logo

View all jobs

Risk Management Framework (RMF) Navy Qualified Validator (NQV)

Norfolk, Virginia · Information Technology
Responsibilities:
  • Conduct security assessments of system security plans to help ensure that plans provide security controls for information systems that meet stated security requirements.
  • Conduct comprehensive assessments of the management, operational, and technical security controls employed within or inherited by an information system to determine the overall effectiveness of the controls.
  • Ensure compliance of security configurations for IT systems and aid in providing clear and concise processes and procedures for the implementation and enforcement of system security configurations.
  • Support the risk management process by helping to determine and assign risk impact ratings in accordance with Information Assurance standards guidelines and methodologies and by aiding in the development and maintenance of Plans of Action and Milestones (POA&Ms) for IT systems identified in the Risk Management Framework (RMF) process and annual security assessments of IT systems.
  • Provide assessments of the severity of weaknesses or deficiencies discovered in the information system and its environment of operation and recommend corrective actions to address identified vulnerabilities and prepare the security assessment reports containing the results and findings from system security assessments.
  • Demonstrated knowledge and experience of IA / INFOSEC concepts and requirements: Firewall Policy, Ports & Protocols, Cybersecurity, Cybersafe
  • Knowledge of the DOD A&A process and standards: DIACAP, RMF
  • System / network vulnerability analysis
  • Risk assessment and risk mitigation analysis
  • Security Test and Evaluation (ST&E)
  • Contingency planning
  • Knowledge and experience of the Defense Information Systems Agency published Security Technical Information Guidance (STIG) requirements and implementation/compliance process.
  • Knowledge of virtualization, networking, Windows and Linux Operating Systems, and storage and backup.
  • Possess strong oral and technical writing skills.
  • Possess extensive knowledge of the US Government Information Assurance Security Processes.
  • Knowledge of Information Assurance policies and procedures, and processes are also desired.
  • Practical experience in Cybersecurity, Engineering, T&E or A&A.
Navy Experience:
  • Experience independently performing the NQV Level III activities defined in the Navy’s RMF.
  • Process Guide and successfully completing all required validator tasks for one or more Security Authorization
    Packages through the SCA within the past year (or equivalent direct DoD RMF A&A experience as approved by the IA TA).
  • Navy IT sites, systems and infrastructure: In-depth familiarity and understanding of Navy IT sites, systems and infrastructure (Including NCS and PIT); applies Navy RMF guidance to Navy A&A efforts (or equivalent direct DoD RMF A&A experience as approved by the IA TA).
  • Test & Evaluation: Experience in allocating assigned security controls into assessment objectives and procedures, developing and executing Security Assessment Plans by selecting and tailoring appropriate assessment methods, depth and coverage, and applying sequencing to reduce duplication of effort and provide cost effective assessment solutions.
  • The Validator shall possess a thorough understanding of Navy’s A&A process, and an advanced understanding of applicable Navy systems including, but not limited to, networks and IT infrastructure such as the Navy Marine Corps Internet (NMCI), Outside the Contiguous United States (OCONUS) Navy Enterprise Network (ONE-NET), IT-21/Afloat networks, and Joint systems, and Platform IT such as Navy Control Systems and Weapons platforms.
Certifications:
  • DoD 8570.01-M IAM/IAT Level III Certification or CISSP
Education:
  • Bachelor's degree or AA/AS in Information Assurance or InfoSec field and 4 years of experience OR 7 years of experience
Security Clearance:
  • Secret

About HN Consulting
HN Consulting LLC is a Small Disadvantaged Business (SDB) and a Virginia certified Small, Women, and Minority-owned business (SWaM). HN Consulting is a process- and value-driven consulting and information technology management company.
 
HN Consulting is an Equal Opportunity/Affirmative Action employer. All qualified candidates will receive consideration for employment without regard to disability, protected veteran status, race, color, religious creed, national origin, citizenship, marital status, sex, sexual orientation/gender identity, age (40 or over), or genetic information. HN Consulting's commitment to diversity and inclusive selection practices includes ensuring qualified long-term unemployed job seekers receive equal consideration for employment.
 
Benefits:
  • 100% Company Paid Medical Coverage including Health, Vision, and Dental
  • Basic Life Insurance and Accidental Death and Dismemberment Insurance (AD&D)
  • Short-Term and Long-Term Disability (STD/LTD) Insurances
  • Pre-Tax Benefits
  • Paid Holidays
  • Vacation and PTO/Sick Leave
  • 401(k) Plan
  • Job Related Education and Training Assistance
  • Employee Referral Bonus
clj

Share This Job

Powered by