Senior Cybersecurity Internal Controls Administrator (Information Assurance Engineer - Senior)CGI Federal is looking for a Senior Cybersecurity Internal Controls Administrator (Information Assurance Engineer - Senior) to help support a program we are working on for the Army's PL ALTESS contract. PL ALTESS, or Product Lead for Acquisition, Logistics, and Technology Enterprise Systems and Services, is a key U.S. Army organization providing IT services and support to the Army and Department of Defense. As a managed service provider, ALTESS delivers infrastructure, platform, and application services across data centers and commercial clouds. It plays a crucial role in modernizing IT systems by migrating them to the cloud and managing mission-critical applications to ensure Army readiness. ALTESS oversees IT service delivery across various hosting locations, aligning with Department of Defense digital transformation strategies as part of PEO Enterprise. This position is located in USA VA Radford -- USAVARAD1.The Senior Cybersecurity Internal Controls Administrator (Information Assurance Engineer - Senior) will provide comprehensive support in accordance with DoDI , DoDI , and AR 25-2.
The role involves providing Enterprise eMASS and RMF services, including developing RMF packages, maintaining asset lists and categorizations, and scheduling and coordinating system validation reviews. The administrator will generate artifacts to support control compliance, review ACAS and STIG reports, and coordinate remediation efforts. Additionally, the role includes creating, tracking, and maintaining Plan of Action Milestones (POA&M), performing annual security reviews, participating in Continuity of Operations (COOP) and Incident Response testing, and maintaining Army PPSM and Circuit Registry records. The administrator will also participate in SW Assurance reviews to ensure ongoing items are appropriately documented via eMASS POA&M.Required qualifications to be successful in this role include: Cybersecurity Certification (such as CISSP/etc.), Active DoD Secret Security Clearance, 10 or more years' experience with Cybersecurity and RMF related areas, extensive experience with Enterprise eMASS and RMF services, proficiency in developing RMF packages and maintaining asset lists and categorizations, ability to schedule and coordinate system validation reviews, experience generating artifacts to support control compliance, knowledge of ACAS and STIG reports and coordinating remediation efforts, experience creating, tracking, and maintaining Plan of Action Milestones (POA&M), ability to perform annual security reviews, participation in Continuity of Operations (COOP) and Incident Response testing, ability to maintain Army PPSM and Circuit Registry records, participation in SW Assurance reviews and documenting items via eMASS POA&M, and experience with security compliance and control documentation. Desired qualifications/non-essential skills required include a Bachelor's degree in Computer Science or equivalent years of experience, familiarity with DoDI , DoDI , and AR 25-2, strong analytical and problem-solving skills, excellent communication and coordination skills, experience with Army enterprise monitoring tools and practices, knowledge of security regulations and best industry practices, ability to work effectively in a team environment and collaborate with various stakeholders, experience with incident response activities, and understanding of Continuity of Operations Plans and Communication Plans.