This position supports the NIWC PAC Information Technology Management Support Services contract. The Cybersecurity Engineer III will provide hands-on cybersecurity and accreditation support for a DoD environment, with a strong focus on RMF, A&A, eMASS, security controls, STIGs, POA&Ms, and ATO activities.
Support Assessment & Authorization (A&A) activities and the Risk Management Framework (RMF) accreditation lifecycle.
Develop, maintain, and update A&A documentation, including SSPs, SAPs, SARs, and POA&Ms.
Manage accreditation activities within eMASS, including scheduled tasking, ATO-related activities, quarterly IV&V, STIG checks, ASRs, and monthly POA&M updates.
Test and evaluate security controls based on security categorization, applicable overlays, and control tailoring.
Conduct security assessments, identify vulnerabilities, document findings, and recommend appropriate remediation.
Develop and maintain accurate POA&Ms, including mitigation statements, milestone tracking, and alignment with applicable security controls.
Perform and support DISA STIG assessments and remediation activities.
Support cybersecurity monitoring and incident response activities, including incident triage and impact assessment.
Support ATO, ATC, IATC, and IATT submissions and resubmissions, as applicable.
Maintain DISA circuit connections (CCSDs), system inheritance relationships, and accreditation workflow schedules.
Apply security requirements across classified, intelligence, privacy, and other applicable environments.
10+ years of cybersecurity or incident response experience, preferably within DoD or federal environments.
Active Secret clearance.
Strong hands-on experience with RMF and Assessment & Authorization (A&A).
Hands-on experience with eMASS and DoD accreditation processes.
System Security Plans (SSPs)
Security Assessment Plans (SAPs)
Security Assessment Reports (SARs)
Plans of Actions & Milestones (POA&Ms)
Strong experience with security controls, DISA STIGs, vulnerability assessment, testing, and remediation.
Experience supporting cybersecurity monitoring, security testing, auditing, and risk assessment.
Ability to work 100% onsite in San Diego, CA at the NIWC PAC location.
IAM Level II certification required. One of the following:
CISSP or CISSP Associate
CASP+
CAP
CGRC
CISM
GSLC
Preferred: CISSP
| Location | San Diego, California |
Browse dozens of recruiter approved resume templates, layouts and formats. Choose your favorite and make it your own in minutes.
Free resume templatesImprove your existing resume or start from scratch and create a standout, ATS-friendly resume. Add job-specific content, download and apply.
Free resume builder