This job originated on www.usajobs.gov. For the full announcement and to apply, visit www.usajobs.gov/job/772540400. Only resumes submitted according to the instructions on the job announcement listed at www.usajobs.gov will be considered.
Marine Corps Community Services (MCCS) is looking for the best and brightest to join our Team! MCCS is a comprehensive program that supports and enhances the quality of life for Marines, their families, and others in the Marine Corps Community. We offer a team oriented environment comprised of military personnel, civilian employees, contractors and volunteers who keep the organization functioning smoothly and effectively.
01/24/2024 to 02/07/2024
$100,000 - $125,000 per year
NF 05
1 vacancy in the following location:
No
25% or less - Varies
No
Permanent
Full-time
Competitive
NA
No
No
66608
772540400
The Cybersecurity Analyst will serve within the Enterprise Cybersecurity and Compliance Office as a Validator. The validator will examine through demonstration, inspection, or analysis the extent to which a system or application meets a set of security requirements as specified by the Authorizing Official (AO), governing instructions, and directives. The Security Control Validator (SCV) develops and conducts tests of systems to evaluate compliance with specifications and requirements by applying principles and methods for cost effective planning, evaluating, verifying, and validating of technical, functional, and performance characteristics (including interoperability) of systems or elements of systems incorporating IT.
Conducts assessments of threats and vulnerabilities; determines deviations from acceptable configurations, enterprise or local policy; assesses the level of risk; and develops and/or recommends appropriate mitigation countermeasures in operational and nonoperational situations. The position is responsible for evaluation of IT systems or its individual components to determine compliance with published standards. Plans, prepares, and executes tests of systems to evaluate results against specifications and requirements as well as analyze/report test results.
Roles include:
Determine level of assurance of developed capabilities based on test results. Develop test plans to address specifications and requirements. Make recommendations based on test results. Determine scope, infrastructure, resources, and data sample size to ensure system requirements are adequately demonstrated. Create auditable evidence of security measures. Perform Windows registry analysis. Analyze the results of software, hardware, or interoperability testing. Perform operational testing. Test, evaluate, and verify hardware and/or software to determine compliance with defined specifications and requirements. Provide recommendations for possible improvements and upgrades. Review or conduct audits of information technology (IT) programs and projects.
Conduct import/export reviews for acquiring systems and software. Ensure that supply chain, system, network, performance, and cybersecurity requirements are included in contract language and delivered. Maintain deployable cyber defense audit toolkit to support cyber defense audit missions. Perform technical (evaluation of technology) and nontechnical (evaluation of people and operations) risk and vulnerability assessments of relevant technology focus areas
Make recommendations regarding the selection of cost-effective security controls to mitigate risk. Coordinate with project management, development, and other technical teams to create and submit A&A packages using (MCCAST). Perform technical testing and validation of applications, systems, and networks to evaluate levels of compliance with (STIG), and perform the formal security assessment in step 4 of the RMF process and initiate and finalize the (SAR).
Assess the implementation of security controls and hardening on various technology platforms for vulnerabilities, STIGs, security requirements guides (SRG), RMF security controls. Coordinate and interface with a team of system administrators and network engineers to complete Cybersecurity testing on systems and networks, and assist with remediation guidance and verification, in accordance with DoD, DoN, USMC, and DISA guidance.
Assists in the daily operations and development of the MR Cybersecurity program that identifies architecture, requirements, objectives and policies, personnel and processes and procedures as they relate to DOD, DON, USMC policy, standards, and guidelines. Provides security oversight for MR and subordinate commands. As a SCV, test the implementation of applicable Cybersecurity controls for an assigned MCCS system. Ensures that development, review, endorsement, and maintenance of security compliance documentation is accomplished. Validates that documentation includes the System Security Plan(s) (SSP) for all MR applications, networks, and stand-alone systems.
Performs security compliance efforts IAW the PCI, FISMA, NIST SP 800 series, FIPS series, and USMC related policies and procedures. Coordinates directly with Project Managers, service providers, consultants and other USMC commands for compliance requirements. Works directly and proactively with MCCS IT Security staff, Project Managers, IT Managers, and HQMC C4/CY to meet objectives and to ensure maximum effective use of tools, techniques, and methodologies in proposing, developing, and implementing IT solutions. Liaises with designated HQMC C4 office staffs responsible for system CY and IT Portfolio management to ensure currency with compliance matters.
Occasional travel to complete work assignments, conduct training or attend conferences and meetings may be required. This is a white-collar position where occasional lifting up to 20 lbs. may be required.
EVALUATIONS:
Bachelors¿ Degree in Information Technology or Business related field appropriate to the work of position OR five years of experience performing specific tasks for Independent Verification and Validation (IV&V), security assessments, risk assessments, or cybersecurity (CY): OR an appropriate combination of education and experience that demonstrates possession of knowledge and skill equivalent to that gained in the above, OR appropriate experience that demonstrates that the applicant has acquired the knowledge, skills, and abilities equivalent to that gained in the above.
Certification as an Information Systems Security Professional (CISSP) is required or equivalent level education and appropriate experience with DoD system security and information assurance (IA) policy and procedures.
As an authorized and privileged user of Department of Defense Information Systems must fulfill the requirement to complete DoD Workforce Improvement Program certification (8570.01-M) as a condition of access within six months of employment.
Expertise in:
Proficient in/Experience with:
Broad Knowledge of:
May serve as a liaison for communication and response to task orders issued by Marine Forces Cyber Command (MARFORCYBER), HQMC C4, Marine Corps Installations Command (MCICOM), and Marine Corps Systems Command (MCSC) for all Information Technology and Cybersecurity initiatives.
This position has been designated as a position of trust. The incumbent must be eligible for an Access National Agency Check and Inquiries (ANACI/ Tier 3) background investigation to review and respond to SIPRNet Task Orders (TASKORD), Warning Orders (WARNORD), Fragmentary Orders (FRAGO), and Operational Directives (OPDIRS) for all Cybersecurity Incident Response tasks. Appointment and continued employment is subject to a favorable adjudication of the security investigation.
Eligible for incremental telework as determined by MR/MF policy.
GENERAL INFORMATION: Applicants are assured of equal consideration regardless of race, age, color, religion, national origin, gender, GINA, political affiliation, membership or non-membership in an employee organization, marital status, physical handicap which has no bearing on the ability to perform the duties of the position. This agency provides reasonable accommodations to applicants with disabilities. If you need a reasonable accommodation for any part of the application and hiring process, please notify the agency. The decision on granting reasonable accommodation will be on a case-by-case basis.
It is Department of Navy (DON) policy to provide a workplace free of discrimination and retaliation. The DON No Fear Act policy link is provided for your review: https://www.donhr.navy.mil/NoFearAct.asp.
A career with the U.S. government provides employees with a comprehensive benefits package. As a federal employee, you and your family will have access to a range of benefits that are designed to make your federal career very rewarding. Opens in a new windowLearn more about federal benefits.
The Federal government offers a number of exceptional benefits to its employees. Benefits you get to enjoy while working at MCCS include but are not limited to:
• Stability of Federal Civilian Service
• People with passion for doing work that matters
• Quality of Work Life Balance
• Competitive Pay
• Comprehensive Benefit Packages
• Marine Corps Exchange and Base Facility Privileges
Eligibility for benefits depends on the type of position you hold and whether your position is full-time, part-time or intermittent. Contact the hiring agency for more information on the specific benefits offered.
You will be evaluated for this job based on how well you meet the qualifications above.
Your application/resume and supporting documentation will be used to determine whether you meet the job qualifications listed on this announcement. This vacancy will be filled by the best qualified applicant as determined by the selecting official.
A career with the U.S. government provides employees with a comprehensive benefits package. As a federal employee, you and your family will have access to a range of benefits that are designed to make your federal career very rewarding. Opens in a new windowLearn more about federal benefits.
The Federal government offers a number of exceptional benefits to its employees. Benefits you get to enjoy while working at MCCS include but are not limited to:
• Stability of Federal Civilian Service
• People with passion for doing work that matters
• Quality of Work Life Balance
• Competitive Pay
• Comprehensive Benefit Packages
• Marine Corps Exchange and Base Facility Privileges
Eligibility for benefits depends on the type of position you hold and whether your position is full-time, part-time or intermittent. Contact the hiring agency for more information on the specific benefits offered.
As a new or existing federal employee, you and your family may have access to a range of benefits. Your benefits depend on the type of position you have - whether you're a permanent, part-time, temporary or an intermittent employee. You may be eligible for the following benefits, however, check with your agency to make sure you're eligible under their policies.
Varies - Review "OTHER INFORMATION"
Education must be accredited by an accrediting institution recognized by the U.S. Department of Education in order for it to be credited towards qualifications. Therefore, provide only the attendance and/or degrees from schools accredited by accrediting institutions recognized by the U.S. Department of Education.
Failure to provide all of the required information as stated in this vacancy announcement may result in an ineligible rating or may affect the overall rating.
All applications must be submitted online via the MCCS Careers website: https://careers.usmc-mccs.org
Resumes/applications emailed or mailed will not be considered for this vacancy announcement. Resumes submitted with pictures will not be considered. To be considered for employment, the application or resume must be submitted online by 11:59 PM (EST) on the closing date of the announcement.
Note: To check the status of your application or return to a previous or incomplete application, log into your MCCS user account and review your application status.
All applicants who submit an application via our Careers page at https://careers.usmc-mccs.org will be able to view their application status online.
The Federal hiring process is set up to be fair and transparent. Please read the following guidance.
Varies - Review "OTHER INFORMATION"
Education must be accredited by an accrediting institution recognized by the U.S. Department of Education in order for it to be credited towards qualifications. Therefore, provide only the attendance and/or degrees from schools accredited by accrediting institutions recognized by the U.S. Department of Education.
Failure to provide all of the required information as stated in this vacancy announcement may result in an ineligible rating or may affect the overall rating.
All applications must be submitted online via the MCCS Careers website: https://careers.usmc-mccs.org
Resumes/applications emailed or mailed will not be considered for this vacancy announcement. Resumes submitted with pictures will not be considered. To be considered for employment, the application or resume must be submitted online by 11:59 PM (EST) on the closing date of the announcement.
Note: To check the status of your application or return to a previous or incomplete application, log into your MCCS user account and review your application status.
All applicants who submit an application via our Careers page at https://careers.usmc-mccs.org will be able to view their application status online.
The Federal hiring process is set up to be fair and transparent. Please read the following guidance.
This job originated on www.usajobs.gov. For the full announcement and to apply, visit www.usajobs.gov/job/772540400. Only resumes submitted according to the instructions on the job announcement listed at www.usajobs.gov will be considered.
Learn more about
Serving Those Who Serve