Cyber Security Analyst (Isso)
Current Performs the ongoing RMF/A&A/ATO projects in support of client security systems using NIST SP 800-37 Rev 1 as a guide. Extensive knowledge in Categorizing Information Systems (using FIPS 199 and NIST SP 800-60 Vol 2 Rev 1 as a guide) Selects and implements applicable security controls (technical, operational and management) using NIST SP 800-53 Rev 4 as a guide. Create, update and revise System Security Plans, Contingency Plans, Incident Reports and Plan of Action & Milestones (POA&Ms). Independently develop a variety of Security Authorization deliverables including; System Security Plans, Security Assessments Reports, Configuration Management Plans, Contingency Plans, and POA&M. Reviews Privacy Impact Assessment (PIA) document after a positive PTA is created and ensure PII findings are recorded in the System of Record Notice (SORN) Generate, review and update System Security Plans (SSP) against NIST 800-18 and NIST 800 53 requirements. Performs ongoing continuous monitoring using NIST 800-137 Rev 1 as a guide.