**This position is fully remote
**This position requires an active Secret or Top Secret clearance
**This position is supporting the Marine Corps
Perform cybersecurity tasks for Global Combat Support System- Marine Corps (GCSS-MC) applications, components, sub-components, and environments in support of the GCSS-MC system, cloud migration effort, and audit remediation.
o Verify and validate that security updates and patches are tested and applied to software and operating systems. Document all findings in a weekly report.
o Generate software quality code reviews with Government provided automated tool(s).
o Maintain a security Plan of Action and Milestones (POA&M) that lists all vulnerabilities identified by every assessment, and when that assessment identified the vulnerability, in accordance with DoD and USMC Risk Management Framework policies.
o Review, implement, and maintain the role-based access controls (RBAC) in support of the GCSS-MC and sub-components privileged user access.
o Review information assurance vulnerability management (IAVMs), communications tasking orders (CTOs), Marine Corps directives (MCDs), operational directives (OPDIRs), vulnerability alerts, and vendor notifications to determine applicability to GCSS-MC/LCM Family of Systems (FoS) and to assess impact and provide assessment to the ISSM. In addition, track, report status, and provide remediation suggestions for the vulnerabilities.
o Support all activities required for maintaining the authority to operate (ATO) and Federal Information Security Management Act (FISMA) compliances. These activities include, but are not limited to:
§ Annual Security Reviews, Annual Security Control testing, Annual Contingency Plan testing, and quarterly update and submission of a quarterly Plan of Action and Milestones (POA&M).
· Support cybersecurity testing by generating:
o A cybersecurity detailed test plan (DTP) required when testing for accreditation that identifies specifically how the system should be tested
o Thorough risk assessment that identifies the security posture of the system.
o Conduct testing (pre/post) scans for the LI2S-MC systems/requirements related to system accreditations.
· Participate in cybersecurity discussions and vulnerability assessment scan reviews and provide technical guidance and solutions implementing cybersecurity best practices which will increase the security of the system and mitigate or eliminate vulnerabilities. The technical guidance and solutions must align with applicable security technical implementation guides (STIGs).
· Generate, review, and update cybersecurity documentation as required by MCSC risk management framework (RMF) processes.
· Support cyber readiness inspection (CRI) and IV&V events as required by the GCSS-MC PMO ISSM. This task includes but is not limited to:
o Reviewing and updating systems security documentation, performing pre-assessment scans, analyzing vulnerability scan results, analyzing, and updating configuration documentation, evaluating STIGs, evaluating test results, preparing, and reviewing POA&Ms, and providing remediation options for vulnerabilities.
o All vulnerabilities shall be identified in the Security POA&M.
· Other duties as assigned.
BA/BS degree from an accredited college or university; MA/MS degree preferred.
By providing your phone number, you consent to: (1) receive automated text messages and calls from the Judge Group, Inc. and its affiliates (collectively "Judge") to such phone number regarding job opportunities, your job application, and for other related purposes. Message & data rates apply and message frequency may vary. Consistent with Judge's Privacy Policy, information obtained from your consent will not be shared with third parties for marketing/promotional purposes. Reply STOP to opt out of receiving telephone calls and text messages from Judge and HELP for help.
The Judge Group Inc., is a leading professional services firm specializing in talent, technology, and learning solutions. We consult, staff, train, and solve. Through our work we make people and organizations better. Our services are successfully delivered through a network of more than 30 offices across the United States, Canada, and India.
The Judge Group is proud to partner with the best and brightest companies in business today, including over 60 of the Fortune 100. We serve organizations in financial services, healthcare, life sciences, insurance, government (including aerospace and defense), manufacturing, and technology and telecommunications. If you would like to learn more about The Judge Group visit www.judge.com or call toll free (800) 360-4474.