OPEN - Cybersecurity Engineer - San Diego, CA (TacMobile)
Titanium Cobra Solutions is an organization that has a long history of GETTING THE JOB DONE; on-time, on-budget, and within the highest standards of quality. Our staff has a passion to truly make a difference for our client community by tactfully challenging the status quo, while delivering effective solutions that create business value for our customers. Our solution-focused team is a collection of technical, project, and process-oriented professionals who collectively make the impossible, possible. If you are up to the challenge of an always evolving agile organization with ideals that value their personnel’s value – Come join our team!
For more exciting career opportunities contact: info@titaniumcobra.com
Position Summary
We are currently seeking a talented and experienced individual to join our team to provide Cybersecurity Engineering support for our program. This position is located in San Diego, CA. Your contributions will play a vital role in ensuring the successful accomplishment of the program's mission requirements. This position requires you to work on-site at the government client site, working closely with colleagues and collaborating effectively with the client as needed.
Minimum Requirements:
Bachelor’s Degree.
7+ years of demonstrated experience providing cybersecurity engineering services within a program management office (PMO).
Experience using Microsoft Office applications, including Word, Excel, and PowerPoint.
Ability to maintain an active security clearance.
Ability to self-start and multitask in a fast-paced environment and prioritize multiple tasks with minimal supervision.
Active DOD TS Clearance Required
An active clearance is required for this position. Applicants selected will be subject to a security investigation and may need to meet eligibility requirements for access to classified information.
Key Roles and Responsibilities:
Updates and maintains Cyber Security (CS) Strategy documentation that is compliant with DoD CS policies and regulations including the Risk Management Framework (RMF) processes. Specifically, TacMobile products that need to renew legacy system Authority to Operate certifications (ATOs) and obtain new increment accreditation (ATO).
Aids operational sites with analysis and preparation of items related to the Command Cybersecurity Operational Readiness Inspections (CCORls). This includes identifying and assisting with gaps in TacMobile ISEA documentation and Operational site's policies, instructions, and Standard Operating Procedures (SOPs).
Conducts Cyber Assist Visits (CAVs) with all TacMobile operational sites. CAV is a midÂterm effort to provide training and assistance to improve TOC/MTOC self-sufficiency in assessing cyber posture and taking appropriate actions to harden it. It is based on the site's evaluation under a CCORI.
Assist PMW750 Cyber APM with TacMobile cybersecurity tasks, data calls, or RFls as needed.
Provide cybersecurity engineering support for systems and programs in the production phase for the program resulting in the successful accomplishment of mission requirements.
Address accreditation requirements for P-8A Fleet Releases and TacMobile Technical Refreshes.
Provide cybersecurity engineering support to conduct Cybersecurity RMF A&A activities in support of DoD cybersecurity requirements such as CYBERSAFE and CCA compliance.
Examples of support functions include the following:
Collaborate with stakeholders such as the PMO and ISEA cyber personnel to obtain and sustain PMO PoR or supported accreditations.
Support the implementation and sustainment of the RMF in accordance with the RMF Process Guide and other DoD/DoN cyber directives. Examples of support functions include the following:
Prepare, review, and submit RMF A&A documentation to approving authorities.
Upload documents into the eMASS database
Prepare A&A documentation by performing security scans, analyzing, and recommending solutions, mitigating vulnerabilities by applying updates, remedies, and patches using the STIG and IAV
Routinely track the system or information environment for security-related events and configuration changes that negatively affect security posture.
Report adverse changes in the security posture of systems and propose mitigations immediately to the SCA and AO
Provide technical comments, questions, and recommendations for a reassessment of any or all security controls to the SCA or AO as necessary.
Validate cybersecurity tests results to ensure compliance prior to submitting them to the PSO, SCA, and AO for review and approval.
Validate activities and controls are enacted to secure information.
Analyze and review gaps in security and propose solutions to mitigate risks in technical and business processes.
Support the identification and implementation of the security control baseline set and any applicable overlays.
Assess the quality of security control implementation against requirements.
Coordinate security control validation with the ISSM, SCA Liaison, PSO, and AO
Support the management of schedule entries to ensure vulnerabilities are accurately tracked, mitigated, and resolved in accordance with deadlines.
Report missed deadlines to the AO. Conduct cybersecurity testing including the use of ACAS.
Record security controls
Record security control compliance status during the continuous monitoring phase of the lifecycle. This includes performing annual security reviews, testing of cybersecurity controls, and testing of the contingency plan to maintain FISMA compliance.
Manage and address trouble calls.
Register systems in the designated government tool (e.g. eMASS, VRAM, DITPR - DON/DADMS)
Provide support for cyber-related inspections.
Comply with requirements such as TASKORDs, CTOs, and IAVM.
Other support functions include:
Conducting weekly applicability reviews and newly released IAVs.
Collaborating with stakeholders (e.g. engineers) to test and release patches for IAVs; and
Updating the VRAM database weekly for vulnerabilities.
Support the mitigation and closure of vulnerabilities under the system's change control process.
Prepare cybersecurity strategy documentation compliant with DoD CS policies and regulations including the RMF process.
Prepare SSAAs with associated appendices.
Provide technical comments, questions, and recommendations to categorize systems and implement RMF security controls.
Support cybersecurity program requirements to meet Test and Evaluation and RMF accreditation requirements for current and future PMO supported systems.
Provide technical comments, questions, and recommendations to address risks related to cybersecurity.
Present results to the stakeholders such as the NAVSEA Echelon II and AO Team to obtain approval and signature for SARs and Security Authorization Packages, to include IATTs and ATOs
Analyze and review proposed changes to the fielded hardware and software systems to determine impacts on system cybersecurity accreditation for in-service systems and increments.
Conduct analyses such as trend analyses to support cybersecurity efforts.
Updates and maintains Cyber Security (CS) Strategy documentation that is compliant with DoD CS policies and regulations including the Risk Management Framework (RMF) processes. Specifically, TacMobile products that need to renew legacy system Authority to Operate certifications (ATOs) and obtain new increment accreditation (ATO).
Aids operational sites with analysis and preparation of items related to the Command Cybersecurity Operational Readiness Inspections (CCORls). This includes identifying and assisting with gaps in TacMobile ISEA documentation and Operational site's policies, instructions, and Standard Operating Procedures (SOPs).
Conducts Cyber Assist Visits (CAVs) with all TacMobile operational sites. CAV is a mid term effort to provide training and assistance to improve TOC/MTOC self-sufficiency in assessing cyber posture and taking appropriate actions to harden it. It is based on the site's evaluation under a CCORI.
Assist the Cyber APM with TacMobile cybersecurity tasks, data calls, or RFls as needed.
EEO Commitment:
Titanium Cobra Solutions is proud to be an equal opportunity employer, seeking to create a welcoming and diverse environment. All qualified applicants will receive consideration for employment without regard to race, color, religion, gender, gender identity or expression, sexual orientation, national origin, ancestry, physical or mental disability, medical condition, marital status, genetics, age, or veteran status or any other applicable legally protected status or characteristic.