The role involves utilizing the NIST Risk Management Framework (RMF) and related continuous monitoring activities to maximize the security of assigned systems and ensure compliance. The position requires providing technical security expertise in planning, coordinating, preparing, and authoring security authorization documentation necessary to comply with Federal, DoD, and organizational policies. This role focuses on recommending, monitoring, and assessing compliance with security controls, rather than implementing them.
ResponsibilitiesESSENTIAL
This role is responsible for being knowledgeable on cybersecurity principles, risk management process, and implementation.
Working knowledge of applicable IC, DoD policies, procedures, and operating instructions related to Information Technology, Cybersecurity, Information Assurance, and Information Management (IT/IA/IM).
Ability to collaborate with application leads, sysadmins, DBAs, developers, and testers to ensure assigned systems are security compliant and achieve/maintain ATO.
Ability to develop, draft, assess, review, and/or endorse all information systems security plans and other security authorization artifacts and documents such as:
System Security Plans (SSP)
Controls Testing (Security Test and Evaluation (ST&E) Plans
Security Controls Traceability Matrix (SCTM)
Security Assessment Procedures
Security Assessment Reports
Plans of Actions & Milestones (POA&Ms)
Privileged and General User Guides
Cyber SOPs
Concept of Operations
Working knowledge in guiding complex information systems through assessment and authorization control gates.
Working knowledge in authorization applications such as ServiceNow and eMASS.
Working knowledge in loading artifacts such as STIG checklists and Nessus scans.
Ability to implement STIG checklists and mitigate scan findings.
Ability to establish the day-to-day implementation, oversight, continuous monitoring, and maintenance of the security configuration, practices, and procedures for each information system.
Working knowledge of configuration management, system maintenance, and integration testing.
Ability to review technical configurations and make recommendations on the protection of classified and sensitive data.
Ability in the use of tools to prevent and/or negate malicious code.
Ability in detecting and preventing computer security compromises in a classified environment.
Ability to collaborate with Incident Response Teams and provide viable recommendations for the resolution of computer security incidents.
Ability to establish and maintain security protocols.
Ability to establish and maintain effective internal and external working relationships with government and contractor program managers, security professionals, and mission partners.
Ability to effectively provide ISSO guidance to System Administrators.
Ability to communicate and work with stakeholders to resolve computer security incidents and vulnerability compliance.
Ability to implement security measures to mitigate or remediate vulnerabilities and security deficiencies and provide justification for acceptance of residual risk.
Ability to perform security reviews/assessments, identify gaps in security architecture, and develop a security risk management plan.
Ability to review and analyze system audit logs to identify anomalous activity and potential threats to network resources.
Individual contributor that works under limited supervision.
Determines approach to work, monitored / supervised based on key objective check-ins.
Lead assignments for specific job function or projects.
Lead entry level individual contributors to ensure the work completion as per set standards and procedures.
ADDITIONAL
Other duties as assigned.
Scheduled weekly hours: 40
Day shift – With occasional afterhours and weekends (< 3%)
REQUIRED
Must have 2-6 years of relevant work experience with Associate’s Degree in information technology or computer science. Equivalent work experience may be considered in lieu of degree.
Knowledge of cybersecurity principles and organizational requirements (relevant to confidentiality, integrity, availability, authentication, non-repudiation).
Knowledge of the full RMF process, the selected candidate must have experience completing a full system assessment resulting in an authorization to operate (ATO).
Knowledge of the security authorization processes and procedures as defined in the RMF in NIST SP800-37 and familiarity with the ICD503, CNSSI1253, SP800-53, etc.
Knowledge of systems security testing and evaluation methods.
Knowledge of countermeasures for identified security risks.
Knowledge of how to use network analysis tools to identify vulnerabilities.
Knowledge of network security architecture concepts including topology, protocols, components, and principles (e.g., application of defense-in-depth).
Knowledge of security systems including anti-virus applications, content filtering, firewalls, authentication systems, and intrusion detection and notification systems.
Oral and written communication skills for change procedures, and management updates.
Experience implementing and/or verifying compliance with DISA STIGs.
Experience with using Security Content Automation Protocol (SCAP) tools.
Experience working independently on cybersecurity in support of a client.
Experience with risk analysis and compensatory security controls incorporating system/mission owner, and unique operational constraints.
Must have or be able to obtain a TS security clearance, be able to take/pass a polygraph, and be able to maintain both for the tenure of this position.
Position tenure ship is dependent on completing the full security clearance application process successfully within 1-2 years of accepting position.
Must have all required IT / Security certifications and maintain for the tenure of this position.
Must be a U.S. Citizen.
DESIRED
DOD 8570 certification for Info Assurance Management (IAM) level III. Prefer candidates who hold Certified Information Systems Security Professionals (CISSP) credential.
We offer a comprehensive and competitive benefits package. Employee benefits vary by role, however, may include Health and Wellness, Mental Health, Retirement Savings, Life and Disability, Paid Maternity and Parental Leave, Paid Time Off, Tuition Reimbursement, and an Employee Assistance Program.
The salary range for this position is $74,600 - $112,000
Skills Required
- 2-6 years of relevant cybersecurity or information technology work experience
- Associate's degree in information technology or computer science, or equivalent work experience in lieu of degree
- Knowledge of cybersecurity principles, including confidentiality, integrity, availability, authentication, and non-repudiation
- Experience completing a full NIST RMF system assessment resulting in an Authorization to Operate
- Knowledge of RMF security authorization processes, NIST SP 800-37, ICD 503, CNSSI 1253, and NIST SP 800-53
- Knowledge of systems security testing and evaluation methods
- Knowledge of countermeasures for identified security risks
- Knowledge of network analysis tools for identifying vulnerabilities
- Knowledge of network security architecture, topology, protocols, components, and defense-in-depth principles
- Knowledge of antivirus, content filtering, firewalls, authentication, and intrusion detection systems
- Oral and written communication skills for change procedures and management updates
- Experience implementing or verifying compliance with DISA STIGs
- Experience using Security Content Automation Protocol tools
- Experience working independently on cybersecurity projects supporting clients
- Experience with risk analysis and compensatory security controls
- Must have or be able to obtain and maintain a Top Secret security clearance and pass a polygraph
- Must maintain all required IT and security certifications
- U.S. citizenship
- DoD 8570 Information Assurance Management Level III certification
- CISSP certification
Oceaneering Compensation & Benefits Highlights
The following summarizes recurring compensation and benefits themes identified from responses generated by popular LLMs to common candidate questions about Oceaneering and has not been reviewed or approved by Oceaneering.
-
Healthcare Strength — Healthcare offerings are portrayed as comprehensive, including private medical insurance and broad medical, dental, and vision coverage tailored to local markets. In several contexts, coverage is characterized as good to outstanding.
-
Retirement Support — Retirement programs include pension/retirement plans and a U.S. 401(k), which are consistently highlighted as part of a competitive package. These elements are described as contributing meaningful value to overall compensation.
-
Leave & Time Off Breadth — Leave programs include PTO/vacation, paid holidays, and paid sick leave, with annual leave emphasized globally. Time-off provisions are noted as a steady component of total rewards even when salary opinions differ.
Oceaneering Insights
What We Do
Oceaneering pushes the frontiers of deep water, space and motion entertainment environments to execute with new, leading-edge connections to solve tomorrow’s challenges, today. As the trusted subsea connection specialist, our experience combined with the depth and breadth of our portfolio of technologies allows us to engineer solutions for the most complex subsea challenges. From routine to extreme, our integrated products, services, and innovative solutions safely de-risk operational systems, increase reliability, and enable a lower total cost of ownership. We are connecting what’s needed with what’s next as the world’s largest ROV operator and the leading ROV provider to the oil and gas industry with over 300 systems operating worldwide. With our safety-focused and innovative approach, we responsively and decisively react to subsea challenges while providing solutions swiftly and efficiently.

.png)






