This role requires a strategic understanding of how emerging technologies (like A.I.) and high-level USMC Cyber Directives impact the acquisition lifecycle and overall enterprise risk posture.
What Your Day-To-Day Looks Like (Position Responsibilities):
What You Need to Succeed (Minimum Requirements):
- A.I. Risk & Architecture: Experience assessing the risk of Artificial Intelligence (A.I.) and Machine Learning (ML) capabilities, including familiarity with emerging DoD A.I. security guidelines, data pipeline security, and assessing A.I. toolsets within the authorization boundary.
- DoD/ DoW Cyber Directives: Proven capability to interpret, analyze, and direct programmatic responses to MFCC (Marine Forces Cyber Command) and DCDC (Department of Defense Cyber Defense Command) TaskOrds, Cyber Tasking Orders (CTOs), and other organizational directives, policies, and messages governing cyber / IT.
- Strategic POA&M Management: Expert-level creation, management, and strategic burn-down of complex Plan of Action and Milestones (POA&Ms) across multiple enterprise systems, ensuring alignment with USMC continuous monitoring timelines / requirements.
- CND Oversight: Advanced understanding of Computer Network Defense (CND) architectures, including zero-trust principles, network boundary defense, and threat intelligence integration.
- RMF Leadership: Deep expertise navigating eMASS and leading systems through the complete Risk Management Framework (RMF) Assess and Authorize (A&A) lifecycles and workflows.
- Deep understanding of NIST SP 800-53 security controls, CNSSI 1253, NIST SP 800-161 & NIST SP 800-162, and DoDI 8510.01.
- Experience drafting organizational cybersecurity policies, Incident Response Plans, and Continuous Monitoring Strategies.
- Advanced proficiency using the DISA STIG Viewer, executing SCAP Compliance Checker (SCC), using eMASSter, and manually validating STIG/SRG requirements on diverse operating systems (Windows, Red Hat Linux, Cisco IOS, Cisco ASA).
- Expert level understanding of applying zero-trust methodologies to system design and tracking implementation throughout the system life-cycle.
Ideally, You Also Have (Preferred Qualifications):
• Security Clearance: Active Secret clearance
• DoD 8140/8570.01-M Baseline Certification: IAM Level II or III (e.g., CISSP, CISM, CAP/CGRC) AND highly recommended to hold a CSSP Auditor/Manager baseline.
Perks of Working for Us (Benefits):
Medical Coverage – Cigna - 4 Options
- Traditional - PPO Open Access Plus Network
- (2) HDHP - PPO Open Access Plus Network
- HDHP - EPO Open Access Plus Network
Dental Coverage – Cigna - PPO Base & Buy-Up Plans
Vision Coverage – Principal - VSP Choice Network
Paid Holidays: Full-time employees receive 11 paid federal holidays
Paid Time Off (PTO) – PTO accrual starts at 15 days per year
Training Benefit – Annual training allowance available toward any job-related training or education
401(k) – Multiple Fund Choices through Fidelity with a company match
For our full list of benefits, please visit http://www.sprymethods.com/careers/benefits/
Skills Required
- Assess risk of AI and Machine Learning capabilities and DoD AI security guidelines
- Interpret and direct programmatic responses to MFCC, DCDC, Cyber Tasking Orders and DoD cyber directives
- Create, manage, and strategically burn-down complex POA&Ms across enterprise systems
- Understand and oversee Computer Network Defense (CND) architectures and zero-trust principles
- Lead RMF Assess and Authorize lifecycles and workflows, including eMASS usage
- Deep understanding of NIST SP 800-53, CNSSI 1253, NIST SP 800-161, NIST SP 800-162, and DoDI 8510.01
- Draft organizational cybersecurity policies, Incident Response Plans, and Continuous Monitoring Strategies
- Advanced proficiency with DISA STIG Viewer, SCAP Compliance Checker (SCC), eMASSter, and manual STIG/SRG validation
- Manual validation of STIG/SRG requirements on Windows, Red Hat Linux, Cisco IOS, and Cisco ASA
- Expert application of zero-trust methodologies throughout system lifecycle
- 4-8 years of progressive DoD cybersecurity, information assurance, or CND experience
- Active Secret security clearance
- DoD 8140/8570.01-M baseline certification (IAM Level II/III e.g., CISSP, CISM, CAP/CGRC); CSSP Auditor/Manager recommended
What We Do
Spry is a certified Small Business headquartered in McLean, VA. Spry provides Enterprise, C4IT, Management, and Cyber Solutions to the federal government and commercial entities. Founded in 2001, Spry Methods was built on the foundation of combining industry knowledge with unmatched responsiveness to produce results for our customers. Our goal is to build a business dedicated to the maximization of value for all stakeholders starting with our employees, our customers, and our community. We recognize that talented and dedicated employees are our most valued assets and the foundation of our success. Guided by these principles, we have established an impressive track record of proven past performance serving our customers within the Commercial, Federal Civilian, DoD, and Intelligence Communities. A CMMI Level 3 certified and ISO 9001:2008 registered company, Spry is committed to quality and continuous improvement.


.jpeg)