As an F-35 Classified Cybersecurity Security team member you will be supporting Special Access Programs (SAPs) and ensure classified Information Systems (IS) meet cybersecurity requirements and government directives by interpreting the Joint Special Access Program (SAP) Implementation Guide (JSIG) in determining technical Information Assurance (IA) requirements and ensure proper security implementation of the Risk Management Framework (RMF).
Perform system vulnerability risk assessments, Assured File Transfers, hardware/software configuration management, media management, data integrity containments and investigations on IA related security violations/incidents, to include updating the Configuration and Media Management Databases. Develop system documentation for information system authorization, security management, and continuous monitoring of both networked and standalone classified systems.
Ensure security tool functionality across interconnected WANs, ISOLAN, standalones, and Lab environments. Determine technical Information Assurance (IA) requirements and ensure proper security implementation of the Risk Management Framework (RMF). Identify systems and tools to improve security. Work through procurement and with the administration teams to deploy the security tools, configure, and maintain them. Develop technical solutions to complex problems which require extensive technical expertise and ingenuity.
Provide cybersecurity education and training for all system users on risk mitigation strategies. Conduct required internal IA assessments of the F-35 Classified networks and SAP Facilities (SAPFs) along with interpreting and implementing the policies and procedures required to maintain an Authority to Operate (ATO) and coordinate the destruction of classified material and media.
Collaborate with F‑35 supplier organizations to prepare, review, and submit ATO documentation; facilitate monthly meetings, train ISSOs on SAPF Equipment Removal Packages, software/hardware approvals, and ATO evidence; act as liaison between government customers and suppliers.
Represent the organization as a Subject Matter Expert in Information Assurance requirements.
Perform other associated duties as required.
Ensure compliance with governing documents and security policies and assist in regulatory periodic assessments. Implements and tests state-of-the-art secure operating systems, networks, and database solutions. Stays current with system vulnerabilities and provides current security training to all system users. Conducts risk assessments and provides recommendations for secure implementation and compliance in accordance with government regulations and information assurance/cybersecurity guidelines. Creates, maintains and submits information system security documents and reports to regulatory agencies. Assesses and mitigates system security threats/risks throughout the program life cycle; validates system security requirements definition and analysis; establishes system security documentation; assists with the implementation of security procedures; verifies information system security requirements; performs information system certification and accreditation planning, testing, assessing and liaison activities. Familiar with information system security architectural documentation standards. Able to apply information assurance / cyber security standards, directives, guidance and policies to an architectural/risk based framework. Provide architectural / risk based analysis of information assurance / cyber security features and relate existing system to future needs and trends and requirements. For engineers providing security information assurance, use Info Assurance Engineer (E254, L254). For security professionals providing systems security analysis, use Computer Systems Security Analysis (E121, L121).