CALIBRE Systems, Inc.

Cybersecurity Assessment and Authorization Subject Matter Expert (SME)

CALIBRE Systems, Inc. · Courtry, Ile-de-France, France

Business Consulting and Services · 501-1,000 employees

2 d ago
Remote Senior (5-10 yrs) Other France
Log in to apply, save this posting, or score it against your profile with AI.

About the role

The SME will provide subject-matter expertise for the assessment and authorization of information systems in accordance with RMF processes. They are responsible for evaluating security controls, assessing vulnerabilities, and briefing senior management on authorization progress and findings.

What they look for

Risk Management Framework NIST 800-53 Cybersecurity Assessment Authorization Security Controls Vulnerability Assessment Risk Assessment DoD Cybersecurity Policies Information Systems Security Analytical Skills Written Communication Presentation Skills Operational Technology Cloud-hosted Services Enterprise IT Environments

Requirements

Candidates must have at least five years of relevant experience in Certification and Accreditation or Assessment and Authorization. Additionally, an active Secret security clearance and a DoD-approved 8570/8140 IAM Level III baseline certification are required.

Full description

CALIBRE is an employee-owned, mission-focused solutions and digital transformation company.

CALIBRE is seeking a Cybersecurity Assessment and Authorization (A&A) Subject Matter Expert (SME) to support the Defense Logistics Agency (DLA). The Cybersecurity A&A SME will provide subject-matter expertise related to the assessment and authorization of information systems and associated cybersecurity policies and procedures.

The selected candidate will execute DoW/DLA cybersecurity processes to authorize information systems, maintain existing system authorizations, and support systems undergoing the authorization process.

Responsibilities

  • Serve as a cybersecurity subject matter expert for the assessment and authorization of information systems.

  • Execute DoW/DLA cybersecurity processes supporting initial and ongoing system authorization.

  • Support information systems throughout the Risk Management Framework (RMF) process.

  • Assess security controls identified in NIST Special Publication 800-53.

  • Conduct security-control assessments and authorization reviews for large, complex enterprise environments.

  • Support the assessment and authorization of large and small enclaves, cloud-hosted services, Operational Technology (OT), Automated Information System (AIS) applications, and outsourced IT processes.

  • Evaluate identified vulnerabilities and noncompliant security controls.

  • Determine the residual risk associated with identified vulnerabilities.

  • Assess the potential impact of cybersecurity vulnerabilities on a system’s current or future authorization.

  • Brief senior management on the progress, findings, and results of information systems undergoing the RMF process.