&M PowerShell Python Risk Assessment Risk assessments Risk Management Risk Management Framework RMF SAP Scripting Security Security audits Security Controls Security Documentation Security frameworks Security Operations Security policies Security posture Shell Shell scripting STIG Support Sustainment Systems architecture System security documentation Systems Engineering Technical Technical Planning Testing Validation Verbal communication Verification Vulnerability Management Workflows
EducationAS Business Degree Engineering Information Security Information Systems Security Systems Engineering Technical
Certifications