PitchMeAI
Amyx, Inc.

Cybersecurity Assessment and Authorization SME

Amyx, Inc. · United States

  • Hybrid
  • Full-time
  • $140,000 / year
  • United States
Tailored resumekeyword-matched to this role.
Hiring managerwe find who's hiring.
Intro emaildrafted to reach them directly.

Job highlights

  • Remote Cybersecurity SME role for DLA.
  • Focus on Assessment and Authorization (A&A).
  • Utilize NIST 800-53 and RMF.
  • Work with diverse IT infrastructure.
  • Requires DOD Secret Clearance.

About the role

Cybersecurity Assessment and Authorization SME

Amyx is seeking a Cybersecurity Assessment and Authorization Subject Matter Expert to join our Defense Logistics Agency program remotely.

Responsibilities

  • Serves as a cybersecurity Subject Matter Expert (SME) with regards to Assessment and Authorization (A&A) of information systems and all associated cybersecurity policies and procedures.
  • Performs a DOD cybersecurity process while either authorizing an information system or serving as a SME for an information system undergoing authorization.
  • Possess an understanding of how the security controls identified in the NIST 800-53 apply to the process of assessing and authorizing a large organization’s IT infrastructure such as DLA’s, in which there is a compilation of large and small enclaves, AIS applications and outsourced IT processes.
  • Determines the applicable severity value for an identified vulnerability (e.g., non-compliant security control) and determines the possible ramifications on the system’s current or future authorization.
  • Briefs senior management on the progress or results of an information system undergoing the Risk Management Framework (RMF) process.
  • Must have the ability to communicate accurate information.

Daily Tasks

  • Run and Analyze system and software scans
  • Develop and track POA&Ms relative to scan findings
  • Coordinate with DLA ISSMs on vulnerability management and continuous ATO management
  • Work with Operations and Developments teams to address security findings, apply STIGs and manage the IAVA process
  • Participate and support a SAFe agile release methodology with testers embedded in the Agile Release Train (ART)
  • Conduct review meetings for reported issues with stakeholders and move issues through process
  • General understanding of software testing methodologies
  • Have practical and working knowledge of all Microsoft Office applications
  • Analytical and Critical Thinking Skills
  • Quality interpersonal skills
  • Quality oral and written communication skills

Supported Technologies

  • Oracle e-Business Suite R12, Oracle Federal
  • Oracle Cloud infrastructure (OCI)
  • Splunk
  • Fortify
  • Oracle Cloud Guard

Required Qualifications

  • Five (5) years of relevant Risk Management Framework (RMF) and NIST A&A experience
  • DOD cybersecurity experience
  • Experience in assessing security controls and conducting authorization reviews for large, complex organizations.
  • Experienced in the general tenets supporting the overall DOD implementation of its authorization process, to include supporting cybersecurity policy, procedures, and processes.
  • Knowledgeable in the cybersecurity of emerging technology areas such as Cloud and Industrial Control Systems (ICSs), warehouse execution systems and Operational Technology (OT) infrastructures.
  • DOD Secret Clearance and must possess IT-II Non-Critical Sensitive security clearance or Tier 3 (T3)

Desired Skills and Qualifications

  • OCI Certified
  • Experience with an Agile Framework
  • Experience with the Continuous ATO process and integration of those processes with an Agile Framework

Benefits

  • Medical, Dental, and Vision Plans (PPO & HSA options available)
  • Flexible Spending Accounts (Health Care & Dependent Care FSA)
  • Health Savings Account (HSA)
  • 401(k) with matching contributions
  • Roth Qualified Transportation Expense with matching contributions
  • Short Term Disability
  • Long Term Disability
  • Life and Accidental Death & Dismemberment
  • Basic & Voluntary Life Insurance
  • Wellness Program
  • PTO
  • 11 Holidays
  • Professional Development Reimbursement

Salary

100-140k

Contact Information

Please contact talent@amyx.com with any questions!

Equal Opportunity Employer Statement

Amyx is proud to be an Equal Opportunity Employer. All qualified candidates will be considered without regard to race, color, religion, national origin, age, disability, sexual orientation, gender identity, status as a protected veteran, or any other characteristic protected by law. Amyx is a VEVRAA federal contractor and we request priority referral of veterans.

Physical Demands

Employee needs to be able to sit at a workstation for extended periods; use hand(s) to handle or feel objects, tools, or controls; reach with hands and arms; talk and hear. Most positions require ability to work on desktop or laptop computer for extended periods of time reading, reviewing/analyzing information, and providing recommendations, summaries and/or reports in written format. Must be able to effectively communicate with others verbally and in writing. Employee may be required to occasionally lift and/or move moderate amounts of weight, typically less than 20 pounds. Regular and predictable attendance is essential.

Key skills/competency

  • Cybersecurity Assessment and Authorization SME
  • Risk Management Framework (RMF)
  • NIST A&A
  • DOD Cybersecurity
  • Security Controls Assessment
  • Authorization Reviews
  • Vulnerability Management
  • Continuous ATO
  • Agile Framework
  • STIGs

Skills & topics

  • Cybersecurity
  • Assessment and Authorization
  • SME
  • Risk Management Framework
  • RMF
  • NIST
  • DOD
  • A&A
  • Information Security
  • Vulnerability Management
  • Splunk
  • OCI
  • Oracle
  • Remote
  • Defense Logistics Agency
  • DLA

How to get hired

  • Tailor your resume: Highlight RMF, NIST A&A, and DOD cybersecurity experience. Quantify achievements in authorization reviews.
  • Showcase technical skills: Emphasize experience with NIST 800-53, Splunk, and OCI if applicable.
  • Demonstrate A&A expertise: Provide examples of assessing security controls and conducting authorization reviews for complex organizations.
  • Address clearance requirements: Clearly state your DOD Secret Clearance and IT-II Non-Critical Sensitive security clearance or Tier 3 (T3).
  • Highlight communication: Mention your ability to brief senior management and communicate accurate information.

Technical preparation

Master NIST 800-53 security controls.,Practice RMF process steps.,Familiarize with Splunk and OCI.,Understand STIGs and IAVA process.

Behavioral questions

Describe a complex authorization review.,How do you brief senior management?,How do you handle conflicting security findings?,How do you collaborate with Dev/Ops teams?

Frequently asked questions

What specific cybersecurity frameworks does Amyx require for this Cybersecurity Assessment and Authorization SME role at DLA?
For this Cybersecurity Assessment and Authorization SME role supporting the Defense Logistics Agency (DLA), Amyx requires extensive experience with the Risk Management Framework (RMF) and NIST A&A processes. You should be knowledgeable about NIST 800-53 security controls and their application within large, complex IT infrastructures.
What are the clearance requirements for the remote Cybersecurity Assessment and Authorization SME position at Amyx?
The Cybersecurity Assessment and Authorization SME position requires a DOD Secret Clearance. Additionally, candidates must possess an IT-II Non-Critical Sensitive security clearance or a Tier 3 (T3) clearance.
Does Amyx offer opportunities for professional development for a Cybersecurity Assessment and Authorization SME?
Yes, Amyx offers a Professional Development Reimbursement benefit. This can be utilized to support your continuous learning and growth in areas relevant to cybersecurity, such as advanced certifications or training related to Assessment and Authorization.
What is the work arrangement for the Cybersecurity Assessment and Authorization SME role with Amyx's DLA program?
This Cybersecurity Assessment and Authorization SME position is a remote role, allowing you to work from anywhere. You will be joining the Defense Logistics Agency (DLA) program.
What specific technologies are used in this Cybersecurity Assessment and Authorization SME role?
In this role, you'll interact with technologies including Oracle e-Business Suite, Oracle Federal, Oracle Cloud Infrastructure (OCI), Splunk, Fortify, and Oracle Cloud Guard. Familiarity with these or similar systems is beneficial.
How does the SAFe agile methodology apply to the daily tasks of a Cybersecurity Assessment and Authorization SME at Amyx?
As a Cybersecurity Assessment and Authorization SME, you will participate in and support a SAFe agile release methodology. This involves working with testers embedded in the Agile Release Train (ART) and coordinating security efforts within the agile development cycle.
What is the expected salary range for the Cybersecurity Assessment and Authorization SME position?
The salary range for this Cybersecurity Assessment and Authorization SME position is between $100,000 and $140,000 annually, depending on your qualifications and experience.