Job Description
As a Cybersecurity Engineer (System Steward) your expertise will be utilized to identify and minimize cybersecurity risks for the Department of Veterans Affairs (VA). You will be responsible for implementing policies that address requests for information on cyber best practices, assessing risks, supporting Authority to Operate (ATO) activities throughout the NIST Risk Management Framework (RMF) certification/accreditation processes (Steps 1-7), and providing expert guidance on information system security to maintain optimal operational security posture. Your role will involve meticulous system documentation and updates, close collaboration with system administrators, developers, system owners, and Information System Security Officers (ISSO) for ATO support, and translating security concepts into practical recommendations to assist the client in making well-informed security decisions.
The candidate will provide expert communication and consultative support to the VA on matters related to system security certification & accreditation and Authority to Operate (ATO), using Risk Management Framework (RMF). They will have experience in and Technical knowledge of Network and Software Development and experience in the creation of Security-Specific documentation such as Incident Response, Contingency Planning, and Disaster Recovery processes.
The candidate should be familiar with the security controls outlined by the National Institute of Standards and Technology (NIST), as well as the Governance, Risk Management Framework (RMF), and security compliance procedures (GRC) and skilled in providing support for system Authority to Operate (ATO) processes, including the creation of artifacts, implementation of controls, and development of Plan of Action & Milestones (POAM).
About VetsEZ
VetsEZ is seeking a Cybersecurity Engineer to identify and minimize cybersecurity risks for the Department of Veterans Affairs (VA).