Have anyone here ever worked in a role such as this below:
The ideal candidate would have working knowledge of configuring network equipment in accordance with various government regulations and be able to detect and deter unauthorized access.
Should be familiar with configuring network of Windows Domain Controllers and workstations in order to configure for various Government system hardening regulations. Experience with UNIX Based systems a plus.
Must have technical background and ability to interpret and implement various government directives to ensure systems are properly managed & secured. Knowledge of Risk Management Framework (RMF) methodologies is desired.
Be able to perform activities such as auditing, hardening (securing), account creation, etc… in domain environment, including Operating Systems and Network configurations.
Assist in the evaluation of security solutions to ensure they meet security requirements for processing classified information.
Conduct reviews and technical inspections (as directed by the ISSM) to identify and mitigate potential security weaknesses, and ensure that all security features applied to a system are implemented and functional.
Assess changes in the system, its environment, and operational needs that could affect the accreditation.
Strong knowledge preferred with NISPOM & ODAA Manuals, with knowledge of and be able to determine controls applicable to the systems, and documents implementation.
Any opinions on this?