Information Systems Security Officer managing RMF and security integration for CACI. Leading technical projects and mentoring junior engineers while ensuring compliance with cyber regulations.
Responsibilities
Manage Risk Management Framework (RMF) process
Work with system development team to identify needed RMF artifacts and load them into the government’s EMASS system.
Develop security plans, policies, and designs.
Configure and implement security solutions based upon the customer’s performance criteria and specifications
Conduct systems pre-test and acceptance tests to validate the designed performance criteria
Structure mock designs based upon RFP specifications in support of the Bids & Proposal teams
Collaborate with government and /or subcontractors at customer site for security solution integration into existing infrastructure
Develop and perform technical presentations for customers
Mentor junior engineers and technicians
Serve as technical lead on projects.
Travel to other CACI Locations or Customer Sites as necessary
Proactively ensure a safe work environment and adhere to CACI EH&S policies and procedures
Perform other duties as required
Requirements
A Bachelors degree is required.
Knowledge of risk assessment tools, technologies, and methods including EMASS system
Experience designing secure networks, systems, and application architectures
Experience planning, researching, and developing security policies, standards, and procedures
Ability to communicate network security issues to peers and customers
Working knowledge of current Cyber technologies and experience with NIST 800 Series and DoD 8570 regulations and governing DISA STIGs and/or SRGs
Understanding of Information Assurance Vulnerability Management (IAVM) and Information Assurance Vulnerability Assessments (IAVAs)
Prior experience with RMF controls, risk assessments, and POA&M generation
Strong working knowledge of Confidentiality, Integrity, and Availability (CIA) concepts, to include 2-factor authentication, Public Key encryption techniques, patch management, end-point security systems, intrusion detection, security event management and defense-in-depth.
Well versed in DoD cyber security Assessment and Authorizations (A&A) DoD Implementation, Directives, NIST Special Publications and other government cyber security standards, policies, and directives
Experience with Nessus, ACAS, SCAP
Experience completing and review DISA Security Technical Implementation Guides (STIGs)
Experience conducting risk analysis on products and system components through review of CVEs, plugins, IAVAs
Experience onboarding assets to centrally managed Enterprise solutions.
Application Security Architecture and Design experience
Security Compliance Operations and Application Security Assessment experience
DoD 8570.01 IAT level 2 or greater cyber security certification per DoD 8570.01 (such as Security+)
Experience designing and implementing Commercial Solutions for Classified (CSfC) Multi-Site Connectivity Capability Package desired
Systems integration experience
Excellent interpersonal and presentation skills
At least five years of continuous recent experience in the field of DoD information systems security and/or cybersecurity.
Possess an active Information Assurance Management (IAM) Level III certification.
Additional cyber and/or IT certifications such as Certified Information Systems Security Professional (CISSP), Certified Ethical Hacker (CEH), or CompTIA’s Advanced Security Practitioner (CASP)
Security Design Lead in Rabobank's cybersecurity team, designing secure technology solutions for food & agribusiness banking. Collaborating across teams to ensure robust security implementations.
Identity Security Posture Management Specialist enhancing identity security posture at Kemper Insurance. Collaborates across teams to tackle identity risks and compliance challenges in a high - performing culture.
Principal Architect developing cybersecurity strategy for Ensemble's technology - enabled revenue cycle management solutions. Focus on securing cloud architectures and ensuring information assurance in healthcare.
Senior Manager overseeing Security Risk Management at First American. Leading enterprise policies, third - party vendor security, and security strategy execution.
Zscaler Engineer responsible for maintaining cybersecurity tools and developing integrations at HP. Collaborating across teams to enhance data loss prevention strategies and monitor industry threats.
Designer developing comprehensive application solutions for security systems at Johnson Controls. Collaborating on technical sales support and large - scale integrated electronic security systems.
Analyst role supporting Epic Security & Configuration at Acrisure, ensuring application functionality and troubleshooting issues. Collaborating with teams for configuration and security in Applied Epic systems.
Security Detection & Response Engineer for Flutter Entertainment developing security detection frameworks. Collaborating with global teams to enhance cybersecurity operations in complex, multi - cloud environments.
Specialist Software Design Verification Engineer in Cybersecurity at Solventum. Responsible for software verification, testing processes, and compliance with medical device regulations.
Lead defensive threat research on generative and agentic AI systems at RBC. Identify emerging threats and develop proof - of - concept exploits to enhance AI security.