Technical SkillsNIST SP 800-37 (RMF), 800-53 / 53A / 53B, 800-137 (ISCM), FIPS 199 and FIPS 200DHS 4300A Sensitive Systems Handbook and the DHS Systems Engineering Life Cycle (SELC)Government-designated A&A repositories and tracking tools (e.g., eMASS or successor)DISA Security Technical Implementation Guides (STIGs) and Security Requirements Guides (SRGs)Government-approved vulnerability scanning and compliance tooling (e.g., ACAS/Nessus, SCAP-validated scanners)POA&M development, tracking, and closure, including waiver and risk acceptance packagesOperational Technology (OT), Platform IT (PIT), and industrial control system environments, including constraints on agent-based toolingSecurity Impact Assessments and change management board participationInterconnection documentation: ISAs, MOUs, SLAsContingency planning, contingency plan testing, and disaster recovery failover exercisesAudit log review, audit trigger configuration, and incident reporting workflowsSecurity Readiness Reviews for operating systems and applicationsEducationBachelor's degree in cybersecurity, computer science, information systems, engineering, or a related field. Any one of the following satisfies the requirement:CGRC - Governance, Risk and Compliance Certification (formerly CAP)CISSP - Certified Information Systems Security Professional (or CISSP Associate)CISM - Certified Information Security ManagerCASP+ - CompTIA Advanced Security PractitionerGSLC - GIAC Security Leadership CertificationSecurity+ CE - CompTIA Security+ Continuing Education (Level I only)Certification requirements are subject to confirmation against COMDTINST M2620.2 (series) Appendix D, the controlling USCG certification matrix.