Q.E.D. Systems, Inc.

Cybersecurity Administrator

Q.E.D. Systems, Inc.  •  $40 - $55/hr  •  Virginia (Onsite)  •  11 days ago
Apply
AI can make mistakes so check important info. Chat history is never stored.

Job Description

Job Title: Cybersecurity Administrator

Job Location Virginia Beach, VA

Job Category Information Technology/Systems

Job Status Full Time

Salary Range $40 - $55/hr

The Cybersecurity Administrator is responsible for implementing and maintaining the security controls required for CMMC (Cybersecurity Maturity Model Certification) Level 2 across the enterprise, in accordance with NIST SP 800-171, Protecting Controlled Unclassified Information. The administrator will maintain and improve the organization’s System Security Plan (SSP) and Plan of Action and Milestones (POA&M), support assessment readiness with the company’s C3PAO and DIBCAC, and help sustain the security of Controlled Unclassified Information (CUI).

The Cybersecurity Administrator shall have experience with boundary defense techniques, commercial off-the-shelf (COTS) security products, and cloud services used to meet the enterprise’s system security objectives.

Duties and Responsibilities:

  • Plan, develop, implement, test, and document security controls to meet CMMC Level 2 (NIST SP 800-171) requirements
  • Develop and enforce information security policy
  • Perform IT risk and security assessments and support risk mitigation efforts
  • Assess flow-down of DFARS requirements to subcontractors and support vendor/supply-chain risk reviews
  • Develop approaches to mitigate vulnerabilities and recommend changes to systems or components as needed
  • Facilitate an IT business continuity plan
  • Perform internal security control assessments and self-assessments, including SPRS scoring support
  • Identify information protection needs for the computing and network environments
  • Develop, maintain, and analyze the System Security Plan (SSP) and associated cybersecurity risk analysis
  • Advise network, system, and software engineers on the results of cybersecurity risk analysis
  • Execute and support network security initiatives
  • Conduct vulnerability scanning
  • Ensure patch compliance
  • Support incident response and remediation efforts
  • Participate in assessment activities, including interviews, documentation requests, and artifact requests
  • Review responses and deliverables for accuracy and assist with interpreting assessment requests
  • Review assessment findings and assist management in developing responses and remediation plans
  • Create, track, and provide status updates on Plan of Action and Milestones (POA&M) items
  • Develop, update, and maintain metric/KPI status reports on a defined schedule for IT initiatives
  • Respond to requests for clarification and information
  • Oversee and provide technical guidance to Cybersecurity Analysts

Job Requirements / Skillsets:

  • Experience implementing controls to meet NIST SP 800-171 requirements
  • Experience designing and maintaining a System Security Plan (SSP)
  • Experience performing security audits with and without specialized SIEM tools
  • Experience certifying or validating compliance of information systems
  • Current certification compatible with IAT Level III in accordance with DoD 8140 (formerly DoD 8570.01-M), or the ability to obtain one within six months of hire
  • Comprehensive understanding of computer security and the ability to communicate clearly and succinctly in written and oral presentations
  • Working knowledge of a vulnerability management system
  • Experience utilizing MS Purview and Data Loss Prevention (DLP) policies
  • Experience securing cloud-based security controls

Job Preferences:

  • Current ISC2 CISSP certification
  • Experience developing and testing an Incident Response Plan
  • Mobile Device Management (MDM) administration
  • Experience with network administration
  • Experience with system administration
  • Experience implementing or managing FedRAMP-authorized vendor products (e.g., GCC High)
  • Experience in a classified environment

Education:

Bachelor’s degree in computer science, Information Technology, Computer Information Systems, or a related field and 5 years of experience in the field or a related area; or a Master’s degree in a related field and 2 years of experience in the field or a related area. Active industry cybersecurity certifications (ISC2, CompTIA, Cisco, Microsoft) may substitute for some years of experience depending on the certification.

Security Clearance

Requires U.S. citizenship and the ability to obtain a DoD Secret clearance.

Benefits:

Q.E.D. offers competitive benefits such as: Paid Leave, Medical, Dental, Vision, Short/Long-Term Disability, 401(k) retirement plan, Basic Life Insurance, supplemental insurance, and an Employee Assistance Program.

To Apply:

Email resume to Julio Valdez at jvaldez@qedsysinc.com

EOE, including disability/vets

Q.E.D. Systems, Inc.

About Q.E.D. Systems, Inc.

Quod Erat Demonstrandum (QED) – “That which has been demonstrated or proven” – QED Systems Inc. is a marine engineering and industrial services company with more than 50 years of experience on nearly every class of U.S. Navy surface ships, aircraft carriers, submarines, service craft, Army watercraft, Military Sealift Command ships, and United States Coast Guard vessels. QED Systems is a NAVSEA-qualified Agreement for Boat Repair (ABR) contractor with an ASQ/ANSI/ISO 9001:2015 and NAVSEA Standard Item 009-04 Compliant Quality Management System (QMS) and an SSPC QP-1 certification for field application of coatings on complex structures.

QED has an exceptional record of performance with a wide variety of customers including Naval Surface Warfare Center Philadelphia (NSWC-PD), Puget Sound Naval Shipyard and Intermediate Maintenance Facility (PSNS & IMF), Pearl Harbor Naval Shipyard and Intermediate Maintenance Facility (PHNSY & IMF), Norfolk Naval Shipyard (NNSY), Portsmouth Naval Shipyard (PNSY), Mid-Atlantic Regional Maintenance Center (MARMC), Southwest Regional Maintenance Center (SWRMC), Southeast Regional Maintenance Center (SERMC), and Naval Sea Systems Command (NAVSEA) headquarters. With this nationwide experience, we have gained a broader perspective on ways to standardize products and cohesively manage our support to East Coast and West Coast activities at a cost savings to our customers.

Our established organization includes multiple operational Directorates which are staffed to support efforts in every Fleet Concentration Area (FCA). These Directorates have the facilities, equipment, personnel policies, procedures, and infrastructure necessary to perform a variety of contracted tasks on all classes of ships, submarines and watercraft, as well as at shore-based activities. Our Core Capabilities include Engineering Services, Planning Services, Technical Services, Fabrication, Logistics, Skilled Resources, and Training.

Industry
Architecture & Engineering
Company Size
201-500 employees
Headquarters
Virginia Beach, VA
Year Founded
1969
Social Media