SonicJobs Logo
Left arrow iconBack to search

Authorizing Official Designated Representative (AODR) Support Analyst

ECS Tech Inc
Posted a day ago, valid for 17 days
Location

Washington, DC, US

Salary

$150,000 - $168,000 per year

Contract type

Full Time

By applying, a Sonicjobs account will be created for you. Sonicjobs's Privacy Policy and Terms & Conditions will apply.

SonicJobs' Terms & Conditions and Privacy Policy also apply.

Sonic Summary

info
  • ECS is seeking an Authorizing Official Designated Representative (AODR) Support Analyst for a hybrid position in Washington, DC, contingent upon contract award.
  • The role involves providing comprehensive cyber security services, serving as the primary support for AODR responsibilities, and ensuring compliance with the Risk Management Framework (RMF).
  • Candidates must have a bachelor's degree in a relevant field, an active Secret clearance, at least one cybersecurity certification, and a total of 13+ years of experience in cyber, IT, or related fields, including 5+ years of executive-level RMF consulting experience.
  • The salary range for this position is between $150,000 and $168,000.
  • The positions are available immediately upon finding qualified candidates with the appropriate background clearance.

ECS is seeking an Authorizing Official Designated Representative (AODR) Support Analyst to work in our Washington, DC (hybrid) office.  Please Note: This position is contingent upon contract award.


We are looking to hire an AODR Support Analyst to support a full range of cyber security services on a long-term contract in Washington DC and the surrounding areas. These positions are full time/permanent and will support a US Government civilian agency. The positions are available immediately upon finding a qualified candidates with the appropriate background clearance.

 

Position Responsibilities:

  • Serve as the primary support for all AODR-related responsibilities as outlined in NIST SP 800-37.
  • Provide significant cyber consultation, oversight services, authoritative technical support, and approval of Risk Management Framework (RMF) deliverables (security categorization, security baseline control selection, system security plan, contingency plans, POA&Ms, security assessment cost estimates, security assessment plan, security assessment report, pre- and post-assessment remediation of security assessment findings, risk assessment calculations, and security authorization recommendations) on behalf of the Department Authorizing Official (AO) within the service delivery timeframes established by the Federal client.
  • Serve as the primary and/or backup individual responsible for responding to system-level inquiries, based on system assignments, with minimal supervisory attention. 
  • Provides comprehensive customer service and maintain a collaborative rapport with client cyber and business entities and senior managers, employees, and other internal and external contacts in support of cyber security compliance deliverables and mission support work.
  • Provide accurate and concise oral and written responses to inquiries and respond to concerns with initiative and decisiveness and take appropriate steps to resolve any issue as directed/authorized.
  • Be a driver of holistic and enterprise-scale changes in cyber-security programs within large Federal client.  Act as a “disruptor to the status-quo” to drive needed changes to cybersecurity and related agency-wide workflows (Privacy, SDLC, procurement, etc.) to ensure that security and privacy best-practices and statutory and regulatory requirements are met in a holistic and cost-effective manner.
  • Provide consultation expertise at various levels with a large Federal agency to develop and maintain enterprise-scale cyber security program that reacts quickly to changing regulatory and operational drivers, including emerging technical, operational and management risk-drivers:
    • Participate in Daily, Weekly, and Monthly status meetings with key Government personnel, at times on short notice, to ensure stakeholders are informed of program status and progress on various cyber initiatives. Provide an opportunity to set priorities, identify opportunities or concerns, and coordinate resolution of identified problems.
    • Develop program level security documentation, audit liaison activities, and compliance oversight activities to strengthen the security program and promote compliance with the Risk Management Framework (RMF).
    • Support the performance of independent security and privacy control assessments in support of Security Assessment & Authorization (SA&A).
    • Support the management and implementation of continuous monitoring solutions to increase the visibility and transparency of network activity.

Salary Range: $150,000-$168,000

General Description of Benefits

Qualifications
  • A bachelor’s degree from an accredited college in systems engineering, computer science, computer engineering, information technology, management information systems or equivalent.
  • Active Secret clearance or higher.
  • At least one Cybersecurity or related certification.  Preferred include:
    • Certified Information Systems Security Professional (CISSP)
    • Certified Information Systems Auditor (CISA)
    • Certified Information Security Manager (CISM)
    • GIAC Security Essentials Certification (GSEC)
    • Certified in Governance, Risk, and Compliance (CGRC)
    • Project Management Professional (PMP)
  • Combined 13+ years in cyber, IT or related fields.
  • 5+ years of Executive-Level cyber RMF consulting experience advising Cybersecurity programs in large federal organizations.
  • 4+ years Information Systems Security Officer (ISSO) experience for enterprise class systems and applications.
  • Strong interpersonal and human relations skills, including ability to communicate technical concepts to non-technical personnel.
  • Strong written, verbal, and presentation skills, including demonstrated ability to interact effectively with Senior Agency management and leadership.
  • Strong stakeholder management and engagement skills with staff at all levels, including ability to collaborate with people of varied technical backgrounds and management levels.
  • Advanced understanding of and experience with GRC tools, policy, procedures, and processes, including (but not limited to) FISMA audits and compliance, NIST, RMF, and recent Executive Orders.
  • Experience with NIST Risk Management Framework and Governance, Risk & Compliance (GRC) and Information Assurance capabilities/tools.
  • Strong familiarity with NIST Risk Management Framework at the subject matter expert level, particularly including SP 800-30, -37, -39, -137, -53, and -53A/B.
  • Ability to guide the development of enterprise-specific implementation guidance for agency management.
  • Ability to analyze and interpret Federal legislation, directives, Office of Management and Budget (OMB) mandates, and guidance provided by the National Institute of Standards and Technology (NIST) against existing information security and privacy policy to identify required updates.
  • Ability to conduct research on new and emerging information technologies and develop comprehensive information security and privacy policy, standards/guidelines, and procedures to facilitate the implementation of information security and privacy controls. Must have working knowledge of the Privacy Act of 1974 (as amended), the Federal Information Security Modernization Act (FISMA).



Learn more about this Employer on their Career Site

Apply now in a few quick clicks

By applying, a Sonicjobs account will be created for you. Sonicjobs's Privacy Policy and Terms & Conditions will apply.

SonicJobs' Terms & Conditions and Privacy Policy also apply.