SCA 1 102-098 | | | | Security Control Assessor (SCA) 1- This is a future position that may come open in the future. We are currently building our pipeline.
Responsible for conducting a comprehensive assessment of the management, operational, and technical security controls employed within or inherited by an Information System (IS) to determine the overall effectiveness of the controls (i.e., the extent to which the controls are implemented correctly, operating as intended, and producing the desired outcome with respect to meeting the security requirements for the system). SCAs also provide an assessment of the severity of weaknesses or deficiencies discovered in the IS and its environment of operation and recommend corrective actions to address identified vulnerabilities. Responsibilities will cover Collateral, Sensitive Compartmented Information (SCI) and Special Access Program (SAP) activities within the customer’s area of responsibility.
Performance shall include:
Perform oversight of the development, implementation and evaluation of IS security program policy; special emphasis placed upon integration of existing SAP network infrastructure
Perform assessment of ISs, based upon the Risk Management Framework (RMF) methodology in accordance with the Joint SAP Implementation Guide (JSIG)
Advise the IS Owner (ISO), Information Data Owner, Program Security
Officer, and the Delegated and/or Authorizing Official (DAO/AO) on any assessment and authorization issues
Evaluate Authorization packages and make recommendation to the AO and/or DAO for authorization
Evaluate IS threats and vulnerabilities to determine whether additional safeguards are required
Advise the Government concerning the impact levels for Confidentiality, Integrity, and Availability for the information on a system
Ensure security assessments are completed and results documented and prepare the Security Assessment Report (SAR) for the Authorization boundary
Initiate a Plan of Action and Milestones with identified weaknesses for each Authorization Boundaries assessed, based on findings and recommendations from the SAR
Evaluate security assessment documentation and provide written recommendations for security authorization to the Government
Discuss recommendation for authorization and submit the security authorization package to the AO/DAO
Assess proposed changes to Authorization boundaries operating environment and mission needs to determine the continuation to operate.
Review and concur with all sanitization and clearing procedures in accordance with Government guidance and/or policy
Assist the Government compliance inspections
Assist the Government with security incidents that relate to cybersecurity and ensure that the proper and corrective measures have been taken
Ensure organization are addressing and conducting all phases of the system development life cycle
Evaluate Hardware and Software to determine security impact that it might have on Authorization boundaries
Evaluate the effectiveness and implementation of Continuous Monitoring Plans
Represent the customer on inspection teams
Required Education and Experience:
Bachelor's degree
5-7 years related experience
3+ years experience in SAP, SCI, or Collateral IS and implementation of regulations
Prior performance in role of ISSO and ISSM
DESIRED: SAP experience
Training:
Security Clearance:
IC-CAP provides equal employment opportunities (EEO) to all applicants for employment without regard to race, color, religion, gender, sexual orientation, gender identity or expression, national origin, age, disability, genetic information, marital status. | |
ISSO 2 102-096 | | | | Information System Security Officer (ISSO) 2 is responsible for ensuring the appropriate operational security posture is maintained for an information system and as such, works in close collaboration with the ISSM and ISO. The position shall have the detailed knowledge and expertise required to manage the security aspects of an information system and, in many organizations, is assigned responsibility for the day-to-day security operations of a system. This also will include physical and environmental protection, personnel security, incident handling, and security training and awareness. It will be required to work in close coordination with the ISSM and ISO in monitoring the information system(s) and its environment of operation to include developing and updating the authorization documentation, implementing configuration management across authorization boundaries. This will include assessing the security impact of those changes and making recommendation to the ISSM. The primary function is working within Special Access Programs (SAP) supporting Department of Defense agencies, such as HQ Air Force, Office of the Secretary of Defense and Military Compartments efforts. The position will provide “day-to-day” support for Collateral, Sensitive Compartmented Information and SAP activities.
Duties may include:
Assist the ISSM in meeting their duties and responsibilities
Prepare, review, and update authorization packages
Ensure approved procedures are in place for clearing, sanitizing, and destroying various types of hardware and media
Notify ISSM when changes occur that might affect the authorization determination of the information system(s)
Conduct periodic reviews of information systems to ensure compliance with the security authorization package.
Coordinate any changes or modifications to hardware, software, or firmware of a system with the ISSM and AO/DAO prior to the change
Monitor system recovery processes to ensure security features and procedures are properly restored and functioning correctly
Ensure all IS security-related documentation is current and accessible to properly authorized individuals
Ensure audit records are collected, reviewed, and documented (to include any anomalies)
Attend required technical and security training (e.g., operating system, networking, security management) relative to assigned duties
Execute the cyber security portion of the self-inspection, to include provide security coordination and review of all system assessment plans
Identify cyber security vulnerabilities and assist with the implementation of the countermeasures for them
Prepare reports on the status of security safeguards applied to computer systems
Perform ISSO duties in support of in-house and external customers
Conduct security impact analysis activities and provide to the ISSM on all configuration management changes to the authorization boundaries.
Required Education and Experience:
Bachelor's degree AND 2-5 years related experience -OR- 6-9 years of relevant additional experience in lieu of degree
Experience in developing RMF packages or bodies of evidence
Prior performance in roles such as System/Network Administrator or ISSO
SAP experience
Training:
Security Clearance:
IC-CAP provides equal employment opportunities (EEO) to all applicants for employment without regard to race, color, religion, gender, sexual orientation, gender identity or expression, national origin, age, disability, genetic information, marital status. | |
Lead Integrator (Expert) 112-130 | | | 09/05/2024 | Lead Integrator (Expert) provides integration support to the Government and coordinates contract
engineering activities across organizational boundaries for system/capability development or
modification efforts. They lead enterprise planning of engineering and integration activities and
perform issue resolution. The Lead Integrator works directly with Government Office/Division
Chiefs to prioritize work assignments and align the necessary resources to execute tasks.
Duties include:
Assists Government Office/Division Chiefs in assessing, documenting, and tracking new
engineering requirements and facilitating technical exchange meetings (TEMs) used to inform
Government and Contractor teams about systems engineering and integration activities.
Supports the Government in resource planning, coordination and analysis.
Coordinates project schedules to support defined strategic effectivities.
Plans major systems engineering Program Reviews and Control Gate Reviews including scheduling of meetings and preparation of briefings/presentations.
Assists in the preparation of documents, records, forms, reports, and plans covering systems engineering and integration activities.
Provide change management oversight, to plan resource alignment, identify priority adjustments, and identify needed skillsets.
Education and Experience:
Required
18+ years' experience.
Masters’ degree in Engineering, Computer Science, Information Technology, Management Information Systems, or related STEM degree program, or equivalent Expert level work experience as a Lead Integrator.
Expert experience in engineering, design and analysis of IT or related systems experience in all
phases of design, development, analysis and documentation, and development of standards and
guidelines for tasks being performed.
Expert-level working experience in government or industry in DoD/IC Acquisition Process or PPBES.
Education and Experience:
Desired
Working knowledge of Model Based Systems Engineering, processes, tools and languages.
Software Development Framework certification.
Experience Integrating solutions using Cloud-based technologies.
Experience Integrating solutions using structured and unstructured Big Data.
Experience Integrating solutions using Automation, Augmentation and Artificial Intelligence technologies.
Experience with and strong understanding of systems engineering lifecycle.
Security Clearance:
IC-CAP provides equal employment opportunities (EEO) to all applicants for employment without regard to race, color, religion, gender, sexual orientation, gender identity or expression, national origin, age, disability, genetic information, marital status. | |
PSR 2 102-093 | | | 03/30/2024 | Program Security Representative (PSR) II - This is a future position that may come open in the future. We are currently building our pipeline.
The primary function of the PSR II is to provide multi-discipline security support for one or more of the customer’s Special Access Programs (SAP). The position will provide “day-to-day” multi-discipline analysis for Collateral, Sensitive Compartmented Information (SCI) and SAP activities.
Duties May include:
Ensure strict adherence to the provisions of the NISPOM, its Supplement, the DoD Overprint, DCID, ICD, and SAP policy
Assist in developing and executing approved policies and procedures for safeguarding SAP, SCI and collateral data in support of US military operations
Provide day-to-day security support that includes continuous assessment of procedures to identify shortfalls and provide appropriate recommendations for revising and improving security policies, procedures, and systems
Identify vulnerabilities, threats, and risks to test, training, and operational activities
Assist in developing, implementing, and training the Operations Security program
Assist in providing contractor and subordinate facility assistance and oversight
Brief all levels of personnel, both in the government and senior civilian services, on a variety of security related topics
Conduct and document SAP facility compliance reviews, follow-on facility reviews, and facility close outs
Monitor, report and track all corrective actions resulting from compliance reviews
Ensure timely notification of pertinent security matters to program technical and management staff
Conduct exploration of any loss, compromise, or suspected compromise of classified and/or sensitive information, including conducting preliminary inquiries and generating damage assessments resulting from the loss of classified information.
Coordinate with SAP security personnel to ensure lessons learned are incorporated into the curriculum for the SAP security education & awareness program.
Education and Experience
Required:
Bachelor's degree AND 8-10 years of related experience (Security Fundamentals Professional Certification (SFPC) counts towards no more than 5 years of experience)
12-14 years of related experience in lieu of degree
SAP experience
Training:
Security Clearance:
IC-CAP provides equal employment opportunities (EEO) to all applicants for employment without regard to race, color, religion, gender, sexual orientation, gender identity or expression, national origin, age, disability, genetic information, marital status. | |
Senior Systems Engineer 112-129 | | | 03/29/2024 | Sr. Systems Engineer guides engineering teams in taking a multi-discipline approach to requirements engineering, solutions engineering, scheduling, reliability, resiliency, services development, integration, test and evaluation, maintainability and analysis across the National System of Geospatial-intelligence (NSG), Allied System of Geospatial-intelligence (ASG) and Federal Agencies to ensure timely and accurate GEOINT.
Duties may include:
Guides Mid-level and Junior-level system engineers performing requirements engineering, solutions engineering, scheduling, reliability, resiliency, services development, integration, test and evaluation, maintainability and analysis across the National System of Geospatial-intelligence (NSG), Allied System of Geospatial-intelligence (ASG) and Federal Agencies.
Guides the planning, analysis/traceability of user requirements, architectures traceability, procedures, and problems to automate or improve existing systems and review cloud service capabilities, workflow, and scheduling limitations.
Guides Mid-level and Junior-level system engineers developing solutions designs based on analysis of requirements and new technology.
Assists the Government in the capture and translation of mission and customer requirements/needs into systems/capability requirements and solutions.
Supports the analyses and allocation of requirements to systems architecture components and executing programs.
Assists the Government in performing systems integration activities.
Conducts Analysis of Alternatives (AoAs), Course of Actions (CoAs), Trade Studies, and Engineering Assessments.
Assists the Government in strategic technical planning, project management, performance engineering, risk management and interface design.
Operates at the level of integrating multiple systems, services, processes, and interfaces within a Major Systems Acquisitions across organizational and agency boundaries.
Ability to solve complex problems, lead a team(s) and work independently and proactively with minimal supervision.
Education and Experience
Required:
Bachelor’s degree or higher in Systems Engineering or in a related STEM degree program, or an additional 4 years of Senior-Level Systems Engineer work experience
12-18 years of experience
Senior-level experience in government or industry in relevant work areas including: DoD/IC Acquisition Process, Requirements Process, PPBES Process or system engineering of large complex System of Systems or Service Oriented Architecture/Cloud environments.
Experience with and strong understanding of systems engineering lifecycle.
Experience communicating and collaborating both within and external to organization, to include with senior executives and leaders.
Desired:
Master’s degree in Systems Engineering or in a related STEM degree program.
Working knowledge of Model Based Systems Engineering, processes, tools and languages.
Working knowledge of Software Development Frameworks.
INCOSE Certified System Engineering Professional (CSEP) certification.
Experience in the field of geospatial intelligence.
Licensure as a professional engineer.
Membership or leadership participation in any of the following professional organizations: ACSM, ASCE, ASPRS, OGC, SAREM, or USGIF.
Demonstrated knowledge in photogrammetry, remote sensing, image science, information sciences, geographic information systems, geomatics, or related fields.
Demonstrated knowledge of the current NSG/ASG and NRO enterprises.
Security Clearance:
IC-CAP provides equal employment opportunities (EEO) to all applicants for employment without regard to race, color, religion, gender, sexual orientation, gender identity or expression, national origin, age, disability, genetic information, marital status. | |
Net-Sys Admin 1 102-091 | | | | Network-System Administrator (Net-Sys Admin) 1's primary function will be to organize, install, and support government organization’s computer systems, including local area networks (LANs), wide area networks (WANs), network segments, intranets, and other data communication systems. This will also include helping architect, design and analyze network models. It will require participation in decisions about buying future hardware or software to upgrade organization’s infrastructure. This position might be called upon to provide technical support to computer users to help solve user problems. This position will support activities within Special Access Programs (SAP) supporting Department of Defense agencies, such as HQ Air Force, Office of the Secretary of Defense and Military Compartments efforts. The position will provide “day-to-day” support for Collateral, Sensitive Compartmented Information (SCI) and SAP activities.
Duties may include:
Ability to operate under supervision
Execute day to day management and operations of systems and networks
Manage COTS & GOTS products to collect, display and remediate a variety of automated system security and system operations/performance functions and metrics
Follow Operations and Maintenance (O&M) checklists to maintain the service (daily, weekly, monthly, yearly O&M checklists); build Tactics, Techniques and Processes (TTPs) and Standard Operating Processes (SOPs) associated with service checklists
Operate monitoring tools/capabilities with the enterprise Security Information and Event Management (SIEM) and create/tailor complex event alarms/rules and summary reports
Assist in analyzing technical risk, upon request, of emerging cybersecurity tools and processes
Work as part of a security incident response team as needed
Working technical competency in one or more of the following supported platforms: Microsoft Windows Server, Red Hat Enterprise Linux servers, MS Hyper-V/VMWare/ESx/Xen Hypervisors, Enterprise networking/firewalls/intrusion detection/prevention systems, forensic analysis/vulnerability assessment, Group Policy management and configuration, Scripting, BMC Footprints, WSUS, , Lumension, Bitlocker, SQL Server 2012, TomCat, IIS, Windows Server2012r2/2016, Win 10, Red Hat 6.5, Microsoft Office Toolkits, SEIMs, Logrhythm, ACAS/Nessus/SCAP, mandatory/role-based access control concepts (e.g. SE Linux extensions to RHEL, PitBull, AppArmor, and Sentris) , video teleconferencing/VOIP, Oracle/MS SQL database security, and Apache/IIS Web server security
Education and Experience
Required:
Training:
Security Clearance:
IC-CAP provides equal employment opportunities (EEO) to all applicants for employment without regard to race, color, religion, gender, sexual orientation, gender identity or expression, national origin, age, disability, genetic information, marital status. | |
SME Instructor GEOINT Analysis Level 1 106-003 | Springfield, VA or St. Louis, MO | | 07/29/2024 | We are primarily sourcing level 2 Candidates but will consider level 1 Candidates.
SME Instructor GEOINT Analysis Level 1 delivers in-resident and distributed learning instructional programs in accordance with course requirements at the NGA College. Uses instructional methods such as guided discussions, lectures, demonstrations, small group exercises, seminars, workshops, and laboratories. Uses instructional technology, including but not limited to Blackboard. Conducts assessment strategy in accordance with the course design, including instructor observation, testing, and grading. Provides formal and informal student feedback. Provides subject matter expertise throughout the curriculum creation process, including content review and feedback to development staff. Relevant instructional experience includes, but is not limited to, developing and delivering technical training and educational courses in academic, commercial, government, or industrial organizations. Relevant SME experience includes, but is not limited to, experience in technical field as described in the Instructor technical competency requirements by Work Role.
Work Role:
Desired degree(s) in one of the following; Geography, Geodetic Science, Geospatial Intelligence, Spatial Statistics, or a related discipline
Possess documented experience within the last 36 months as Geospatial Analyst that has created, analyzed, and interpreted spatial data. The Candidate will apply their knowledge of geographic information science and technology, statistics, spatial thinking, remote sensing, intelligence issues and social and physical science to characterize events, discover relationships and trends, and produce geospatial products
Possess a working knowledge of the application of Geographic Information Systems (GIS) and analysis of geospatial data to solve intelligence problems that may face the DoD or the Intelligence Community
Demonstrated fundamental knowledge of the principles and applications of imagery interpretation, digital image processing systems, collections, and sensor phenomenology
Demonstrated strong working knowledge of ESRI GIS software and extensions and NGA, DoD, Federal, and Commercial data sources, standards, and models
Demonstrated experience maintaining a database
Demonstrated experience creating, editing, reviewing, and responding to Requests for Information
For deployment teaching deployer training instructors, requires documented experience supporting a GEOINT mission within the past 24 months. May require additional documented experience directly supporting the NGA mission at a site external to customer base (e.g., OCO-related deployment, Disaster/Humanitarian Relief support, etc.) within the past 24 months of RFP release date.)
Job Requirements:
Demonstrated strong working knowledge of ESRI GIS software and extensions and NGA, DoD, Federal, and Commercial data sources, standards, and models
Experience with the application of GIS and analysis of geospatial data to solve intelligence problems that may face the DoD or the Intelligence Community
Demonstrated fundamental knowledge of the principles and applications of imagery interpretation, digital image processing systems, collections, and sensor phenomenology
Demonstrated experience maintaining a database
Desired Qualifications:
Activity-Based Intelligence (ABI) experience
Overhead Persistent Infrared (OPIR): Aside from a background in Imagery Science and specifically with OPIR, familiarity with OATS, FADE MIST, and ArcGIS would be helpful, but not all are required
Pre-Deployment: Apply and understand specific requirements to prepare deployers in assessing threats, situational awareness, and criminal activity while working in high-threat regions. Candidate may have experience as a GEOINT or Imagery Analyst and hopefully have experience in deployment environments. Also, candidate needs to be familiar with ArcGIS, QGIS, or equivalent GIS systems, GRiD, RemoteView, SOCET GXP, and QT Modeler
Level 1 Experience:
Bachelor’s degree in area of expertise plus three years of experience; or six years of relevant experience. The expertise must align with work role.
Desired Minimum Instructional Experience: Three (3) years of relevant instructor experience.
Level 2 Experience:
Master’s degree in area of expertise plus 3 years of relevant experience; or bachelor’s degree in area of expertise plus 5 years of relevant experience; or 20 years of relevant experience
Desired Minimum Teaching Experience: Four (4) years of relevant instructor experience
Security Clearance:
IC-CAP provides equal employment opportunities (EEO) to all applicants for employment without regard to race, color, religion, gender, sexual orientation, gender identity or expression, national origin, age, disability, genetic information, marital status | |
ISSE 3 102-090 | | | | Information System Security Engineer (ISSE) 3 is primarily responsible for conducting information system security engineering activities with a focus on lifecycle of current systems and future requirement scoping. The position will collect and process the captured information security requirements and ensures that the requirements are effectively integrated into information systems through purposeful security architecting, design, development, and configuration. The position is an integral part of the development team designing and developing organizational information systems or upgrading legacy systems. The ISSE employs best practices when implementing security requirements within an information system including software engineering methodologies, system/security engineering principles, secure design, secure architecture, and secure coding techniques. This position’s main function is working within Special Access Programs (SAP) supporting Department of Defense (DoD) agencies, such as HQ Air Force, Office of the Secretary of Defense and Military Compartments efforts. The position will provide “day-to-day” support for Collateral, Sensitive Compartmented Information (SCI) and SAP activities.
Duties may include:
Perform oversight of the development, implementation and evaluation of information system security program policy; special emphasis placed upon integration of existing SAP network infrastructures
Perform analysis of network security, based upon the Risk Management Framework (RMF) with emphasize on Joint Special Access Program Implementation Guide (JSIG) authorization process
Provides expert support, research and analysis of exceptionally complex problems, and processes relating to them
Provides expert level consultation and technical services on all aspects of Information Security Serves as technical expert to the Cybersecurity Assessment Program providing technical direction, interpretation and alternatives to complex problems
Builds IA into systems deployed to operational environments
Assists architects and systems developers in the identification and implementation of appropriate information security functionality to ensure uniform application of DoD and other agencies security policy and enterprise solutions
Enforce the design and implementation of trusted relations among external systems and architectures.
Assesses and mitigates system security threats/risks throughout the program life cycle Contributes to the security planning, assessment, risk analysis, risk management, certification and awareness activities for system and networking operations
Thinks independently and demonstrates exceptional written and oral communications skills. Applies advanced technical principles, theories, and concepts
Contributes to the development of new principles, concepts, and methodologies
Works on unusually complex technical problems and provides highly innovative and ingenious solutions
Lead a team of System Security Engineers and Certification and Accreditation Analysts responsible for ensuring the customers national and international security interests are protected as support equipment are designed and tested
Recommends cybersecurity software tools and assists in the development of software tool requirements and selection criteria to include the development of product specific STIGs from applicable DISA SRGs
Review ISSE related designs and provides security compliance recommendations
Leads technical teams in implementation of predetermined long-range goals and objectives
Supports customer and SAP community IA working groups, participate in SSE IPT reviews
Provides expert level consultation and technical services on all aspects of Information Security
Review ISSE related designs and provides security compliance recommendations
Develop and provide IA risk management recommendations to the customer
Provide ISSE support for Mission and Training systems design and development
Assist with development and maintenance of the Program Protection Plan
Assist with site activation activities and design reviews
Represent the customer in various ISSE related working groups, advisory groups, and advisory council meetings
Chair and or Co-Chair customer and SAP community IA working groups, participate in ISSE IPT reviews
Represent the customer in various SSE related working groups, advisory groups, and advisory council meetings
Strong background in Patch/Configuration management, DevOps, and tier 3 support
Assist team to design, integrate, and implement JSIG/RMF Continuous Monitoring tools and processes
Integrate COTS & GOTS products to collect, display and remediate a variety of automated system security and system operations/performance functions and metrics
Perform security assessments of servers/network devices/security appliances
Develop improvements to security assessments with regard to accuracy and efficiency
Integrate ancillary monitoring tools/capabilities with the enterprise security information and event management (SIEM) and create/tailor complex event alarms/rules and summary reports
Write and execute cybersecurity test procedures for validation of control compliance
Monitor/analyze output of cybersecurity related tools for reportable security incidents and residual risk
Analyze technical risk of emerging cybersecurity tools and processes
Work as part of a security incident response team as needed
Build operational Operations and Maintenance (O&M) checklists to maintain the service (daily, weekly, monthly, yearly O&M checklists); build Tactics, Techniques and Processes and Standard Operating Processes associated with service checklists
Integrate/Develop new techniques to improve Confidentiality, Integrity, and Availability for networks/systems operating at various classification levels
Advanced technical competency in one or more of the following supported platforms: Microsoft Windows Server, Active Directory, Red Hat Enterprise Linux servers, MS Hyper-V/VMWare/ESx/Xen Hypervisors, Enterprise networking/firewalls/intrusion detection/prevention systems, forensic analysis/vulnerability assessment, Group Policy management and configuration, Scripting, BMC Footprints, WSUS, , Lumension, Bitlocker, SQL Server 2012, TomCat, IIS, Windows Server 2012r2/2016, Win 10, Red Hat 6.5, Microsoft Office Toolkits, SEIMs, Logrhythm, ACAS/Nessus/SCAP, mandatory/role-based access control concepts (e.g. SE Linux extensions to RHEL, PitBull, AppArmor, and Sentris), video teleconferencing/VOIP, Oracle/MS SQL database security, and Apache/IIS Web server security.
Education and Experience:
Bachelor's degree -or- 4 years of additional, relevant experience, in lieu of degree
15 of years experience; with prior performance in roles such as ISSO, ISSM, SCA, or SAP IT Technical Director
SAP experience
Training:
Security Clearance:
IC-CAP provides equal employment opportunities (EEO) to all applicants for employment without regard to race, color, religion, gender, sexual orientation, gender identity or expression, national origin, age, disability, genetic information, marital status. | |
PSR 2 102-088 | | | | Program Security Representative 2’s primary function is to provide multi-discipline security support for one or more of the customer’s Special Access Programs (SAPs). The position will provide “day-to-day” multi-discipline analysis for Collateral, Sensitive Compartmented Information (SCI) and Special Access Program (SAP) activities.
Performance shall include:
Ensure strict adherence to the provisions of the NISPOM, its Supplement, the DoD Overprint, DCID, ICD, and SAP policy
Assist in developing and executing approved policies and procedures for safeguarding Special Access
Program (SAP), Sensitive Compartmented Information (SCI) and collateral data in support of US military operations
Provide day-to-day security support that includes continuous assessment of procedures to identify shortfalls and provide appropriate recommendations for revising and improving security policies, procedures, and systems
Identify vulnerabilities, threats, and risks to test, training, and operational activities
Assist in developing, implementing, and training the Operations Security program
Assist in providing contractor and subordinate facility assistance and oversight
Brief all levels of personnel, both in the government and senior civilian services, on a variety of security related topics
Conduct and document SAP facility compliance reviews, follow-on facility reviews, and facility close-outs
Monitor, report and track all corrective actions resulting from compliance reviews
Ensure timely notification of pertinent security matters to program technical and management staff
Conduct exploration of any loss, compromise, or suspected compromise of classified and/or sensitive information, including conducting preliminary inquiries and generating damage assessments resulting from the loss of classified information.
Coordinate with SAP security personnel to ensure lessons learned are incorporated into the curriculum for the SAP security education & awareness program.
Education and Experience:
Security Clearance:
IC-CAP provides equal employment opportunities (EEO) to all applicants for employment without regard to race, color, religion, gender, sexual orientation, gender identity or expression, national origin, age, disability, genetic information, marital status. | |
Database Administrator (Senior) 112-128 | | | 08/13/2024 | Database Administrator (Senior) assists in leading the Foundation GEOINT Standards (FGS) database management and FGS-DPS Cloud buildout to include database migration, edits, report generations and database administration, API integration with the user interface (UI) development.
Duties include:
Assist in leading the Source Foundation GEOINT (SF) Standards Team in the role of building, maintaining useable database environment and structure to support the enhancement and maintenance of cloud based applications.
Assist the customer in defining and shaping the FGS cloud based, DevOps strategic vision and buildout of SF symbology data-driven online presence using Continuous Integration/ Deployment (CI/CD) DevOps technologies.
Strong team player, self-starter, comfortable working in a complex/multifaceted development environment
Attend and contribute to the Defense Geospatial Information Working Group (DGIWG) technical meeting, an international Symbology Standards forum.
Ability to work independently and as a team leader under tight deadlines managing priorities
Ensure connectivity between application programing interface (APIs) both internal and external
Demonstrated ability to work in a multi-contractor / government organization
Ability to work with international partners, travelling to meet face-to-face when necessary but also able to work well via email and teleconference.
Provide expertise to interpret and implement customer data requirements
Maintain and track an Agile schedule in an appropriate project management capability (Redmine, JIRA, etc.)
Education and Experience:
Required
12 to 18 years' experience
Bachelor’s degree or higher IT, Computer Science or relevant field plus 6 +years’ experience to include 2+ years of Database Administration, System Engineering, System Integration, and/or Web Development experience, or equivalent Senior Level work experience as a Database Administrator.
12 + years of experience in related field, with 3 year of recent NGA/IC experience
Proficient in Linux, MySQL/PostGRES/ Relational Database, PHP/Python (LAMP)
Experience with HTML5, JavaScript, SQL
Experience:
Desired
Experience and knowledge of the NGA/DGIWG Data Product Specifications
Understanding of the Global, Regional, Local and Urban/Specialized (GRLS) topographic data stores
Experience with cloud-based or DevOps environment and/or open source capabilities (GitLab, Pivotal Cloud Foundry (PCF), Jenkins, AWS (Amazon Web Service) technologies, etc.)
Familiarity with Cloud Services (Platform as a Service, Database as a Service, etc.)
Knowledge of the NSG, preferably experience providing systems engineering to high visibility NSG segments.
Security Clearance:
IC-CAP provides equal employment opportunities (EEO) to all applicants for employment without regard to race, color, religion, gender, sexual orientation, gender identity or expression, national origin, age, disability, genetic information, marital status. | |
SCA 2 102-086 | | | 05/24/2024 | Security Control Assessor (SCA) 2 is responsible for conducting a comprehensive assessment of the management, operational, and technical security controls employed within or inherited by an IS to determine the overall effectiveness of the controls (i.e., the extent to which the controls are implemented correctly, operating as intended, and producing the desired outcome with respect to meeting the security requirements for the system). SCAs also provide an assessment of the severity of weaknesses or deficiencies discovered in the IS and its environment of operation and recommend corrective actions to address identified vulnerabilities. Responsibilities will cover Collateral, Sensitive Compartmented Information (SCI) and Special Access Program (SAP) activities within the customer’s area of responsibility.
Performance shall include:
Perform oversight of the development, implementation and evaluation of IS security program policy; special emphasis placed upon integration of existing SAP network infrastructure
Perform assessment of ISs, based upon the Risk Management Framework (RMF) methodology in accordance with the Joint Special Access Program (SAP) Implementation Guide (JSIG)
Advise the Information System Owner (ISO), Information Data Owner (IDO), Program Security
Officer (PSO), and the Delegated and/or Authorizing Official (DAO/AO) on any assessment and authorization issues
Evaluate Authorization packages and make recommendation to the AO and/or DAO for authorization
Evaluate IS threats and vulnerabilities to determine whether additional safeguards are required
Advise the Government concerning the impact levels for Confidentiality, Integrity, and Availability for the information on a system
Ensure security assessments are completed and results documented and prepare the Security Assessment Report (SAR) for the Authorization boundary
Initiate a Plan of Action and Milestones (POA&M) with identified weaknesses for each Authorization Boundaries assessed, based on findings and recommendations from the SAR
Evaluate security assessment documentation and provide written recommendations for security authorization to the Government
Discuss recommendation for authorization and submit the security authorization package to the AO/DAO
Assess proposed changes to Authorization boundaries operating environment and mission needs to determine the continuation to operate.
Review and concur with all sanitization and clearing procedures in accordance with Government guidance and/or policy
Assist the Government compliance inspections
Assist the Government with security incidents that relate to cybersecurity and ensure that the proper and corrective measures have been taken
Ensure organization are addressing and conducting all phases of the system development life cycle (SDLC)
Evaluate Hardware and Software to determine security impact that it might have on Authorization boundaries
Evaluate the effectiveness and implementation of Continuous Monitoring Plans
Represent the customer on inspection teams.
Education and Experience:
Bachelor's degree
7-9 years related experience; 4+ years experience in SAP, SCI, or Collateral Information Systems (S) security and implentation of regulations identified in the description of duties; Prior performance in the role of ISSO and ISSM or SCA
Training and Certifications:
Security Clearance:
IC-CAP provides equal employment opportunities (EEO) to all applicants for employment without regard to race, color, religion, gender, sexual orientation, gender identity or expression, national origin, age, disability, genetic information, marital status. | |
Senior Technology Advisor - Security Operations Center (SOC) 104-040 | Colorado Springs, CO or Bolling AFB, Washington DC and Reston, VA | | 07/08/2024 | Senior Technology Advisor - Security Operations Center (SOC) with diverse experience in information technology and cybersecurity to join our esteemed Security Operations Center (SOC) team. This role will be responsible for providing strategic guidance, conducting research, and authoring thought-leading whitepapers on emerging technologies while identifying innovative service improvement opportunities within the organization's security landscape. The successful candidate will have a proven track record of staying abreast of industry trends and best practices to ensure optimal security posture.
Level 4:
Responsible for providing business and technical architectural guidance to development teams, business groups, and customers for existing and new products and services.
Identifies solutions based on business and technical criteria, analyzes alternatives based on trade space, and implements designs.
Researches current and emerging technologies and process methodologies and proposes changes and tailoring where needed.
Assesses the system and business process architectures currently in place and works with staff to recommend improvements.
Ensures technical architecture teams deliver efficient and effective system solutions to support business goals and objectives.
Develops, enhances, and maintains established service design procedure and process by applying process frameworks and methodologies.
Prepares and presents test plan, technical presentations, and analyst briefings.
Identifies customer requirements, analyzes alternatives, and conducts product recommendations related to software, platform, and network configurations.
Provides updates to stakeholders on project cost, schedule, and quality in comparison to stakeholder objectives.
Responsibilities:
Strategic Advising: Serve as a trusted advisor to senior management, business units, and other stakeholders by offering recommendations on IT and cybersecurity strategies, policies, and procedures that align with organizational objectives.
Research & Analysis: Conduct in-depth analysis and research on cutting-edge technologies, industry trends, and best practices to inform decision-making processes related to security operations.
Whitepaper Authoring: Develop well-researched, insightful, and engaging whitepapers addressing various aspects of IT and cybersecurity, such as threat intelligence, incident response, risk assessment, and compliance.
Service Improvement Identification: Continuously identify, assess, and recommend new or improved services to enhance the overall efficiency, effectiveness, and security of the organization's IT infrastructure.
Mentorship & Collaboration: Actively mentor junior members of the SOC team and the Analysis Support Team (AST), fostering a culture of continuous learning and professional growth. Work closely with cross-functional teams across the organization to promote knowledge sharing and collaboration.
Training & Education: Plan, develop, and deliver training programs and workshops for staff at all levels to improve their understanding of current and evolving cybersecurity threats, tools, and best practices.
Vendor Evaluation: Assess potential vendors, partners, and solutions providers to ensure alignment with the organization's security needs and goals.
Incident Response Planning: Contribute to the development of comprehensive incident response plans, playbooks, and procedures to minimize the impact of security incidents.
Reporting & Metrics: Analyze data from security monitoring systems and other sources to provide regular reports and metrics on key performance indicators, risk mitigation efforts, and return on investment for the SOC team's initiatives.
Requirements Analysis: Perform requirements analysis to help define functional user requirements for all SOC and Task order mission functions.
Required skill and Abilties:
Relevant work experience in Information Technology and Cybersecurity, including roles in SOC, Network/Security Engineering, Threat Intelligence, or similar domains.
Demonstrated expertise in multiple IT disciplines, including network architecture, cloud security, endpoint protection, vulnerability management, identity and access management, and incident response.
Proven ability to analyze complex technical issues and translate them into clear, concise language for non-technical audiences.
Strong written communication skills with a portfolio of published whitepapers or articles showcasing your subject matter expertise.
Aptitude for identifying market trends and emerging technologies with the potential to positively impact the organization's security posture.
Excellent interpersonal and influencing skills with the capacity to build relationships and credibility at all levels within the organization and externally.
Experience managing vendor relationships and evaluating potential partners for IT security products and services.
Ability to travel occasionally for conferences, workshops, and client meetings.
Training and Certifications:
Education and Experience:
Security Clearance:
IC-CAP provides equal employment opportunities (EEO) to all applicants for employment without regard to race, color, religion, gender, sexual orientation, gender identity or expression, national origin, age, disability, genetic information, marital status. | |
Systems Engineer Associate Chief Engineer (ACE) Expert-Level 112-127 | | | 06/07/2024 | Systems Engineer Associate Chief Engineer (ACE) Expert-Level is responsible for overseeing integration of external mission partners within the office. This requires knowledge of the enterprise architecture, specifically the external interfaces, and familiarity with data formats to ensure the mission partner’s data arrives within the office’s architecture and is readily available to our end users. The ACE will provide technical oversight and guidance for all projects related to the external interfaces of the office as well as integrating new sources.
Required Qualifications:
Bachelor’s degree in Systems Engineering, Science, Engineering, or related technical experience field such as engineering, physics, mathematics, operations research, engineering management, Computer Science, Information Technology, Management Information Systems, or related STEM degree program.
18+ years of experience in government or industry in related work, including DoD/IC acquisition process, requirements process, PPBES process or engineering of large complex systems of systems, or SOA/cloud environments.
12+ years of experience with the Systems Engineering Lifecycle.
10+ years of experience with technology insertion, assessment and evaluation.
8+ years of systems engineering experience for GEOINT systems, services and products.
8+ years of experience managing systems interfaces and end-to-end systems integration.
5+ years of project management or team leadership experience.
Security Clearance:
IC-CAP provides equal employment opportunities (EEO) to all applicants for employment without regard to race, color, religion, gender, sexual orientation, gender identity or expression, national origin, age, disability, genetic information, marital status. | |
Joint Target Analyst Mid-Level 113-052 | | | 08/21/2024 | Joint Target Analyst Mid-Level
Mid-Level:
Demonstrates working knowledge of the concepts involved in the specific functions outlined in the specified labor category description.
Demonstrates ability to use logic and systematic approaches to gather, evaluate, and synthesize multiple sources of information.
Demonstrates ability to work semi-independently with oversight and direction.
Demonstrates ability to use logic when evaluating and synthesizing multiple sources of information.
Demonstrates ability interpreting analysis to include, but is not limited to, its meaning, importance, and implications.
Demonstrates ability to defend analytic judgements with sound, logical conclusions and adapt analytic judgments when presented with new information, evolving conditions, or unexpected developments.
Demonstrates ability to produce timely, logical, and concise analytic reports, documents, assessments, studies, and briefing materials in formats including Microsoft Office tools (e.g. Excel, Word, PowerPoint, etc.), electronic / soft copy matrices and / or web-enabled formats.
Demonstrates ability to communicate complex issues clearly in a concise and organized manner both verbally and non-verbally, with strong grammar skills.
Demonstrates proficiency using Microsoft Office tools.
Demonstrates ability to develop structured research including, but not limited to, obtaining, evaluating, organizing, and maintaining information within security and data protocols.
Demonstrates ability to recognize nuances and resolve contradictions and inconsistencies in information.
Demonstrates comprehensive mission knowledge and skills that affirms completion of all developmental training and experiences for the labor category.
Demonstrates ability to work independently with minimal oversight and direction.
Demonstrates ability to collaborate and work with other IC members on information sharing, driving collection, and addressing analytic disputes and conflict resolution.
Demonstrates ability to develop concise, insightful, and comprehensive products for defense intelligence.
Demonstrates ability to lead teams in researching multifaceted or critical problems.
Knowledgeable of and demonstrates ability to apply IC and DoD classification guidelines and procedures.
Demonstrates the ability to communicate understanding from information that may be incomplete, indirect, highly complex, seemingly unrelated, and / or technically advanced.
Demonstrates ability to structure analysis based on trends in reporting and a range of analytic perspectives from other analysts, organizations, and intelligence disciplines.
Provides guidance in selecting, designing, and applying analytic methodologies. Uses argument evaluation and validated analytic methodologies to challenge differing perspectives.
Job Duties:
Develops targets and target systems for joint lethal and / or non-lethal engagements. Develops target nominations, creates database records, and databases target intelligence products.
Produces all-source analytic damage estimates and battle damage assessments and assists with combat assessment requirements. Conducts collateral damage estimation, performs target list management, target strategy development, and provides joint target intelligence support to deliberate and dynamic target engagements. Provides recommendations for target prioritization to achieve commander objectives for plans and operations. Provides database nominations, creates and updates database and uploads TMs into databases.
Provides joint target intelligence (JTI) to include target system analysis, joint target development, target list management, and combat assessment IAW Joint Publication (JP) 3-60, Chairman of the Joint Chief of Staff Instruction (CJCSI) 3121, CJCSI 3122, CJCSI 3160, CJSCI 3370, and CJCSI 3162.
Assists with JTI support to dynamic targeting IAW JP 3-60 and joint target enterprise management, target enterprise management (training, automation, standardization, exercise coordination, and readiness), to United States Cyber Command (USCC)
Commander, the USCC J2, J3, J5, and SJA staffs, and the USCC Components. Develops materials and conducts on-the-job training (OJT) for personnel as required.
Assists with long range planning including writing JTI material for plans and order, and coordinates JTI efforts within USCC and its components, other Combatant Commands, the Joint Staff, the Military Targeting Committee, and the Intelligence Community.
Provides recommended input to Chairman of the Joint Chief of Staff manuals/Instructions and Combatant Command policies.
Submits production requirements, Requests for Information, and intelligence report evaluations.
Produces joint target materials that include, but are not limited to, Target System Analysis
(TSA), Electronic Target Folders (ETFs), target graphics, and Battle Damage Assessments (BDA).
Uses intelligence tools, including Modernized Integrated Database (MIDB) interfaces such as
National Production Workshop (NPW) and Joint Targeting Toolbox (JTT).
Uses a wide-range of all-source intelligence research and analytic tools and techniques to
conduct target systems analysis, target development, and BDA, and to provide recommendations to the J2, J3, J5, and USCC Components to conduct OCO/DCO-RA.
Assists in editing all JTI products for content and clarity in support of the USCC J2, J3 and SJA.
Conducts staff functions, including creating, managing and coordinating responses to formal staff packages, responding to requests as subject matter experts, acting as subject matter experts during operational, planning, and joint targeting meetings, working groups, and coordination boards
Provides oral and written updates to J2, J3, J5, SJA and USCC Component leadership.
Education and Experience:
Required
Mid-Level Three (3) years of experience relevant to the specific labor category with at least a portion of the experience within the last two (2) years and either a Bachelor’s degree or an additional four (4) years of direct experience, for a total of seven (7) years of experience in the specific labor category may be substituted for a Bachelor’s degree.
The ideal Candidate will have:
At least 8 years of experience conducting analysis relevant to the specific labor category with at least a portion of the experience within the last 2 years.
Bachelor's degree in an area related to the labor category from a college or university accredited by an agency recognized by the U.S. Department of Education.
Security Clearance:
IC-CAP provides equal employment opportunities (EEO) to all applicants for employment without regard to race, color, religion, gender, sexual orientation, gender identity or expression, national origin, age, disability, genetic information, marital status. | |
ISSM 2 102-085 | | | | Information System Security Manager (ISSM) 2’s primary function serves as a principal advisor on all matters, technical and otherwise, involving the security of information systems under their purview. Primary support will be working within Special Access Programs (SAP) supporting Department of Defense (DoD) agencies, such as HQ Air Force, Office of the Secretary of Defense, and Military Compartment efforts. The position will provide “day-to-day”
support for Collateral, Sensitive Compartmented Information (SCI) and SAP activities.
Performance shall include:
Perform oversight of the development, implementation and evaluation of information system security program policy; special emphasis placed upon integration of existing SAP network infrastructures
Develop and oversee operational information systems security implementation policy and guidelines of network security, based upon the Risk Management Framework (RMF) with emphasize on Joint SAP Implementation Guide (JSIG) authorization process
Advise customer on RMF assessment and authorization issues
Perform risk assessments and make recommendations to DoD agency customers
Advise government program managers on security testing methodologies and processes
Evaluate authorization documentation and provide written recommendations for authorization to government PMs
Develop and maintain a formal Information Systems Security Program
Ensure that all IAOs, network administrators, and other cyber security personnel receive the necessary technical and security training to carry out their duties
Develop, review, endorse, and recommend action by the AO or DAO of system assessment documentation
Ensure approved procedures are in place for clearing, sanitizing, and destroying various types of hardware and media
Develop and execute security assessment plans that include verification that the features and assurances required for each protection level functioning
Maintain a and/or applicable repository for all system authorization documentation and modifications
Institute and implement a Configuration Control Board (CCB) charter
Develop policies and procedures for responding to security incidents, to include investigating and reporting security violations and incidents
Ensure proper protection or corrective measures have been taken when an incident or vulnerability has been discovered within a system
Ensure that data ownership and responsibilities are established for each authorization boundary, to include accountability, access rights, and special handling requirements
Ensure development and implementation of an information security education, training, and awareness program, to include attending, monitoring, and presenting local cyber security training.
Evaluate threats and vulnerabilities to ascertain whether additional safeguards are needed
Assess changes in the system, its environment, and operational needs that could affect the authorization
Ensure that authorization is accomplished a valid Authorization determination has been given for all authorization boundaries under your purview
Review AIS assessment plans
Coordinate with PSO or cognizant security official on approval of external information systems (e.g., guest systems, interconnected system with another organization)
Conduct periodic assessments of the security posture of the authorization boundaries
Ensure configuration management (CM) for security-relevant changes to software, hardware, and firmware and that they are properly documented
Ensure periodic testing is conducted to evaluate the security posture of IS by employing various intrusion/attack detection and monitoring tools [(shared responsibility with Information System Security Officers (ISSO)]
Ensure that system recovery and reconstitution processes developed and monitored to ensure that the authorization boundary can be recovered based on its availability level determination
Ensure all authorization documentation is current and accessible to properly authorized individuals
Ensure that system security requirements are addressed during all phases of the system life cycle
Develop Assured File Transfers (AFT) in accordance with the JSIG
Participate in self-inspections
Conduct the duties of the ISSO if one is not present and/or available.
Education and Experience:
Training and Certifications:
Security Clearance:
IC-CAP provides equal employment opportunities (EEO) to all applicants for employment without regard to race, color, religion, gender, sexual orientation, gender identity or expression, national origin, age, disability, genetic information, marital status. | |
CI-IOI Analyst Senior 102-084 | | | | Counterintelligence-Information Operations Intelligence (CI/IOI) Analyst Senior will provide “day-to-day” multi-discipline analysis and planning support for the Information Operations Division of HAF A3O-QI, Pentagon, Washington, DC. IO Intelligence / CI Analyst responsibilities will cover Collateral, Sensitive Compartmented Information and Special Access Program (SAP) activities.
Performance shall include:
Plan, organize, and evaluate Air Force (AF) security and viability/effectiveness of highly sensitive and often highly classified programs and plans supporting sensitive activities and SAPs within the AF and DoD
Provide prompt review and coordination of unique and highly classified proposals requiring a vast knowledge of AF, DoD, Federal and non-federal organizations, tactics, policies, and processes. This includes, but is not limited to, dealing with sensitive intelligence collection programs and other sensitive activities primarily supporting the AF, but also DoD in general
Research, analyze, review, and provide meaningful recommendation, including written products, when appropriate, to AF commands and senior leadership regarding security, counterintelligence, and signature reduction issues
Identify, assess, and provide recommendations for potential security vulnerabilities; review all pertinent security directives, regulations and instructions to ensure compliance; prepare future threat analysis assessments
Provide prompt and responsive customer support and subject matter expertise as required to ensure the accomplishment of the mission/task
Ensure that detailed coordination for sensitive activities and SAPs does not disclose National Security intent, capabilities, or vulnerabilities, and be prepared to brief selected portions to Senior AF and DoD officials, both verbally or in writing.
Required Education and Experience:
Bachelor's degree
5 years intelligence/IO experience in any DoD component or minimum 4 years IO, operations, policy, military planning or intelligence/CI experience
10 years military or equivalent (GS/GG/Contractor) experience at operational level
Desired:
Security Clearance:
IC-CAP provides equal employment opportunities (EEO) to all applicants for employment without regard to race, color, religion, gender, sexual orientation, gender identity or expression, national origin, age, disability, genetic information, marital status. | |
Cyber Intrusion Detection System Administrator Level 5 104-039 | Colorado Springs, CO or Bolling AFB, Washington D.C
Reston, VA | | 03/29/2024 | Cyber Intrusion Detection System Administrator Level 5 will have an impact on securing our clients' missions and ensuring we anticipate the threats of tomorrow. As a Cyber Intrusion Detection System Administrator you will help ensure today is safe and tomorrow is smarter.
Level 5:
Investigates, analyzes, and responds to cyber incidents within a network environment or enclave.
Uses data collected from a variety of cyber defense tools (e.g., IDS alerts, firewalls, network traffic logs) to analyze events that occur within their environments for the purposes of mitigating threats.
Interprets, analyzes, and reports all events and anomalies in accordance with computer network directives, including initiating, responding, and reporting discovered events.
Evaluates, tests, recommends, coordinates, monitors, and maintains cybersecurity policies, procedures, and systems, including access management for hardware, firmware, and software.
Ensures that cybersecurity plans, controls, processes, standards, policies, and procedures are aligned with cybersecurity standards.
Identifies security risks and exposures, determines the causes of security violations and suggests procedures to halt future incidents and improve security.
Researches and evaluates new concepts and processes to improve performance.
Analyzes cross-functional problem sets, identifies root causes and resolves issues.
Develops techniques and procedures for conducting cybersecurity risk assessments and compliance audits, the evaluation and testing of hardware, firmware and software for possible impact on system security, and the investigation and resolution of security incidents such as intrusion, frauds, attacks or leaks.
May coach and provide guidance to less-experienced professionals.
May serve as a team or task lead.
HOW A CYBER INTRUSION DETECTION SYSTEM ADMINISTRATOR WILL MAKE AN IMPACT:
Monitor day-to-day operations of the sensors (Suricata, Palo Alto, and ArcSight) located at supporting customer's locations.
Perform Enterprise Defense Countermeasure (DC) activities and coordination with other government agencies to record and prepare incident reports and analysis methodology and results.
Monitor and analyze signature alerts from Intrusion Detection/Prevention Systems (IDS/IPS) for false positives.
Provide technical enforcement of organizational security policies.
Provide "tune-or-drop" recommendations towards the DC team's Signature Lifecycle Review procedure.
Provide insight to Detection and Response teams on signature functionality and providing signature tuning as needed.
Communicate with customers and teammates clearly and concisely.
Maintain current knowledge of relevant technology as assigned.
Participate in special projects as required.
Position is day shift but may require evening, weekend or shift-work (depending on operational tempo).
Required Skills and Abilities:
Experience authoring Snort signatures.
Experience authoring Yara rules.
Experience with Perl Compatible Regular Expressions (PCRE).
Preferred Skills:
Experience in intrusion detection and prevention systems.
Proficient in network security technologies and protocols.
Dashboarding in Splunk
Palo Alto Certification Next-Generation Firewall.
Education and Experience:
Training and Certifications:
Security Clearance:
IC-CAP provides equal employment opportunities (EEO) to all applicants for employment without regard to race, color, religion, gender, sexual orientation, gender identity or expression, national origin, age, disability, genetic information, marital status. | |
Cyber Security Analyst Level 3 104-038 | Bolling AFB, Washington D.C or Reston, VA or Colorado Springs, CO or Norfolk, VA or Riverdale, MD or Charlottesville, VA or Pearl Harbor, HI | | 03/29/2024 | Cyber Security Analyst Level 3 will help ensure today is safe and tomorrow is smarter. Our work depends on a Cyber Security Analyst joining our team of analysts, stationed in diverse CONUS and OCONUS locations tasked with monitoring and protecting the classified and unclassified systems of a major Intelligence Community Agency for fraud, waste, and abuse, to include inappropriate content, illegal activity, Identity leakage, and Insider threat activity.
Level 3:
Investigates, analyzes, and responds to cyber incidents within a network environment or enclave.
Uses data collected from a variety of cyber defense tools (e.g., IDS alerts, firewalls, network traffic logs) to analyze events that occur within their environments for the purposes of mitigating threats.
Interprets, analyzes, and reports all events and anomalies in accordance with computer network directives, including initiating, responding, and reporting discovered events.
Evaluates, tests, recommends, coordinates, monitors, and maintains cybersecurity policies, procedures, and systems, including access management for hardware, firmware, and software.
Ensures that cybersecurity plans, controls, processes, standards, policies, and procedures are aligned with cybersecurity standards.
Identifies security risks and exposures, determines the causes of security violations and suggests procedures to halt future incidents and improve security.
Researches and evaluates new concepts and processes to improve performance.
Analyzes cross-functional problem sets, identifies root causes and resolves issues.
Develops techniques and procedures for conducting cybersecurity risk assessments and compliance audits, the evaluation and testing of hardware, firmware and software for possible impact on system security, and the investigation and resolution of security incidents such as intrusion, frauds, attacks or leaks.
May coach and provide guidance to less-experienced professionals.
May serve as a team or task lead.
HOW A CYBER SECURITY ANALYST WILL MAKE AN IMPACT:
Gather and handle forensic evidence in accordance with Rules of Evidence and perform forensic analysis of digital information.
Monitor, detect and report indicators of misuse, abuse, data spillage, insider threat, and security violations.
Identify acceptable use policy infractions.
Review event logs to determine events of interest.
Monitor for fraud, waste and abuse, including content inappropriate to the workplace, Illegal Activity, Productivity Loss and Non-Compliant Activity, as well as Identity Leakage (PII).
Prepare case evidence and incident reports.
Work on special projects as assigned.
WHAT YOU'LL NEED TO SUCCEED:
Preferred Skills: Splunk, Proofpoint, Fidelis, Solera, Windows, and Linux Operating Systems
Education and Experience:
Training and Certifications:
Security Clearance:
IC-CAP provides equal employment opportunities (EEO) to all applicants for employment without regard to race, color, religion, gender, sexual orientation, gender identity or expression, national origin, age, disability, genetic information, marital status. | |
Expert Systems Architect 112-126 | | | 03/20/2024 | Systems Architect (Expert-Level) assist in leading the design and development of solutions for complex applications problems, API design, data services, platform services, cloud services and infrastructure services to meet user requirements and align to strategic goals and the Enterprise Architecture.
Duties may include:
Assists Government in directing the design, development, maintenance, and documentation of solution architectures ensuring traceability to the Enterprise architecture and Enterprise requirements.
Guides the analysis of user requirements, procedures, and problems to automate or improve existing systems and review computer system capabilities, workflow, and scheduling limitations.
Guides development of proposed changes to the solutions architecture design based on analysis of requirements and new technology.
Oversees and coordinates the work of Senior-, Mid-, and Junior-level Systems Architect contractors.
Education and Experience
Required:
Bachelor's degree or higher in Computer Science, Information Technology, Engineering, Engineering Management, Management Information Systems, or related STEM degree program, or related equivalent additional experience of 4 years with no degree or 2 years with a non-STEM degree.
18+ years of experience in government or industry in relevant work areas including: Enterprise Architecture, Solution Architecture, Data Architecture, Department of Defense Architecture Framework (DoDAF), or Intelligence Community’s (IC) Program Architecture Guidance (PAG).
Previous NGA and/or NSG/ASG program/project work experience
Previous IC or DoD program/project work experience
Desired:
Master’s degree in Computer Science, Information Technology, Engineering, Engineering Management, Management Information Systems, or related STEM degree program.
Working knowledge of Model-Based Systems Engineering, processes, tools and languages.
Federated Enterprise Architect Certifications: Certified Enterprise Architect
National Defense University, College of Information and Cyberspace, Enterprise Architecture Certification
Security Clearance:
IC-CAP provides equal employment opportunities (EEO) to all applicants for employment without regard to race, color, religion, gender, sexual orientation, gender identity or expression, national origin, age, disability, genetic information, marital status. | |
ISSM 3 102-083 | | | | Information System Security Manager (ISSM) 3
The primary function serves as a principal advisor on all matters, technical and otherwise, involving the security of information systems under their purview. Primary support will be working within Special Access Programs (SAP) supporting Department of Defense (DoD) agencies, such as HQ Air Force, Office of the Secretary of Defense, and Military Compartment efforts. The position will provide “day-to-day” support for Collateral, Sensitive Compartmented Information and SAP activities.
Duties May include:
Lead, cultivate and maintain productive working relationships with other DoD agencies managers, data stewards, and senior leadership to foster productive and positive cyber security profile
Participate in the strategic planning and implementation of the Cyber Security Program
Provide expert input to the formulation of cyber security policies based upon the Risk Management Framework (RMF) with emphasize on Joint Special Access Program Implementation Guide (JSIG) authorization process
Advise customer on RMF assessment and authorization issues
Develop and implement a security assessment plan
Perform risk assessments and make recommendations to DoD agency customers
Advise government program managers on security testing methodologies and processes
Evaluate authorization documentation and provide written recommendations for authorization togovernment PM’s
Develop and maintain a formal Information Systems Security Program
Ensure that all IAOs, network administrators, and other cyber security personnel receive the necessary technical and security training to carry out their duties
Develop, review, endorse, and recommend action by the AO or DAO of system assessment documentation
Ensure approved procedures are in place for clearing, sanitizing, and destroying various types of hardware and media
Develop and execute security assessment plans that include verification that the features and assurances required for each protection level functioning
Institute and implement a Configuration Control Board (CCB) charter
Maintain a and/or applicable repository for all system authorization documentation and modifications
Develop policies and procedures for responding to security incidents, to include investigating and reporting security violations and incidents
Ensure proper protection or corrective measures have been taken when an incident or vulnerability has been discovered within a system
Ensure that data ownership and responsibilities are established for each authorization boundary, to include accountability, access rights, and special handling requirements
Ensure development and implementation of an information security education, training, and awareness program, to include attending, monitoring, and presenting local cyber security training.
Evaluate threats and vulnerabilities to ascertain whether additional safeguards are needed
Assess changes in the system, its environment, and operational needs that could affect the authorization
Ensure that authorization is accomplished a valid Authorization determination has been given for all authorization boundaries under your purview
Review AIS assessment plans
Coordinate with PSO or cognizant security official on approval of external information systems (e.g., guest systems, interconnected system with another organization)
Conduct periodic assessments of the security posture of the authorization boundaries
Ensure configuration management (CM) for security-relevant changes to software, hardware, and firmware and that they are properly documented
Ensure periodic testing is conducted to evaluate the security posture of IS by employing various intrusion/attack detection and monitoring tools (shared responsibility with ISSOs)
Ensure that system recovery and reconstitution processes developed and monitored to ensure that the authorization boundary can be recovered based on its availability level determination
Ensure all authorization documentation is current and accessible to properly authorized individuals
Ensure that system security requirements are addressed during all phases of the system life cycle
Establish and develop a self-inspection program within the organization
Periodically review system security to accommodate changes to policy or technology
Coordinate all technical security issues outside of area of expertise or responsibility with ISSE
Provide expert research and analysis in support of expanding programs and area of responsibility as it pertains to cyber security and information technology activities
Develop Assured File Transfers (AFT) on accordance with the JSIG
Provide leadership, mentoring, and quality assurance for Cyber Security and Information Technology team members
Education and Experience
Required:
Master’s degreeand 10+ years of experience or 16 years of relevant experience in lieu of degree
Prior performance in roles such as ISSO or ISSM
2+ years of SAP experience
Training:
Security Clearance:
IC-CAP provides equal employment opportunities (EEO) to all applicants for employment without regard to race, color, religion, gender, sexual orientation, gender identity or expression, national origin, age, disability, genetic information, marital status. | |
PSR 2 102-082 | | | 04/23/2024 | Program Security Representative 2’s primary function is to provide multi-discipline security support for one or more of the customer’s Special Access Programs (SAPs). The position will provide “day-to-day” multi-discipline analysis for Collateral, Sensitive Compartmented Information (SCI) and Special Access Program (SAP) activities.
Performance shall include:
Ensure strict adherence to the provisions of the NISPOM, its Supplement, the DoD Overprint, DCID, ICD, and SAP policy
Assist in developing and executing approved policies and procedures for safeguarding Special Access
Program (SAP), Sensitive Compartmented Information (SCI) and collateral data in support of US military operations
Provide day-to-day security support that includes continuous assessment of procedures to identify shortfalls and provide appropriate recommendations for revising and improving security policies, procedures, and systems
Identify vulnerabilities, threats, and risks to test, training, and operational activities
Assist in developing, implementing, and training the Operations Security program
Assist in providing contractor and subordinate facility assistance and oversight
Brief all levels of personnel, both in the government and senior civilian services, on a variety of security related topics
Conduct and document SAP facility compliance reviews, follow-on facility reviews, and facility close-outs
Monitor, report and track all corrective actions resulting from compliance reviews
Ensure timely notification of pertinent security matters to program technical and management staff
Conduct exploration of any loss, compromise, or suspected compromise of classified and/or sensitive information, including conducting preliminary inquiries and generating damage assessments resulting from the loss of classified information.
Coordinate with SAP security personnel to ensure lessons learned are incorporated into the curriculum for the SAP security education & awareness program
Education and Experience:
Training and Certficiations:
Security Clearance:
IC-CAP provides equal employment opportunities (EEO) to all applicants for employment without regard to race, color, religion, gender, sexual orientation, gender identity or expression, national origin, age, disability, genetic information, marital status. | |
PSR 3 102-081 | | | | Program Security Representative 3’s primary function is to provide multi-discipline security support for one or more of the customer’s Special Access Programs (SAP). The position will provide “day-to-day” multi-discipline analysis for Collateral, Sensitive Compartmented Information (SCI) and SAP activities.
Performance shall include:
Ensure strict adherence to the provisions of the NISPOM, its Supplement, the DoD Overprint, DCID, ICD, and SAP policy
Assist in developing and executing approved policies and procedures for safeguarding SAP, SCI, and collateral data in support of US military operations
Provide day-to-day security support that includes continuous assessment of procedures to identify shortfalls and provide appropriate recommendations for revising and improving security policies, procedures, and systems
Identify vulnerabilities, threats, and risks to test, training, and operational activities
Assist in developing, implementing, and training the Operations Security program
Assist in providing contractor and subordinate facility assistance and oversight
Brief all levels of personnel, both in the government and senior civilian services, on a variety of security related topics
Conduct and document SAP facility compliance reviews, follow-on facility reviews, and facility close-outs
Monitor, report and track all corrective actions resulting from compliance reviews
Ensure timely notification of pertinent security matters to program technical and management staff
Conduct exploration of any loss, compromise, or suspected compromise of classified and/or sensitive information, including conducting preliminary inquiries and generating damage assessments resulting from the loss of classified information.
Coordinate with SAP security personnel to ensure lessons learned are incorporated into the curriculum for the SAP security education & awareness program
Provide leadership, mentoring, and oversight of team members.
Education and Experience
Required:
Bachelor's degree and 10-12 years related experience -OR- 14-16 years related experience in lieu of degree
Security Fundamentals Professional Certification (SFPC) counts towards no more than 5 years of experience)
2+ years SAP experience.
Security Clearance:
IC-CAP provides equal employment opportunities (EEO) to all applicants for employment without regard to race, color, religion, gender, sexual orientation, gender identity or expression, national origin, age, disability, genetic information, marital status. | |
ASR 3 102-079 | | | | Activity Security Representative 3’s primary function is to provide multi-disciplined security support to a customer’s facility and organization. The position will provide “day-to-day” support for Collateral, Sensitive Compartmented Information (SCI) and Special Access Program (SAP) activities.
Duties may include:
Classification reviews of inbound and outbound correspondence
Assist in the maintenance of a document accountability database and associated correspondence
Processing inbound and outbound classified mail and receipt records
Perform destruction of classified materials
Process magnetic media for accountability
Reproduction support for classified materials
Maintain various daily logs for a variety of administrative functions associated with document control
Assist in the processing of inbound data and outbound data transfer files
Transfer electronic data files to internal customers
Maintain an extensive customer database point of contact listing
Assist with researching, processing, filing, and maintaining inbound and outbound visit notices
Escort facility visitors and maintains associated logs
Assist in the preparation of facility access control badges
Conduct entry and exit inspections
Assist in the maintenance of facility access control entry systems, to include visitor control
Perform data entry to the Personnel Access Security System database and maintain all customer sponsored billets and quota information
Assist in maintaining personnel security files for all personnel of the supported element
Follow and enforce the customer’s Standard Operating Procedures
Provide support for the security awareness and education programs
Perform miscellaneous administrative support functions as directed by the contractor site lead and/or the Senior Security Representative
Review, track, and monitor security clearance processing activities with appropriate government personnel to achieve appropriate clearance actions
Participate in Air Force SAP security compliance inspections of government organizations and industry
Implement Top Secret Control for accountable material and associated correspondence
Prepare and/or process inbound and outbound classified mail, faxes, courier packages and receipts
Prepare, process, and/or review Program Access Request (PARs) for accuracy and access eligibility
Execute Special Access Program Nomination Process Questionnaires
Conduct Defense Central Index of Investigations (DCII), Joint Personnel Access System (JPAS), and SAPNP reviews of candidates being submitted for SAP access
Perform data entry and record checks in the Air Force Access Data System (AFADS) and maintainsvall customer sponsored personnel access information current
Perform indoctrinations
Provide leadership, mentoring, and quality assurance for Team Members.
Education and Experience
Required:
Desired:
Training and Certifications:
Security Clearance:
IC-CAP provides equal employment opportunities (EEO) to all applicants for employment without regard to race, color, religion, gender, sexual orientation, gender identity or expression, national origin, age, disability, genetic information, marital status. | |
Net-Sys Admin 1 102-077 | | | | Network-System Administrator (Net-Sys Admin) 1 function will be to organize, install, and support government organization’s computer systems, including local area networks (LANs), wide area networks (WANs), network segments, intranets, and other data communication systems. This will also include helping architect, design and analyze network models. It will require participation in decisions about buying future hardware or software to upgrade organization’s infrastructure. This position might be called upon to provide technical support to computer users to help solve users’ problems. This position will support activities within Special Access Programs (SAPs) supporting Department of Defense (DoD) agencies, such as HQ Air Force, Office of the Secretary of Defense (OSD) and Military Compartments efforts. The position will provide “day-to-day” support for Collateral, Sensitive Compartmented Information (SCI) and Special Access Program (SAP) activities.
Performance shall include:
Ability to operate under supervision.
Execute day to day management and operations of systems and networks
Manage COTS & GOTS products to collect, display and remediate a variety of automated system security and system operations/performance functions and metrics
Follow Operations and Maintenance (O&M) checklists to maintain the service (daily, weekly, monthly, yearly O&M checklists); build Tactics, Techniques and Processes (TTPs) and Standard Operating Processes (SOPs) associated with service checklists
Operate monitoring tools/capabilities with the enterprise security information and event management (SIEM) and create/tailor complex event alarms/rules and summary reports
Assist in analyzing technical risk, upon request, of emerging cybersecurity tools and processes
Work as part of a security incident response team as needed
Working technical competency in one or more of the following supported platforms: Microsoft Windows Server, Red Hat Enterprise Linux servers, MS Hyper-V/VMWare/ESx/Xen Hypervisors, Enterprise networking/firewalls/intrusion detection/prevention systems, forensic analysis/vulnerability assessment, Group Policy management and configuration, Scripting, BMC Footprints, WSUS, , Lumension, Bitlocker, SQL Server 2012, TomCat, IIS, Windows Server2012r2/2016, Win 10, Red Hat 6.5, Microsoft Office Toolkits, SEIMs, Logrhythm, ACAS/Nessus/SCAP, mandatory/role-based access control concepts (e.g. SE Linux extensions to RHEL, PitBull, AppArmor, and Sentris) , video teleconferencing/VOIP, Oracle/MS SQL database security, and Apache/IIS Web server security
Education and Experience:
Desired:
Training and Certifications:
Security Clearance:
IC-CAP provides equal employment opportunities (EEO) to all applicants for employment without regard to race, color, religion, gender, sexual orientation, gender identity or expression, national origin, age, disability, genetic information, marital status. | |
SCA 1 102-076 | | | | Security Control Assessor (SCA) 1 is responsible for conducting a comprehensive assessment of the management, operational, and technical security controls employed within or inherited by an IS to determine the overall effectiveness of the controls (i.e., the extent to which the controls are implemented correctly, operating as intended, and producing the desired outcome with respect to meeting the security requirements for the system). SCAs also provide an assessment of the severity of weaknesses or deficiencies discovered in the IS and its environment of operation and recommend corrective actions to address identified vulnerabilities. Responsibilities will cover Collateral, Sensitive Compartmented Information (SCI) and Special Access Program (SAP) activities within the customer’s area of responsibility.
Performance shall include:
Perform oversight of the development, implementation and evaluation of IS security program policy; special emphasis placed upon integration of existing SAP network infrastructure
Perform assessment of ISs, based upon the Risk Management Framework (RMF) methodology in accordance with the Joint SAP Implementation Guide (JSIG)
Advise the Information System Owner (ISO), Information Data Owner (IDO), Program Security Officer (PSO), and the Delegated and/or Authorizing Official (DAO/AO) on any assessment and authorization issues
Evaluate Authorization packages and make recommendation to the AO and/or DAO for authorization
Evaluate IS threats and vulnerabilities to determine whether additional safeguards are required
Advise the Government concerning the impact levels for Confidentiality, Integrity, and Availability for the information on a system
Ensure security assessments are completed and results documented and prepare the Security Assessment Report (SAR) for the Authorization boundary
Initiate a Plan of Action and Milestones (POA&M) with identified weaknesses for each Authorization Boundaries assessed, based on findings and recommendations from the SAR
Evaluate security assessment documentation and provide written recommendations for security authorization to the Government
Discuss recommendation for authorization and submit the security authorization package to the AO/DAO
Assess proposed changes to Authorization boundaries operating environment and mission needs to determine the continuation to operate.
Review and concur with all sanitization and clearing procedures in accordance with Government guidance and/or policy
Assist the Government compliance inspections
Assist the Government with security incidents that relate to cybersecurity and ensure that the proper and corrective measures have been taken
Ensure organization are addressing and conducting all phases of the system development life cycle (SDLC)
Evaluate Hardware and Software to determine security impact that it might have on Authorization boundaries
Evaluate the effectiveness and implementation of Continuous Monitoring Plans
Represent the customer on inspection teams.
Education and Experience
Required:
Bachelor's degree and 5-7 years related experience -OR- 9-11 year related experience in lieu of degree
Prior performance in role of ISSO and ISSM
3+ years experience in SAP, SCI, or Collateral Information Systems (IS) and implementation of regulations
Training and Certifications:
Security Clearance:
IC-CAP provides equal employment opportunities (EEO) to all applicants for employment without regard to race, color, religion, gender, sexual orientation, gender identity or expression, national origin, age, disability, genetic information, marital status. | |
PSR 2 102-075 | | | | Program Security Representative 2- This is a future position that may come open in the future. We are currently building our pipeline.
The primary function is to provide multi-discipline security support for one or more of the customer’s Special Access Programs (SAPs). The position will provide “day-to-day” multi-discipline analysis for Collateral, Sensitive Compartmented Information (SCI) and Special Access Program (SAP) activities.
Performance shall include:
Ensure strict adherence to the provisions of the NISPOM, its Supplement, the DoD Overprint, DCID, ICD, and SAP policy
Assist in developing and executing approved policies and procedures for safeguarding Special Access
Program (SAP), Sensitive Compartmented Information (SCI) and collateral data in support of US military operations
Provide day-to-day security support that includes continuous assessment of procedures to identify shortfalls and provide appropriate recommendations for revising and improving security policies, procedures, and systems
Identify vulnerabilities, threats, and risks to test, training, and operational activities
Assist in developing, implementing, and training the Operations Security program
Assist in providing contractor and subordinate facility assistance and oversight
Brief all levels of personnel, both in the government and senior civilian services, on a variety of security related topics
Conduct and document SAP facility compliance reviews, follow-on facility reviews, and facility close-outs
Monitor, report and track all corrective actions resulting from compliance reviews
Ensure timely notification of pertinent security matters to program technical and management staff
Conduct exploration of any loss, compromise, or suspected compromise of classified and/or sensitive information, including conducting preliminary inquiries and generating damage assessments resulting from the loss of classified information.
Coordinate with SAP security personnel to ensure lessons learned are incorporated into the curriculum for the SAP security education & awareness program.
Education and Experience:
Bachelor's degree -or- 4 years of additional, relevant experience, in lieu of degree
5-7 years related experience (Security Fundamentals Professional Certification (SFPC) counts towards 3 years of experience)
Desired:
Training and Certifications:
Security Clearance:
IC-CAP provides equal employment opportunities (EEO) to all applicants for employment without regard to race, color, religion, gender, sexual orientation, gender identity or expression, national origin, age, disability, genetic information, marital status. | |
Net-Sys Admin 1 102-073 | | | | Network-System Administrator (Net-Sys Admin) 1's primary function will be to organize, install, and support government organization’s computer systems, including local area networks (LANs), wide area networks (WANs), network segments, intranets, and other data communication systems. This will also include helping architect, design and analyze network models. It will require participation in decisions about buying future hardware or software to upgrade organization’s infrastructure. This position might be called upon to provide technical support to computer users to help solve users’ problems. This position will support activities within Special Access Programs (SAPs) supporting Department of Defense (DoD) agencies, such as HQ Air Force, Office of the Secretary of Defense (OSD) and Military Compartments efforts. The position will provide “day-to-day” support for Collateral, Sensitive Compartmented Information (SCI) and Special Access Program (SAP) activities.
Performance shall include:
Ability to operate under supervision
Execute day to day management and operations of systems and networks
Manage COTS & GOTS products to collect, display and remediate a variety of automated system security and system operations/performance functions and metrics
Follow Operations and Maintenance (O&M) checklists to maintain the service (daily, weekly, monthly, yearly O&M checklists); build Tactics, Techniques and Processes (TTPs) and Standard Operating Processes (SOPs) associated with service checklists
Operate monitoring tools/capabilities with the enterprise security information and event management (SIEM) and create/tailor complex event alarms/rules and summary reports
Assist in analyzing technical risk, upon request, of emerging cybersecurity tools and processes
Work as part of a security incident response team as needed
Working technical competency in one or more of the following supported platforms: Microsoft Windows Server, Red Hat Enterprise Linux servers, MS Hyper-V/VMWare/ESx/Xen Hypervisors, Enterprise networking/firewalls/intrusion detection/prevention systems, forensic analysis/vulnerability assessment, Group Policy management and configuration, Scripting, BMC Footprints, WSUS, , Lumension, Bitlocker, SQL Server 2012, TomCat, IIS, Windows Server2012r2/2016, Win 10, Red Hat 6.5, Microsoft Office Toolkits, SEIMs, Logrhythm, ACAS/Nessus/SCAP, mandatory/role-based access control concepts (e.g. SE Linux extensions to RHEL, PitBull, AppArmor, and Sentris) , video teleconferencing/VOIP, Oracle/MS SQL database security, and Apache/IIS Web server security
Education and Experience:
Desired:
Training and Certifications:
Security Clearance:
IC-CAP provides equal employment opportunities (EEO) to all applicants for employment without regard to race, color, religion, gender, sexual orientation, gender identity or expression, national origin, age, disability, genetic information, marital status. | |
Senior Systems Engineer 112-125 | | | 06/24/2024 | Systems Engineer (Senior-Level) guides engineering teams in taking a multi-discipline approach to requirements engineering, solutions engineering, scheduling, reliability, resiliency, services development, integration, test and evaluation, maintainability and analysis across the National System of Geospatial-intelligence (NSG), Allied System of Geospatial-intelligence (ASG) and Federal Agencies to ensure timely and accurate GEOINT.
Duties include:
Guides Mid-level and Junior-level system engineers performing requirements engineering, solutions engineering, scheduling, reliability, resiliency, services development, integration, test and evaluation, maintainability and analysis across the National System of Geospatial-intelligence (NSG),
Allied System of Geospatial-intelligence (ASG) and Federal Agencies.
Guides the planning, analysis/traceability of user requirements, architectures traceability, procedures, and problems to automate or improve existing systems and review cloud service capabilities, workflow, and scheduling limitations.
Guides Mid-level and Junior-level system engineers developing solutions designs based on analysis of requirements and new technology.
Assists the Government in the capture and translation of mission and customer requirements/needs into systems/capability requirements and solutions.
Supports the analyses and allocation of requirements to systems architecture components and executing programs.
Assists the Government in performing systems integration activities.
Conducts Analysis of Alternatives (AoAs), Course of Actions (CoAs), Trade Studies, and Engineering Assessments.
Assists the Government in strategic technical planning, project management, performance engineering, risk management and interface design.
Operates at the level of integrating multiple systems, services, processes, and interfaces within Major Systems Acquisitions across organizational and agency boundaries
Skills and Experience:
Required:
12 to 18 years experience.
Senior-level working experience in government or industry in relevant work areas including: DoD/IC Acquisition Process, Requirements Process, PPBES Process or system engineering of large complex System of Systems or Service Oriented Architecture/Cloud environments.
Experience with and strong understanding of systems engineering lifecycle.
Education:
Desired
Master’s degree in Systems Engineering or in related technical or scientific fields such as engineering, physics, mathematics, operations research, engineering management, Computer
Science, Information Technology, Management Information Systems, or related STEM degree program.
Working knowledge of Model Based Systems Engineering, processes, tools and languages.
Working knowledge of Software Development Frameworks.
INCOSE Certified System Engineering Professional (CSEP) certification.
Documented work experience in the field of geospatial intelligence.
Licensure as a professional engineer.
Membership or leadership participation in any of the following professional organizations: ACSM, ASCE, ASPRS, OGC, SAREM, or USGIF.
Demonstrated expertise in photogrammetry, remote sensing, image science, information sciences, geographic information systems, geomatics, or related fields.
Demonstrated knowledge of the current NSG/ASG and NRO enterprises.
Security Clearance:
IC-CAP provides equal employment opportunities (EEO) to all applicants for employment without regard to race, color, religion, gender, sexual orientation, gender identity or expression, national origin, age, disability, genetic information, marital status. | |
ServiceNow Web Developer Senior-Level 100-009 | Washington, DC or St. Louis, MO or Valley Forge, PA | | 06/21/2024 | ServiceNow Web Developer Senior-Level will support the migration of existing on-premises, web-based solutions to the customer ServiceNow platform. Provide subject matter expertise on the utilization and maintenance of capabilities delivered to ServiceNow to support creating, troubleshooting, debugging, and root cause analysis through capability migration. Possesses a thorough knowledge of programming and server software operations to include architecture. Develops new Web applications through packaged and customized applications.
Specific duties of the position include:
Performing analysis of alternatives and review of current initiatives
Conducting engineering decomposition and assisting in defining migration tasks and schedules to address architectural and technology changes required to transition to the ServiceNow platform.
Developing and configuring user interfaces that will attract and appeal to users and integrate applications that will meet the customer’s desired workflows.
Building user interfaces and map UI components with data resources to dynamically fetch content utilizing ServiceNow UI Builder.
Creating or integrating web applications and components through the entire software development lifecycle (requirements, design, integration, test, and production).
Developing database-driven Web interfaces for rapid, real-time information sharing.
Developing external Web portals allowing users to input and retrieve accurate information. Experienced in graphics, layout, scripting, programming, as well as development involving compatibility and seamless integration with various technologies such as Java and ColdFusion.
Develop loosely coupled Application Programming Interfaces (APIs) to expose data to multiple consumer types. Ability to integrate data across enterprise systems and services leveraging RESTful APIs.
Candidate will engage as part of team that utilizes an agile scrum delivery model. Individual development and initiative to provide solutions to issues is expected. Good communication is a must.
Candidate must be a ServiceNow developer, not a user.
Education and Experiences:
Required
BS degree is a software or engineering field of study with 10-12 years of experience, MS degree with 8-10 years of experience, or a Phd with 5-7years of experience
DoD Approved Clearance and Poly
Experience:
Required
Adhere to prescribed processes and guidelines for web development workstations and the development environment, to include requesting approval for software download/installation, software configuration, and software version control.
Manage and maintain content for a web presence (internal facing web page and documents, external facing webpage and documents) to include site design, content updates, collecting web metrics, and supporting access by external customers.
Participate in the development of a consolidated business process, integrating and replacing the current project management capabilities; provide installation, customization, support, maintenance, license updates, and monitoring of the consolidated business web presence after implementation.
Demonstrated experience developing custom workflows and components in ServiceNow.
Experience with database design, development and maintenance (Oracle, PostgreSQL, or other as specified) for Test related web projects.
Administer infrastructure resources to install, configure, host, and patch web applications to meet security requirements. Knowledge of both Linux and Windows required.
Experience using Test-Driven-Development and Behavior-Driven-Development best practices.
Provide bi-directional data communication with IT Service Management solutions. Possess strong data integration skills and demonstrated ability to map data schemas between services via APIs.
Build user-friendly custom web forms and workflows within ServiceNow.
Subject matter expertise in the configuration, maintenance, and architecture of ServiceNow deployments.
Programming experience in both front-end and back-end technologies such as HTML, SQL, C, VB, Java, JavaScript, Python, and ColdFusion.
Experience with application styling using CSS, Sass, LeSS, and CSS-in-JS libraries.
Security Clearance:
IC-CAP provides equal employment opportunities (EEO) to all applicants for employment without regard to race, color, religion, gender, sexual orientation, gender identity or expression, national origin, age, disability, genetic information, marital status. | |
Sr. SAR Image Scientist 100-008 | | | 04/24/2024 | Sr. SAR Image Scientist is a unique opportunity to enhance your career by working with the community subject matter experts, directly with the customer and with project autonomy not customarily given as a government contractor. Based on the priorities of the customer, the image scientist will support product evaluations, quality studies, new product initializations, product algorithm assessments, or develop image quality equations to quantify the expected quality of a system given various parameters.
Duties may Include:
Have a working understanding and practical application of modeling components of the image path to include sensor, detector, atmospheric, and material properties.
Simulation and modeling experience and ability to develop algorithm description documentation for software development is needed.
Familiarity with current GEOINT systems, products and development, as well as the exploitation software packages will be necessary to develop test and verification methodologies.
Work within an existing team to complete tasks as prioritized by government customers.
Good communication and teamwork is necessary. A history of delivering results is critical to success.
Sensor modeling; decomposing product formation elements to quantify the overall quality of the image chain
Algorithm assessment to quantify the performance of a product given desire mission application
Performing baseline assessment of system performance to support sensor initialization
Operational monitoring of system performance over time
Responding to detected errors and artifacts by recommending possible causes and corrective actions
Experience and Education
Required:
Bachelor or advanced degree in Image Science, Optics, Engineering, or Applied Physics
12 Years of experience with a BS/BA, or 10 Years of experience with an MS/MA, or 7 Years of experience with a PhD
Must have SAR expertise
Experience working with Imagery and Complex products collected with SAR imaging platforms
Image processing and Digital Signal processing experience
Image chain analysis to include sensor modeling, signal quality and noise, detectors, detector calibration, and complex processing image formation.
Application of error estimation.
Understanding and application of image quality standards (e.g. NIIRS), scales, metrics and image quality equations.
Significant applied knowledge of sensor imaging systems, products, and exploitation processes
Strong understanding of the systems engineering lifecycle to include independent testing and data verification
Strong written and oral communication skills, with emphasis on briefing to obtain decisions and solve technical issues and test plans/reports writing
Ability to work independently as well as part of a team
Willingness to learn, solve problems and perform in a dynamic work environment
Track record of delivering results
Desired:
Knowledge of National System for Geospatial-Intelligence (NSG) tasking, collection, processing, exploitation and dissemination (TCPED) image chain, specifically the exploitation of SAR imagery and complex data products.
Experience working in a DoD or IC operational environment
Experience developing engineering code (C, Python, Matlab, IDL) to solve hard problems and create processes for repeatable results.
Security Clearance:
IC-CAP provides equal employment opportunities (EEO) to all applicants for employment without regard to race, color, religion, gender, sexual orientation, gender identity or expression, national origin, age, disability, genetic information, marital status. | |
SCA 2 102-071 | | | | Security Control Assessor (SCA) 2 is responsible for conducting a comprehensive assessment of the management, operational, and technical security controls employed within or inherited by an IS to determine the overall effectiveness of the controls (i.e., the extent to which the controls are implemented correctly, operating as intended, and producing the desired outcome with respect to meeting the security requirements for the system). SCAs also provide an assessment of the severity of weaknesses or deficiencies discovered in the IS and its environment of operation and recommend corrective actions to address identified vulnerabilities. Responsibilities will cover Collateral, Sensitive Compartmented Information (SCI) and Special Access Program (SAP) activities within the customer’s area of responsibility.
Performance shall include:
Perform oversight of the development, implementation and evaluation of IS security program policy; special emphasis placed upon integration of existing SAP network infrastructure
Perform assessment of ISs, based upon the Risk Management Framework (RMF) methodology in accordance with the Joint Special Access Program (SAP) Implementation Guide (JSIG)
Advise the Information System Owner (ISO), Information Data Owner (IDO), Program Security
Officer (PSO), and the Delegated and/or Authorizing Official (DAO/AO) on any assessment and authorization issues
Evaluate Authorization packages and make recommendation to the AO and/or DAO for authorization
Evaluate IS threats and vulnerabilities to determine whether additional safeguards are required
Advise the Government concerning the impact levels for Confidentiality, Integrity, and Availability for the information on a system
Ensure security assessments are completed and results documented and prepare the Security Assessment Report (SAR) for the Authorization boundary
Initiate a Plan of Action and Milestones (POA&M) with identified weaknesses for each Authorization Boundaries assessed, based on findings and recommendations from the SAR
Evaluate security assessment documentation and provide written recommendations for security authorization to the Government
Discuss recommendation for authorization and submit the security authorization package to the AO/DAO
Assess proposed changes to Authorization boundaries operating environment and mission needs to determine the continuation to operate.
Review and concur with all sanitization and clearing procedures in accordance with Government guidance and/or policy
Assist the Government compliance inspections
Assist the Government with security incidents that relate to cybersecurity and ensure that the proper and corrective measures have been taken
Ensure organization are addressing and conducting all phases of the system development life cycle (SDLC)
Evaluate Hardware and Software to determine security impact that it might have on Authorization boundaries
Evaluate the effectiveness and implementation of Continuous Monitoring Plans
Represent the customer on inspection teams.
Education and Experience
Required:
Bachelor's degree AND 7 years related experience -OR- Associate degree AND 9 years related experience -OR- HS diploma/GED AND 11 years of relevant experience in lieu of degree
4+ years experience in SAP, SCI, or Collateral Information Systems (S) security and implentation of regulations identified in the description of duties
Prior performance in the role of ISSO and ISSM or SCA
Training and Certifications:
Security Clearance:
IC-CAP provides equal employment opportunities (EEO) to all applicants for employment without regard to race, color, religion, gender, sexual orientation, gender identity or expression, national origin, age, disability, genetic information, marital status. | |
Net-Sys Admin 3 102-069 | | | | Network-System Administrator 3's primary function will be to organize, install, and support government organization’s computer systems, including local area networks (LANs), wide area networks (WANs), network segments, intranets, and other data communication systems. This will also include helping architect, design and analyze network models. It will require participation in decisions about buying future hardware or software to upgrade organization’s infrastructure. This position might be called upon to provide technical support to computer users to help solve users’ problems. This position will support activities within Special Access Programs (SAP) supporting Department of Defense agencies, such as HQ Air Force, Office of the Secretary of Defense and Military Compartments efforts. The position will provide “day-to-day” support for Collateral, Sensitive Compartmented Information (SCI) and SAP activities.
Duties may include:
Able to perform self-sustaining and work with little to no oversight
Lead IT ops team on day to day management and operations of Networks and implement capabilities vetted through Cybersecurity, ISSE and higher headquarters to maintain JSIG/RMF Authority to Operate and maintain Continuous Monitoring tools and processes
Manage COTS & GOTS products to collect, display and remediate a variety of automated system, security and system operations/performance functions and metrics.
Assist during security assessments of servers/network devices/security appliances
Assist during security assessments with regard to accuracy and efficiency
Assist with Creation of operational Operations and Maintenance (O&M) checklists to maintain the service (daily, weekly, monthly, yearly O&M checklists); build Tactics, Techniques and Processes (TTPs) and Standard Operating Processes (SOPs) associated with service checklists
Manage and operate monitoring tools/capabilities with the enterprise security information and event management (SIEM) and create/tailor complex event alarms/rules and summary reports
Execute cybersecurity operations procedures for day to day network management, operations and maintenance
Monitor/analyze output of cybersecurity related tools for reportable security incidents and residual risk
Assist in analyzing technical risk, upon request, of emerging cybersecurity tools and processes
Work as part of a security incident response team as needed
Assist ISSM/ISSO/ISSE with the Integration/Development new techniques to improve Confidentiality, Integrity, and Availability for networks/systems operating at various classification levels
Advanced technical competency in one or more of the following supported platforms: Microsoft Windows Server, Active Directory Red Hat Enterprise Linux servers, MS Hyper-V/VMWare/ESx/Xen Hypervisors, Enterprise networking/firewalls/intrusion detection/prevention systems, forensic analysis/vulnerability assessment, Group Policy management and configuration, Scripting, BMC Footprints, WSUS, , Lumension, Bitlocker, SQL Server 2012, TomCat, IIS, Windows Server 2012r2/2016, Win 10, Red Hat 6.5, Microsoft Office Toolkits, SEIMs, Logrhythm, ACAS/Nessus/SCAP, mandatory/role-based access control concepts (e.g. SE Linux extensions to RHEL, PitBull, AppArmor, and Sentris) , video teleconferencing/VOIP, Oracle/MS SQL database security, and Apache/IIS Web server security.
Education and Experience
Required:
Training:
Security Clearance:
IC-CAP provides equal employment opportunities (EEO) to all applicants for employment without regard to race, color, religion, gender, sexual orientation, gender identity or expression, national origin, age, disability, genetic information, marital status. | |
IT-IA Specialist 3 102-065 | | | | Information Technology-Information Assurance (IT-IA) Specialist 3 is working within Special Access Programs (SAPs) supporting Department of Defense (DoD) agencies, such as HQ Air Force, Office of the Secretary of Defense (OSD) and Military Compartments efforts. The position will provide “day-to-day” support for Collateral, Sensitive Compartmented Information (SCI) and Special Access Program (SAP) activities.
Performance shall include:
Establish complex operational software configuration controls and system interfaces for computer system(s) assigned
Maintain file servers, Firewalls, network access, Security Monitoring Systems and system documentation as required
Analyze and troubleshoot system anomalies to ensure optimum equipment performance
Prepare system for operational use and support operational tests
Review, prepare, and update authorization packages
Notify customer when changes occur that might affect authorization accreditation
Conduct cybersecurity portion of the self-inspection’s checklist
Review and provide technical and cyber security coordination on all Bodies of Evidence that makeup the authorization package
Identify any and all vulnerabilities and implement countermeasures
Ensure information systems and network appliances are operated, maintained, and disposed of in accordance with security policies and practices
Perform Video-Teleconferencing VTC System Administration, Scheduling, & Configuration
Provide External Information System(s) Client Support
Perform account creations, changes, & deletions on multiple authorization boundaries
Perform Help Desk & troubleshooting activities
Perform Hardware/Software System Configuration, upgrades and modifications
Perform system and network appliance patching activities
Provide Government-Issued Laptop Support
Assist in Media Control & Accountability activities
Perform COMSEC account/equipment management activities.
Education and Experience:
Training and Certifications:
Security Clearance:
IC-CAP provides equal employment opportunities (EEO) to all applicants for employment without regard to race, color, religion, gender, sexual orientation, gender identity or expression, national origin, age, disability, genetic information, marital status. | |
ASR 3 102-063 | | | | Activity Security Representative 3's primary function is to provide multi-disciplined security support to a customer’s facility and organization. The position will provide “day-to-day” support for Collateral, Sensitive Compartmented Information (SCI) and Special Access Program (SAP) activities.
Duties may include:
Classification reviews of inbound and outbound correspondence
Assist in the maintenance of a document accountability database and associated correspondence
Processing inbound and outbound classified mail and receipt records
Perform destruction of classified materials
Process magnetic media for accountability
Reproduction support for classified materials
Maintain various daily logs for a variety of administrative functions associated with document control
Assist in the processing of inbound data and outbound data transfer files
Transfer electronic data files to internal customers
Maintain an extensive customer database point of contact listing
Assist with researching, processing, filing, and maintaining inbound and outbound visit notices
Escort facility visitors and maintains associated logs
Assist in the preparation of facility access control badges
Conduct entry and exit inspections
Assist in the maintenance of facility access control entry systems, to include visitor control
Perform data entry to the Personnel Access Security System database and maintain all customer sponsored billets and quota information
Assist in maintaining personnel security files for all personnel of the supported element
Follow and enforce the customer’s Standard Operating Procedures
Provide support for the security awareness and education programs
Perform miscellaneous administrative support functions as directed by the contractor site lead and/or the Senior Security Representative
Review, track, and monitor security clearance processing activities with appropriate government personnel to achieve appropriate clearance actions
Participate in Air Force SAP security compliance inspections of government organizations and industry
Implement Top Secret Control for accountable material and associated correspondence
Prepare and/or process inbound and outbound classified mail, faxes, courier packages and receipts
Prepare, process, and/or review Program Access Request (PARs) for accuracy and access eligibility
Execute Special Access Program Nomination Process Questionnaires
Conduct Defense Central Index of Investigations (DCII), Joint Personnel Access System (JPAS), and SAPNP reviews of candidates being submitted for SAP access
Perform data entry and record checks in the Air Force Access Data System (AFADS) and maintains all customer sponsored personnel access information current
Perform indoctrinations
Provide leadership, mentoring, and quality assurance for Team Members.
Education and Experience
Required:
Desired:
Training:
Security Clearance:
IC-CAP provides equal employment opportunities (EEO) to all applicants for employment without regard to race, color, religion, gender, sexual orientation, gender identity or expression, national origin, age, disability, genetic information, marital status. | |
ISSM 2 102-060 | | | | Information System Security Manager (ISSM) 2’s primary function serves as a principal advisor on all matters, technical and otherwise, involving the security of information systems under their purview. Primary support will be working within Special Access Programs (SAPs) supporting Department of Defense (DoD) agencies, such as HQ Air Force, Office of the Secretary of Defense, and Military Compartment efforts. The position will provide “day-to-day” support for Collateral, Sensitive Compartmented Information (SCI) and Special Access Program (SAP) activities.
Performance shall include:
Perform oversight of the development, implementation and evaluation of information system security program policy; special emphasis placed upon integration of existing SAP network infrastructures
Develop and oversee operational information systems security implementation policy and guidelines of network security, based upon the Risk Management Framework (RMF) with emphasize on Joint
Special Access Program Implementation Guide (JSIG) authorization process
Advise customer on Risk Management Framework (RMF) assessment and authorization issues
Perform risk assessments and make recommendations to DoD agency customers
Advise government program managers on security testing methodologies and processes
Evaluate authorization documentation and provide written recommendations for authorization to government PMs
Develop and maintain a formal Information Systems Security Program
Ensure that all IAOs, network administrators, and other cyber security personnel receive the necessary technical and security training to carry out their duties
Develop, review, endorse, and recommend action by the AO or DAO of system assessment documentation
Ensure approved procedures are in place for clearing, sanitizing, and destroying various types of hardware and media
Develop and execute security assessment plans that include verification that the features and assurances required for each protection level functioning
Maintain a and/or applicable repository for all system authorization documentation and modifications
Institute and implement a Configuration Control Board (CCB) charter
Develop policies and procedures for responding to security incidents, to include investigating and reporting security violations and incidents
Ensure proper protection or corrective measures have been taken when an incident or vulnerability has been discovered within a system
Ensure that data ownership and responsibilities are established for each authorization boundary, to include accountability, access rights, and special handling requirements
Ensure development and implementation of an information security education, training, and awareness program, to include attending, monitoring, and presenting local cyber security training.
Evaluate threats and vulnerabilities to ascertain whether additional safeguards are needed
Assess changes in the system, its environment, and operational needs that could affect the authorization
Ensure that authorization is accomplished a valid Authorization determination has been given for all authorization boundaries under your purview
Review AIS assessment plans
Coordinate with PSO or cognizant security official on approval of external information systems (e.g., guest systems, interconnected system with another organization)
Conduct periodic assessments of the security posture of the authorization boundaries
Ensure configuration management (CM) for security-relevant changes to software, hardware, and firmware and that they are properly documented
Ensure periodic testing is conducted to evaluate the security posture of IS by employing various intrusion/attack detection and monitoring tools (shared responsibility with ISSOs)
Ensure that system recovery and reconstitution processes developed and monitored to ensure that the authorization boundary can be recovered based on its availability level determination
Ensure all authorization documentation is current and accessible to properly authorized individuals
Ensure that system security requirements are addressed during all phases of the system life cycle
Develop Assured File Transfers (AFT) on accordance with the JSIG
Participate in self-inspections
Conduct the duties of the Information System Security Officer (ISSO) if one is not present and/or available.
Education and Experience:
Training and Certifications:
Security Clearance:
IC-CAP provides equal employment opportunities (EEO) to all applicants for employment without regard to race, color, religion, gender, sexual orientation, gender identity or expression, national origin, age, disability, genetic information, marital status. | |
ASR 1 102-057 | | | 03/07/2024 | Activity Security Representative 1's primary function is to provide multi-disciplined security support to a customer’s facility and organization. The position will provide “day-to-day” support for Collateral, Sensitive Compartmented Information (SCI) and Special Access Program (SAP) activities.
Duties May include:
Classification reviews of inbound and outbound correspondence
Assist in the maintenance of a document accountability database and associated correspondence
Processing inbound and outbound classified mail and receipt records
Perform destruction of classified materials
Process magnetic media for accountability
Reproduction support for classified materials
Maintain various daily logs for a variety of administrative functions associated with document control
Assist in the processing of inbound data and outbound data transfer files
Transfer electronic data files to internal customers
Maintain an extensive customer database point of contact listing
Assist with researching, processing, filing, and maintaining inbound and outbound visit notices
Escort facility visitors and maintains associated logs
Assist in the preparation of facility access control badges
Conduct entry and exit inspections
Assist in the maintenance of facility access control entry systems, to include visitor control
Perform data entry to the Personnel Access Security System database and maintain all customer sponsored billets and quota information
Assist in maintaining personnel security files for all personnel of the supported element
Follow and enforce the customer’s Standard Operating Procedures
Provide support for the security awareness and education programs
Perform miscellaneous administrative support functions as directed by the contractor site lead and/or the Senior Security Representative.
Education and Experience
Required:
Experience Education Equivalents:
Security Fundamentals Professional Certification (SFPC) counts towards 1 year of experience*
Special Program Security Certification (SPSC) counts towards 1 year of experience*
Maximum equivalent experience for SPED Certifications is no more than 3 years*
*Note: One year experience for each separate SPED Certification; not to exceed three (3) years
Desired
Bachelor’s degree
SAP Experience
Training:
Security Clearance:
IC-CAP provides equal employment opportunities (EEO) to all applicants for employment without regard to race, color, religion, gender, sexual orientation, gender identity or expression, national origin, age, disability, genetic information, marital status. | |
IT-IA Specialist 2 102-054 | | | | Information Technology-Information Assurance (IT-IA) Specialist 2 is working within Special Access Programs (SAPs) supporting Department of Defense (DoD) agencies, such as HQ Air Force, Office of the Secretary of Defense (OSD) and Military Compartments efforts. The position will provide “day-to-day” support for Collateral, Sensitive Compartmented Information (SCI) and Special Access Program (SAP) activities.
Performance shall include:
Establish complex operational software configuration controls and system interfaces for computer system(s) assigned
Maintain file servers, Firewalls, network access, Security Monitoring Systems and system documentation as required
Analyze and troubleshoot system anomalies to ensure optimum equipment performance
Prepare system for operational use and support operational tests
Review, prepare, and update authorization packages
Notify customer when changes occur that might affect authorization accreditation
Conduct cybersecurity portion of the self-inspection’s checklist
Review and provide technical and cyber security coordination on all Bodies of Evidence that makeup the authorization package
Identify any and all vulnerabilities and implement countermeasures
Ensure information systems and network appliances are operated, maintained, and disposed of in accordance with security policies and practices
Perform Video-Teleconferencing VTC System Administration, Scheduling, & Configuration
Provide External Information System(s) Client Support
Perform account creations, changes, & deletions on multiple authorization boundaries
Perform Help Desk & troubleshooting activities
Perform Hardware/Software System Configuration, upgrades and modifications
Perform system and network appliance patching activities
Provide Government-Issued Laptop Support
Assist in Media Control & Accountability activities
Perform COMSEC account/equipment management activities.
Education and Experience:
Training and Certifications:
Security Clearance:
IC-CAP provides equal employment opportunities (EEO) to all applicants for employment without regard to race, color, religion, gender, sexual orientation, gender identity or expression, national origin, age, disability, genetic information, marital status. | |
ISSO 2 102-052 | | | 07/31/2024 | Information System Security Officer (ISSO) 2 is responsible for ensuring the appropriate operational security posture is maintained for an information system and as such, works in close collaboration with the ISSM and ISO. The position shall have the detailed knowledge and expertise required to manage the security aspects of an information system and, in many organizations, is assigned responsibility for the day-to-day security operations of a system. This also will include physical and environmental protection, personnel security, incident handling, and security training and awareness. It will be required to work in close coordination with the ISSM and ISO in monitoring the information system(s) and its environment of operation to include developing and updating the authorization documentation, implementing configuration management across authorization boundaries. This will include assessing the security impact of those changes and making recommendation to the ISSM. The primary function is working within Special Access Programs (SAPs) supporting Department of Defense (DoD) agencies, such as HQ Air Force, Office of the Secretary of Defense (OSD) and Military Compartments efforts. The position will provide “day-to-day” support for Collateral, Sensitive Compartmented Information (SCI) and Special Access Program (SAP) activities.
Performance shall include:
Assist the ISSM in meeting their duties and responsibilities
Prepare, review, and update authorization packages
Ensure approved procedures are in place for clearing, sanitizing, and destroying various types of hardware and media
Notify ISSM when changes occur that might affect the authorization determination of the information system(s)
Conduct periodic reviews of information systems to ensure compliance with the security authorization package.
Coordinate any changes or modifications to hardware, software, or firmware of a system with the ISSM and AO/DAO prior to the change
Monitor system recovery processes to ensure security features and procedures are properly restored and functioning correctly
Ensure all IS security-related documentation is current and accessible to properly authorized individuals
Ensure audit records are collected, reviewed, and documented (to include any anomalies)
Attend required technical and security training (e.g., operating system, networking, security management) relative to assigned duties
Execute the cyber security portion of the self-inspection, to include provide security coordination and review of all system assessment plans
Identify cyber security vulnerabilities and assist with the implementation of the countermeasures for them
Prepare reports on the status of security safeguards applied to computer systems
Perform ISSO duties in support of in-house and external customers
Conduct security impact analysis activities and provide to the ISSM on all configuration management changes to the authorization boundaries.
Education and Experience:
Training and Certifications:
Security Clearance:
IC-CAP provides equal employment opportunities (EEO) to all applicants for employment without regard to race, color, religion, gender, sexual orientation, gender identity or expression, national origin, age, disability, genetic information, marital status. | |
ASR 1 102-051 | | | | Activity Security Representative 1’s primary function is to provide multi-disciplined security support to a customer’s facility and organization. The position will provide “day-to-day” support for Collateral, Sensitive Compartmented Information (SCI) and Special Access Program (SAP) activities.
Performance shall include:
Classification reviews of inbound and outbound correspondence
Assist in the maintenance of a document accountability database and associated correspondence
Processing inbound and outbound classified mail and receipt records
Perform destruction of classified materials
Process magnetic media for accountability
Reproduction support for classified materials
Maintain various daily logs for a variety of administrative functions associated with document control
Assist in the processing of inbound data and outbound data transfer files
Transfer electronic data files to internal customers
Maintain an extensive customer database point of contact listing
Assist with researching, processing, filing, and maintaining inbound and outbound visit notices
Escort facility visitors and maintains associated logs
Assist in the preparation of facility access control badges
Conduct entry and exit inspections
Assist in the maintenance of facility access control entry systems, to include visitor control
Perform data entry to the Personnel Access Security System database and maintain all customer sponsored billets and quota information
Assist in maintaining personnel security files for all personnel of the supported element
Follow and enforce the customer’s Standard Operating Procedures
Provide support for the security awareness and education programs
Perform miscellaneous administrative support functions as directed by the contractor site lead and/or the Senior Security Representative.
Education and Experience:
Required
Experience Education Equivalents:
Security Fundamentals Professional Certification (SFPC) counts towards 1 year of experience*
Special Program Security Certification (SPSC) counts towards 1 year of experience*
Maximum equivalent experience for SPED Certifications is no more than 3 years*
*Note: One year experience for each separate SPED Certification; not to exceed three (3) years
Desired
Bachelor’s degree
SAP Experience
Training and Certifications:
Security Clearance:
IC-CAP provides equal employment opportunities (EEO) to all applicants for employment without regard to race, color, religion, gender, sexual orientation, gender identity or expression, national origin, age, disability, genetic information, marital status. | |
PSR 2 102-048 | | | | Program Security Representative 2's primary function is to provide multi-discipline security support for one or more of the customer’s Special Access Programs (SAPs). The position will provide “day-to-day” multi-discipline analysis for Collateral, Sensitive Compartmented Information (SCI) and Special Access Program (SAP) activities.
Performance shall include:
Ensure strict adherence to the provisions of the NISPOM, its Supplement, the DoD Overprint, DCID, ICD, and SAP policy
Assist in developing and executing approved policies and procedures for safeguarding Special Access Program (SAP), Sensitive Compartmented Information (SCI) and collateral data in support of US military operations
Provide day-to-day security support that includes continuous assessment of procedures to identify shortfalls and provide appropriate recommendations for revising and improving security policies, procedures, and systems
Identify vulnerabilities, threats, and risks to test, training, and operational activities
Assist in developing, implementing, and training the Operations Security program
Assist in providing contractor and subordinate facility assistance and oversight
Brief all levels of personnel, both in the government and senior civilian services, on a variety of security related topics
Conduct and document SAP facility compliance reviews, follow-on facility reviews, and facility close outs
Monitor, report and track all corrective actions resulting from compliance reviews
Ensure timely notification of pertinent security matters to program technical and management staff
Conduct exploration of any loss, compromise, or suspected compromise of classified and/or
sensitive information, including conducting preliminary inquiries and generating damage assessments resulting from the loss of classified information.
Coordinate with SAP security personnel to ensure lessons learned are incorporated into the curriculum for the SAP security education & awareness program.
Education and Experience
Required:
Training and Certifications:
Security Clearance:
IC-CAP provides equal employment opportunities (EEO) to all applicants for employment without regard to race, color, religion, gender, sexual orientation, gender identity or expression, national origin, age, disability, genetic information, marital status. | |
PSR 1 102-047 | | | | Program Security Representative (PSR) 1’s primary function is to provide multi-discipline security support for one or more of the customer’s Special Access Programs (SAP). The position will provide “day-to-day” multi-discipline analysis for Collateral, Sensitive Compartmented Information (SCI) and SAP activities.
Performance shall include:
Ensure strict adherence to the provisions of the NISPOM, its Supplement, the DoD Overprint, DCID, ICD, and SAP policy
Assist in developing and executing approved policies and procedures for safeguarding SAP, SCI and collateral data in support of US military operations
Provide day-to-day security support that includes continuous assessment of procedures to identify shortfalls and provide appropriate recommendations for revising and improving security policies, procedures, and systems
Identify vulnerabilities, threats, and risks to test, training, and operational activities
Assist in developing, implementing, and training the Operations Security program
Assist in providing contractor and subordinate facility assistance and oversight
Brief all levels of personnel, both in the government and senior civilian services, on a variety of security related topics
Conduct and document SAP facility compliance reviews, follow-on facility reviews, and facility close-outs
Monitor, report and track all corrective actions resulting from compliance reviews
Ensure timely notification of pertinent security matters to program technical and management staff
Conduct exploration of any loss, compromise, or suspected compromise of classified and/or sensitive information, including conducting preliminary inquiries and generating damage assessments resulting from the loss of classified information.
Coordinate with SAP security personnel to ensure lessons learned are incorporated into the curriculum for the SAP security education & awareness program.
Education and Experience:
Training and Certifications:
Security Clearance:
IC-CAP provides equal employment opportunities (EEO) to all applicants for employment without regard to race, color, religion, gender, sexual orientation, gender identity or expression, national origin, age, disability, genetic information, marital status. | |
SCA 2 102-045 | | | | Security Control Assessor (SCA) 2 is responsible for conducting a comprehensive assessment of the management, operational, and technical security controls employed within or inherited by an IS to determine the overall effectiveness of the controls (i.e., the extent to which the controls are implemented correctly, operating as intended, and producing the desired outcome with respect to meeting the security requirements for the system). SCAs also provide an assessment of the severity of weaknesses or deficiencies discovered in the IS and its environment of operation and recommend corrective actions to address identified vulnerabilities. Responsibilities will cover Collateral, Sensitive Compartmented Information (SCI) and Special Access Program (SAP) activities within the customer’s area of responsibility.
Performance shall include:
Perform oversight of the development, implementation and evaluation of IS security program policy; special emphasis placed upon integration of existing SAP network infrastructure
Perform assessment of ISs, based upon the Risk Management Framework (RMF) methodology in accordance with the Joint SAP Implementation Guide (JSIG)
Advise the Information System Owner (ISO), Information Data Owner (IDO), Program Security Officer (PSO), and the Delegated and/or Authorizing Official (DAO/AO) on any assessment and authorization issues
Evaluate Authorization packages and make recommendation to the AO and/or DAO for authorization
Evaluate IS threats and vulnerabilities to determine whether additional safeguards are required
Advise the Government concerning the impact levels for Confidentiality, Integrity, and Availability for the information on a system
Ensure security assessments are completed and results documented and prepare the Security Assessment Report (SAR) for the Authorization boundary
Initiate a Plan of Action and Milestones (POA&M) with identified weaknesses for each Authorization Boundaries assessed, based on findings and recommendations from the SAR
Evaluate security assessment documentation and provide written recommendations for security authorization to the Government
Discuss recommendation for authorization and submit the security authorization package to the AO/DAO
Assess proposed changes to Authorization boundaries operating environment and mission needs to determine the continuation to operate.
Review and concur with all sanitization and clearing procedures in accordance with Government guidance and/or policy
Assist the Government compliance inspections
Assist the Government with security incidents that relate to cybersecurity and ensure that the proper and corrective measures have been taken
Ensure organization are addressing and conducting all phases of the system development life cycle (SDLC)
Evaluate Hardware and Software to determine security impact that it might have on Authorization boundaries
Evaluate the effectiveness and implementation of Continuous Monitoring Plans
Represent the customer on inspection teams.
Required Education and Experience:
Bachelor's degree and 7-9 years related experience
-OR- 11-13 years related experience in lieu of degree
Prior performance in the role of ISSO and ISSM or SCA
4+ years experience in SAP, SCI, or Collateral Information Systems security and implentation of regulations identified in the description of duties
Training and Certifications:
Security Clearance:
IC-CAP provides equal employment opportunities (EEO) to all applicants for employment without regard to race, color, religion, gender, sexual orientation, gender identity or expression, national origin, age, disability, genetic information, marital status. | |
PSR 1 102-043 | | | | Program Security Representative (PSR) 1
The primary function is to provide multi-discipline security support for one or more of the customer’s Special Access Programs (SAP). The position will provide “day-to-day” multi-discipline analysis for Collateral, Sensitive Compartmented Information (SCI) and SAP activities.
Duties may include:
Ensure strict adherence to the provisions of the NISPOM, its Supplement, the DoD Overprint, DCID, ICD, and SAP policy
Assist in developing and executing approved policies and procedures for safeguarding SAP, SCI and collateral data in support of US military operations
Provide day-to-day security support that includes continuous assessment of procedures to identify shortfalls and provide appropriate recommendations for revising and improving security policies, procedures, and systems
Identify vulnerabilities, threats, and risks to test, training, and operational activities
Assist in developing, implementing, and training the Operations Security program
Assist in providing contractor and subordinate facility assistance and oversight
Brief all levels of personnel, both in the government and senior civilian services, on a variety of security related topics
Conduct and document SAP facility compliance reviews, follow-on facility reviews, and facility close-outs
Monitor, report and track all corrective actions resulting from compliance reviews
Ensure timely notification of pertinent security matters to program technical and management staff
Conduct exploration of any loss, compromise, or suspected compromise of classified and/or sensitive information, including conducting preliminary inquiries and generating damage assessments resulting from the loss of classified information.
Coordinate with SAP security personnel to ensure lessons learned are incorporated into the curriculum for the SAP security education & awareness program.
Education and Experience
Required:
Bachelor's degree -or- 4 years of additional, relevant experience, in lieu of degree
5-7 years related experience (Security Fundamentals Professional Certification (SFPC) counts towards 3 years of experience)
SAP Experience
Training:
Security Clearance:
IC-CAP provides equal employment opportunities (EEO) to all applicants for employment without regard to race, color, religion, gender, sexual orientation, gender identity or expression, national origin, age, disability, genetic information, marital status. | |
Net-Sys Admin 2 102-042 | | | | Network-System Administrator (Net-Sys Admin) 2 will be to organize, install, and support government organization’s computer systems, including local area networks (LANs), wide area networks (WANs), network segments, intranets, and other data communication systems. This will also include helping architect, design and analyze network models. It will require participation in decisions about buying future hardware or software to upgrade organization’s infrastructure. This position might be called upon to provide technical support to computer users to help solve users’ problems. This position will support activities within Special Access Programs (SAPs) supporting Department of Defense (DoD) agencies, such as HQ Air Force, Office of the Secretary of Defense (OSD) and Military Compartments efforts. The position will provide “day-to-day” support for Collateral, Sensitive Compartmented Information (SCI) and Special Access Program (SAP) activities.
Performance shall include:
Ability to operate under supervision
Execute day to day management and operations of systems and networks
Manage COTS & GOTS products to collect, display and remediate a variety of automated system security and system operations/performance functions and metrics
Follow Operations and Maintenance (O&M) checklists to maintain the service (daily, weekly, monthly, yearly O&M checklists); build Tactics, Techniques and Processes (TTPs) and Standard Operating Processes (SOPs) associated with service checklists
Operate monitoring tools/capabilities with the enterprise security information and event management (SIEM) and create/tailor complex event alarms/rules and summary reports
Assist in analyzing technical risk, upon request, of emerging cybersecurity tools and processes
Work as part of a security incident response team as needed
Working technical competency in one or more of the following supported platforms: Microsoft Windows Server, Red Hat Enterprise Linux servers, MS Hyper-V/VMWare/ESx/Xen Hypervisors, Enterprise networking/firewalls/intrusion detection/prevention systems, forensic analysis/vulnerability assessment, Group Policy management and configuration, Scripting, BMC Footprints, WSUS, , Lumension, Bitlocker, SQL Server 2012, TomCat, IIS, Windows Server2012r2/2016, Win 10, Red Hat 6.5, Microsoft Office Toolkits, SEIMs, Logrhythm, ACAS/Nessus/SCAP, mandatory/role-based access control concepts (e.g. SE Linux extensions to RHEL, PitBull, AppArmor, and Sentris) , video teleconferencing/VOIP, Oracle/MS SQL database security, and Apache/IIS Web server security.
Education and Experience:
Training and Certifications:
Security Clearance:
IC-CAP provides equal employment opportunities (EEO) to all applicants for employment without regard to race, color, religion, gender, sexual orientation, gender identity or expression, national origin, age, disability, genetic information, marital status. | |
ISSM 2 102-041 | | | | Information System Security Manager (ISSM) 2 primary function serves as a principal advisor on all matters, technical and otherwise, involving the security of information systems under their purview. Primary support will be working within Special Access Programs (SAP) supporting Department of Defense (DoD) agencies, such as HQ Air Force, Office of the Secretary of Defense, and Military Compartment efforts. The position will provide “day-to-day” support for Collateral, Sensitive Compartmented Information (SCI) and SAP activities.
Duties may include:
Perform oversight of the development, implementation and evaluation of information system security program policy; special emphasis placed upon integration of existing SAP network infrastructures
Develop and oversee operational information systems security implementation policy and guidelines of network security, based upon the Risk Management Framework (RMF) with emphasize on Joint
Special Access Program Implementation Guide (JSIG) authorization process
Advise customer on RMF assessment and authorization issues
Perform risk assessments and make recommendations to DoD agency customers
Advise government program managers on security testing methodologies and processes
Evaluate authorization documentation and provide written recommendations for authorization to government PMs
Develop and maintain a formal Information Systems Security Program
Ensure that all IAOs, network administrators, and other cyber security personnel receive the necessary technical and security training to carry out their duties
Develop, review, endorse, and recommend action by the AO or DAO of system assessment documentation
Ensure approved procedures are in place for clearing, sanitizing, and destroying various types of hardware and media
Develop and execute security assessment plans that include verification that the features and assurances required for each protection level functioning
Maintain and/or applicable repository for all system authorization documentation and modifications
Institute and implement a Configuration Control Board charter
Develop policies and procedures for responding to security incidents, to include investigating and reporting security violations and incidents
Ensure proper protection or corrective measures have been taken when an incident or vulnerability has been discovered within a system
Ensure that data ownership and responsibilities are established for each authorization boundary, to include accountability, access rights, and special handling requirements
Ensure development and implementation of an information security education, training, and awareness program, to include attending, monitoring, and presenting local cyber security training
Evaluate threats and vulnerabilities to ascertain whether additional safeguards are needed
Assess changes in the system, its environment, and operational needs that could affect the authorization
Ensure that authorization is accomplished a valid Authorization determination has been given for all authorization boundaries under your purview
Review AIS assessment plans
Coordinate with PSO or cognizant security official on approval of external information systems (e.g., guest systems, interconnected system with another organization)
Conduct periodic assessments of the security posture of the authorization boundaries
Ensure configuration management for security-relevant changes to software, hardware, and firmware and that they are properly documented
Ensure periodic testing is conducted to evaluate the security posture of IS by employing various intrusion/attack detection and monitoring tools (shared responsibility with ISSOs)
Ensure that system recovery and reconstitution processes developed and monitored to ensure that the authorization boundary can be recovered based on its availability level determination
Ensure all authorization documentation is current and accessible to properly authorized individuals
Ensure that system security requirements are addressed during all phases of the system life cycle
Develop Assured File Transfers in accordance with the JSIG
Participate in self-inspections
Conduct the duties of the ISSO if one is not present and/or available
Education and Experience:
Required:
Bachelor's degree -or- 4 years of additional, relevant experience, in lieu of degree
7-9 years related experience
Prior performance in roles such as ISSO or ISSM
SAP experience
Training:
Security Clearance:
IC-CAP provides equal employment opportunities (EEO) to all applicants for employment without regard to race, color, religion, gender, sexual orientation, gender identity or expression, national origin, age, disability, genetic information, marital status. | |
ISSM 1 102-040 | | | | Information System Security Manager (ISSM) 1 primary function serves as a principal advisor on all matters, technical and otherwise, involving the security of information systems under their purview. Primary support will be working within Special Access Programs (SAPs) supporting Department of Defense (DoD) agencies, such as HQ Air Force, Office of the Secretary of Defense, and Military Compartment efforts. The position will provide “day-to-day” support for Collateral, Sensitive Compartmented Information (SCI) and Special Access Program (SAP) activities.
Duties may include:
Perform oversight of the development, implementation and evaluation of information system security program policy; special emphasis placed upon integration of existing SAP network infrastructures
Develop and oversee operational information systems security implementation policy and guidelines of network security, based upon the Risk Management Framework (RMF) with emphasize on Joint
Special Access Program Implementation Guide (JSIG) authorization process
Advise customer on Risk Management Framework (RMF) assessment and authorization issues
Perform risk assessments and make recommendations to DoD agency customers
Advise government program managers on security testing methodologies and processes
Evaluate authorization documentation and provide written recommendations for authorization to government PMs
Develop and maintain a formal Information Systems Security Program
Ensure that all IAOs, network administrators, and other cyber security personnel receive the necessary technical and security training to carry out their duties
Develop, review, endorse, and recommend action by the AO or DAO of system assessment documentation
Ensure approved procedures are in place for clearing, sanitizing, and destroying various types of hardware and media
Develop and execute security assessment plans that include verification that the features and assurances required for each protection level functioning
Maintain a and/or applicable repository for all system authorization documentation and modifications
Institute and implement a Configuration Control Board (CCB) charter
Develop policies and procedures for responding to security incidents, to include investigating and reporting security violations and incidents
Ensure proper protection or corrective measures have been taken when an incident or vulnerability has been discovered within a system
Ensure that data ownership and responsibilities are established for each authorization boundary, to include accountability, access rights, and special handling requirements
Ensure development and implementation of an information security education, training, and awareness program, to include attending, monitoring, and presenting local cyber security training.
Evaluate threats and vulnerabilities to ascertain whether additional safeguards are needed
Assess changes in the system, its environment, and operational needs that could affect the authorization
Ensure that authorization is accomplished a valid Authorization determination has been given for all authorization boundaries under your purview
Review AIS assessment plans
Coordinate with PSO or cognizant security official on approval of external information systems (e.g., guest systems, interconnected system with another organization)
Conduct periodic assessments of the security posture of the authorization boundaries
Ensure configuration management (CM) for security-relevant changes to software, hardware, and firmware and that they are properly documented
Ensure periodic testing is conducted to evaluate the security posture of IS by employing various intrusion/attack detection and monitoring tools (shared responsibility with ISSOs)
Ensure that system recovery and reconstitution processes developed and monitored to ensure that the authorization boundary can be recovered based on its availability level determination
Ensure all authorization documentation is current and accessible to properly authorized individuals
Ensure that system security requirements are addressed during all phases of the system life cycle
Develop Assured File Transfers (AFT) on accordance with the JSIG
Participate in self-inspections
Conduct the duties of the Information System Security Officer (ISSO) if one is not present and/or available.
Education and Experience
Required:
Bachelor's degree AND 5 years of related experience -OR- Associate's degree AND 7 years of related experience -OR- HS/GED AND 9 years of relevant experience in lieu of degree
Prior performance in roles such as ISSO or ISSM
SAP Experience
Desired:
Training:
Security Clearance:
IC-CAP provides equal employment opportunities (EEO) to all applicants for employment without regard to race, color, religion, gender, sexual orientation, gender identity or expression, national origin, age, disability, genetic information, marital status. | |
ISSO 2 102-038 | | | 07/29/2024 | Information System Security Officer (ISSO) 2 is responsible for ensuring the appropriate operational security posture is maintained for an information system and as such, works in close collaboration with the ISSM and ISO. The position shall have the detailed knowledge and expertise required to manage the security aspects of an information system and, in many organizations, is assigned responsibility for the day-to-day security operations of a system. This also will include physical and environmental protection, personnel security, incident handling, and security training and awareness. It will be required to work in close coordination with the ISSM and ISO in monitoring the information system(s) and its environment of operation to include developing and updating the authorization documentation, implementing configuration management across authorization boundaries. This will include assessing the security impact of those changes and making recommendation to the ISSM. The primary function is working within Special Access Programs (SAPs) supporting Department of Defense (DoD) agencies, such as HQ Air Force, Office of the Secretary of Defense (OSD) and Military Compartments efforts. The position will provide “day-to-day” support for Collateral, Sensitive Compartmented Information (SCI) and Special Access Program (SAP) activities.
Duties may include:
Assist the ISSM in meeting their duties and responsibilities
Prepare, review, and update authorization packages
Ensure approved procedures are in place for clearing, sanitizing, and destroying various types of hardware and media
Notify ISSM when changes occur that might affect the authorization determination of the information system(s)
Conduct periodic reviews of information systems to ensure compliance with the security authorization package
Coordinate any changes or modifications to hardware, software, or firmware of a system with the ISSM and AO/DAO prior to the change
Monitor system recovery processes to ensure security features and procedures are properly restored and functioning correctly
Ensure all IS security-related documentation is current and accessible to properly authorized individuals
Ensure audit records are collected, reviewed, and documented (to include any anomalies)
Attend required technical and security training (e.g., operating system, networking, security management) relative to assigned duties
Execute the cyber security portion of the self-inspection, to include provide security coordination and review of all system assessment plans
Identify cyber security vulnerabilities and assist with the implementation of the countermeasures for them
Prepare reports on the status of security safeguards applied to computer systems
Perform ISSO duties in support of in-house and external customers
Conduct security impact analysis activities and provide to the ISSM on all configuration management changes to the authorization boundaries.
Experience and Education
Required:
Bachelor's degree -OR- 4 additional years of experience in lieu of degree
2-5 years related experience, especially in developing RMF packages or bodies of evidence
Prior performance in roles such as System/Network Administrator or ISSO
SAP experience
Training and Certifications:
Security Clearance:
IC-CAP provides equal employment opportunities (EEO) to all applicants for employment without regard to race, color, religion, gender, sexual orientation, gender identity or expression, national origin, age, disability, genetic information, marital status. | |
Net-Sys Admin 3 102-039 | | | | Network-System Administrator 3's primary Function will be to Organize, install, and support government organization’s computer systems, including local area networks (LANs), wide area networks (WANs), network segments, intranets, and other data communication systems. This will also include helping architect, design and analyze network models. It will require participation in decisions about buying future hardware or software to upgrade organization’s infrastructure. This position might be called upon to provide technical support to computer users to help solve users’ problems. This position will support activities within Special Access Programs (SAPs) supporting Department of Defense (DoD) agencies, such as HQ Air Force, Office of the Secretary of Defense (OSD) and Military Compartments efforts. The position will provide “day-to-day” support for Collateral, Sensitive Compartmented Information (SCI) and Special Access Program (SAP) activities.
Duties May include:
Able to perform self-sustaining and work with little to no oversight
Lead IT ops team on day to day management and operations of Networks and implement capabilities vetted through Cybersecurity, ISSE and higher headquarters to maintain JSIG/RMF Authority to Operate and maintain Continuous Monitoring tools and processes
Manage COTS & GOTS products to collect, display and remediate a variety of automated system.
security and system operations/performance functions and metrics.
Assist during security assessments of servers/network devices/security appliances
Assist during security assessments with regard to accuracy and efficiency
Assist with Creation of operational Operations and Maintenance (O&M) checklists to maintain the service (daily, weekly, monthly, yearly O&M checklists); build Tactics, Techniques and Processes (TTPs) and Standard Operating Processes (SOPs) associated with service checklists
Manage and operate monitoring tools/capabilities with the enterprise security information and event
management (SIEM) and create/tailor complex event alarms/rules and summary reports
Execute cybersecurity operations procedures for day to day network management, operations and maintenance
Monitor/analyze output of cybersecurity related tools for reportable security incidents and residual risk
Assist in analyzing technical risk, upon request, of emerging cybersecurity tools and processes
Work as part of a security incident response team as needed
Assist ISSM/ISSO/ISSE with the Integration/Development new techniques to improve
Confidentiality, Integrity, and Availability for networks/systems operating at various classification levels
Advanced technical competency in one or more of the following supported platforms: Microsoft Windows Server, Active Directory Red Hat Enterprise Linux servers, MS Hyper-V/VMWare/ESx/Xen Hypervisors, Enterprise networking/firewalls/intrusion detection/prevention systems, forensic analysis/vulnerability assessment, Group Policy management and configuration, Scripting, BMC Footprints, WSUS, , Lumension, Bitlocker, SQL Server 2012, TomCat, IIS, Windows Server 2012r2/2016, Win 10, Red Hat 6.5, Microsoft Office Toolkits, SEIMs, Logrhythm, ACAS/Nessus/SCAP, mandatory/role-based access control concepts (e.g. SE Linux extensions to RHEL, PitBull, AppArmor, and Sentris) , video teleconferencing/VOIP, Oracle/MS SQL database security, and Apache/IIS Web server security.
Education and Experience
Required:
Training:
Security Clearance:
IC-CAP provides equal employment opportunities (EEO) to all applicants for employment without regard to race, color, religion, gender, sexual orientation, gender identity or expression, national origin, age, disability, genetic information, marital status. | |
ASR 2 102-037 | | | | Activity Security Representative 2's the primary function is to provide multi-disciplined security support to a customer’s facility and organization. The position will provide “day-to-day” support for Collateral, Sensitive Compartmented Information (SCI) and Special Access Program (SAP) activities.
Performance shall include:
Classification reviews of inbound and outbound correspondence
Assist in the maintenance of a document accountability database and associated correspondence
Processing inbound and outbound classified mail and receipt records
Perform destruction of classified materials
Process magnetic media for accountability
Reproduction support for classified materials.
Maintain various daily logs for a variety of administrative functions associated with document control
Assist in the processing of inbound data and outbound data transfer files
Transfer electronic data files to internal customers
Maintain an extensive customer database point of contact listing
Assist with researching, processing, filing, and maintaining inbound and outbound visit notices
Escort facility visitors and maintains associated logs
Assist in the preparation of facility access control badges
Conduct entry and exit inspections
Assist in the maintenance of facility access control entry systems, to include visitor control
Perform data entry to the Personnel Access Security System database and maintain all customer sponsored billets and quota information
Assist in maintaining personnel security files for all personnel of the supported element
Follow and enforce the customer’s Standard Operating Procedures
Provide support for the security awareness and education programs
Perform miscellaneous administrative support functions as directed by the contractor site lead and/or the Senior Security Representative.
Education and Experience
Required:
Desired:
Training and Certifications:
Security Clearance:
IC-CAP provides equal employment opportunities (EEO) to all applicants for employment without regard to race, color, religion, gender, sexual orientation, gender identity or expression, national origin, age, disability, genetic information, marital status. | |
ISSO 1 102-036 | | | | Information System Security Officer (ISSO) 1 is responsible for ensuring the appropriate operational security posture is maintained for an information system and as such, works in close collaboration with the ISSM and ISO. The position shall have the detailed knowledge and expertise required to manage the security aspects of an information system and, in many organizations, is assigned responsibility for the day-to-day security operations of a system. This also will include physical and environmental protection, personnel security, incident handling, and security training and awareness. It will be required to work in close coordination with the ISSM and ISO in monitoring the information system(s) and its environment of operation to include developing and updating the authorization documentation, implementing configuration management across authorization boundaries. This will include assessing the security impact of those changes and making recommendation to the ISSM. The primary function is working within Special Access Programs (SAPs) supporting Department of Defense (DoD) agencies, such as HQ Air Force, Office of the Secretary of Defense (OSD) and Military Compartments efforts. The position will provide “day-to-day” support for Collateral, Sensitive Compartmented Information (SCI) and Special Access Program (SAP) activities
Performance shall include:
Assist the ISSM in meeting their duties and responsibilities
Prepare, review, and update authorization packages
Ensure approved procedures are in place for clearing, sanitizing, and destroying various types of hardware and media
Notify ISSM when changes occur that might affect the authorization determination of the information system(s)
Conduct periodic reviews of information systems to ensure compliance with the security authorization package.
Coordinate any changes or modifications to hardware, software, or firmware of a system with the ISSM and AO/DAO prior to the change
Monitor system recovery processes to ensure security features and procedures are properly restored and functioning correctly
Ensure all IS security-related documentation is current and accessible to properly authorized individuals
Ensure audit records are collected, reviewed, and documented (to include any anomalies)
Attend required technical and security training (e.g., operating system, networking, security management) relative to assigned duties
Execute the cyber security portion of the self-inspection, to include provide security coordination and review of all system assessment plans
Identify cyber security vulnerabilities and assist with the implementation of the countermeasures for them
Prepare reports on the status of security safeguards applied to computer systems
Perform ISSO duties in support of in-house and external customers.
Education and Experience:
Desired:
Training and Certifications:
Security Clearance:
IC-CAP provides equal employment opportunities (EEO) to all applicants for employment without regard to race, color, religion, gender, sexual orientation, gender identity or expression, national origin, age, disability, genetic information, marital status. | |