Cyber Security Logistics Specialist SME II supporting Defense Health Agency Risk Management Executive Division initiatives. Responsibilities include documenting security responsibilities and leading self-assessments in cybersecurity contexts.
Responsibilities
Reviews and updates the Detailed Architecture Diagram, Detailed Hardware/Software Inventory, and other system artifacts to determine the DoD IT type.
Develops the baseline set of impact values (low, moderate, or high) for the medical devices.
Identifies common controls associated with the inherited controls in the Security Plan.
Documents responsibilities associated with the inherited controls in the Security Plan.
Initiates the tailoring process in eMASS to modify the control set to account for conditions affecting the specific system more closely.
Adds relevant supplemental security controls and marks extraneous or impertinent controls as 'Not Applicable'.
Identifies security controls to be monitored on an ongoing basis.
Reviews site/organization change control policies.
Documents the method of applying policies to specific controls.
Coordinates with the IV&V Team to clarify information required for Special Access Programs.
Leads the execution of the self-assessment activities.
Completes applicable checklists in assessing the NIST SP 800-53 Revision 4 controls.
Documents upload self-assessment checklist results and artifacts documentation in eMASS.
Provides support with remediation and mitigation efforts.
Creates the Risk Assessment Report.
Coordinates with the ISSM to confirm the completion of the Security Authorization Package prior to eMASS submission.
Assists program leadership with status reports, white papers, weekly activity report, and other ad hoc requirements as necessary.
Performs other job-related duties as assigned
Requirements
Bachelor’s Degree in Information Technology or Cybersecurity, or an equivalent combination of education and experience in lieu of a degree.
8 years of experience.
Federal government contracting experience required.
Must possess a Security+ or other IAT Level I, II / IAM Level I, II certification.
Ability to maintain an Active DoD Secret clearance.
Lead Industrial Security Specialist at Boeing assessing compliance with security programs and implementing corrective actions. Involves extensive travel and oversight of security protocols across multiple locations.
Senior Security Adviser handling governance and US integration tasks at Boeing. Liaising with US - based partners and coordinating crisis management for international security operations.
Senior Manager of IT overseeing operational security services for Xcel Energy. Leading teams to ensure compliance and effective risk management across enterprise security operations.
IT Security Administrator managing access control and audit evidence across systems at Xcel Energy. Involves training security staff and handling incident investigations.
Senior ML Security Engineer developing security tools and frameworks for ML workflows. Ensuring proactive vulnerability detection and compliance with ML security standards at NXP.
Lead a multidisciplinary team at NXP focused on the proactive identification and analysis of security vulnerabilities in semiconductor products. Drive innovative approaches to security testing and team management.
Security Architect designing security architectures for embedded products at NXP. Collaborating with teams on threat assessments and managing security requirements in IoT/Automotive domains.
Security Software Engineer at Pinterest developing IAM infrastructure and tools for identity and authorization. Collaborating on mission - critical features in a team - focused environment.
Senior Network and Security Information Analyst defining and implementing network and information security at Airbus. Managing security assets and compliance across the organization while documenting and reporting vulnerabilities.
Associate Consultant for Microsoft Security focused on supporting the delivery of security solutions. Collaborate with experienced consultants and learn in a remote - first environment with occasional onsite work.