{"schemaVersion":"jobsearcher.job.v1","id":"fa3379e56c1fea73f2ca25ed","url":"https://jobsearcher.com/jobs/fa3379e56c1fea73f2ca25ed","canonicalUrl":"https://jobsearcher.com/jobs/fa3379e56c1fea73f2ca25ed","title":"System Security Analyst","description":"Position Overview\nThe Systems Security Analyst / Information Systems Security Engineer (ISSE) provides cybersecurity engineering support to the Naval Facilities Engineering Systems Command (NAVFAC) Marianas Command Information Office (CIO). The role focuses on protecting the confidentiality, integrity, and availability of Facility-Related Control Systems (FRCS), networks, and data through the full Risk Management Framework (RMF) lifecycle, vulnerability management, continuous monitoring, policy development, and incident response.Personnel are considered Emergency Essential / Mission Essential and may be required to support the MAR Cyber Emergency Response Team (CERT) on-call rotation (with schedule flexing to stay within 40 hours/week).\n\nKey Responsibilities\nDrive end-to-end RMF lifecycle execution (Steps 1–6) in accordance with Department of the Navy (DoN) and NAVFAC Echelon II guidance; verify system inventories and artifacts for compliance, completeness, and quality; format and upload packages into eMASS.\nAchieve, maintain, and track Authorities to Operate (ATOs) for FRCS; facilitate annual security reviews and draft/submit Memorandums for Record (MFRs) for baseline changes.\nDevelop, author, and maintain security policies, Standard Operating Procedures (SOPs), and implementation plans mapped to NIST SP 800-53 control families, tailored to the FRCS environment.\nDevelop and execute a comprehensive Vulnerability Management Strategy; perform vulnerability and compliance assessments using approved DoN tools (ACAS, SCAP, Evaluate STIG); complete manual STIG/SRG validations (.ckl/.cklb); generate Security Center and eMASSter reports; upload results to VRAM.\nSustain System-Level Continuous Monitoring (SLCM): conduct routine scans, audit log analysis, drive remediation/mitigation, and provide accurate quarterly Plan of Action and Milestones (POA&M) updates.\nDeliver on-site validation and testing support for RMF Step 4, coordinating with system owners and independent validators.\nServe as technical representative / Configuration Management (CM) Officer on the Configuration Control Board (CCB); provide security impact analyses and risk assessments for proposed FRCS baseline changes.\nExecute incident response operations as a member of the MAR CERT, including participation in on-call rotations.\nPrioritize and coordinate technical support across FRCS environments; deliver bi-weekly RMF status reports to the ISSM and maintain project status records in Maximo and/or eProjects; prepare Monthly Status Reports (MSRs).\n\nRequired Qualifications\nU.S. Citizenship.\nActive Top Secret security clearance.\nDoDM 8140.03 foundational qualification for Work Role 461 (Systems Security Analyst) at Intermediate (or Advanced) proficiency level.\nIntermediate-level certifications (one required): CCSP, Cloud+, GICSP, GISF, GSEC, or Security+.\nAdvanced-level certifications also accepted (e.g., CISSP, CySA+, etc.).\nMinimum of 5 years of RMF experience and 1 year of specialized experience with Facility-Related Control Systems (FRCS) performing RMF and cybersecurity engineering tasks (strongly preferred).\nDemonstrated ability to work independently with minimal supervision.\nExcellent written and verbal communication skills in English; proven ability to author technical reports, security policies, and procedures and interface effectively with system owners, ISSMs, and other government personnel.\nPhysical capability to perform the duties, including prolonged standing/walking over uneven surfaces, bending, climbing ladders, and lifting IT equipment up to 25 lbs.\nMaintain certification currency and complete required Continuous Professional Development (CPD) hours annually.\nPreferred / Highly Desired\nPrior experience supporting NAVFAC, DoN, or DoD FRCS environments.\nHands-on experience with eMASS, ACAS/Nessus, VRAM, Security Center, STIG Viewer, and Maximo/eProjects.\nFamiliarity with NAVFAC Echelon II RMF Business Rules.","company":"Gbtisolutionsinc","rawCompany":"gbtisolutionsinc","city":"Santa Rita","state":"D","isRemote":false,"isActive":false,"createdAt":"2026-08-06T16:57:51.830Z","occupations":[{"code":"15-1212.00","title":"Information Security Analysts","slug":"information-security-analysts"},{"code":"13-1199.07","title":"Security Management Specialists","slug":"security-management-specialists"},{"code":"15-1299.05","title":"Information Security Engineers","slug":"information-security-engineers"}],"industries":[{"code":"928110","title":"National Security","slug":"national-security"},{"code":"541512","title":"Computer Systems Design Services","slug":"computer-systems-design-services"},{"code":"921190","title":"Other General Government Support","slug":"other-general-government-support"}],"jobPosting":{"@context":"https://schema.org","@type":"JobPosting","title":"System Security Analyst","description":"Position Overview\nThe Systems Security Analyst / Information Systems Security Engineer (ISSE) provides cybersecurity engineering support to the Naval Facilities Engineering Systems Command (NAVFAC) Marianas Command Information Office (CIO). The role focuses on protecting the confidentiality, integrity, and availability of Facility-Related Control Systems (FRCS), networks, and data through the full Risk Management Framework (RMF) lifecycle, vulnerability management, continuous monitoring, policy development, and incident response.Personnel are considered Emergency Essential / Mission Essential and may be required to support the MAR Cyber Emergency Response Team (CERT) on-call rotation (with schedule flexing to stay within 40 hours/week).\n\nKey Responsibilities\nDrive end-to-end RMF lifecycle execution (Steps 1–6) in accordance with Department of the Navy (DoN) and NAVFAC Echelon II guidance; verify system inventories and artifacts for compliance, completeness, and quality; format and upload packages into eMASS.\nAchieve, maintain, and track Authorities to Operate (ATOs) for FRCS; facilitate annual security reviews and draft/submit Memorandums for Record (MFRs) for baseline changes.\nDevelop, author, and maintain security policies, Standard Operating Procedures (SOPs), and implementation plans mapped to NIST SP 800-53 control families, tailored to the FRCS environment.\nDevelop and execute a comprehensive Vulnerability Management Strategy; perform vulnerability and compliance assessments using approved DoN tools (ACAS, SCAP, Evaluate STIG); complete manual STIG/SRG validations (.ckl/.cklb); generate Security Center and eMASSter reports; upload results to VRAM.\nSustain System-Level Continuous Monitoring (SLCM): conduct routine scans, audit log analysis, drive remediation/mitigation, and provide accurate quarterly Plan of Action and Milestones (POA&M) updates.\nDeliver on-site validation and testing support for RMF Step 4, coordinating with system owners and independent validators.\nServe as technical representative / Configuration Management (CM) Officer on the Configuration Control Board (CCB); provide security impact analyses and risk assessments for proposed FRCS baseline changes.\nExecute incident response operations as a member of the MAR CERT, including participation in on-call rotations.\nPrioritize and coordinate technical support across FRCS environments; deliver bi-weekly RMF status reports to the ISSM and maintain project status records in Maximo and/or eProjects; prepare Monthly Status Reports (MSRs).\n\nRequired Qualifications\nU.S. Citizenship.\nActive Top Secret security clearance.\nDoDM 8140.03 foundational qualification for Work Role 461 (Systems Security Analyst) at Intermediate (or Advanced) proficiency level.\nIntermediate-level certifications (one required): CCSP, Cloud+, GICSP, GISF, GSEC, or Security+.\nAdvanced-level certifications also accepted (e.g., CISSP, CySA+, etc.).\nMinimum of 5 years of RMF experience and 1 year of specialized experience with Facility-Related Control Systems (FRCS) performing RMF and cybersecurity engineering tasks (strongly preferred).\nDemonstrated ability to work independently with minimal supervision.\nExcellent written and verbal communication skills in English; proven ability to author technical reports, security policies, and procedures and interface effectively with system owners, ISSMs, and other government personnel.\nPhysical capability to perform the duties, including prolonged standing/walking over uneven surfaces, bending, climbing ladders, and lifting IT equipment up to 25 lbs.\nMaintain certification currency and complete required Continuous Professional Development (CPD) hours annually.\nPreferred / Highly Desired\nPrior experience supporting NAVFAC, DoN, or DoD FRCS environments.\nHands-on experience with eMASS, ACAS/Nessus, VRAM, Security Center, STIG Viewer, and Maximo/eProjects.\nFamiliarity with NAVFAC Echelon II RMF Business Rules.","datePosted":"2026-08-06T16:57:51.830Z","dateModified":"2026-08-06T16:57:51.830Z","hiringOrganization":{"@type":"Organization","name":"Gbtisolutionsinc","sameAs":"https://jobsearcher.com"},"jobLocation":{"@type":"Place","address":{"@type":"PostalAddress","addressLocality":"Santa Rita","addressRegion":"D","addressCountry":"US"}},"identifier":{"@type":"PropertyValue","name":"JobSearcher","value":"fa3379e56c1fea73f2ca25ed"},"url":"https://jobsearcher.com/jobs/fa3379e56c1fea73f2ca25ed"}}