The most security-conscious organizations trust Telos Corporation to protect their vital IT assets. The reputation of our company rests on the quality of our solutions and the integrity of our people. Explore what you can bring to our solutions in the areas of cyber, cloud and enterprise security.
Be a part of the Telos culture and see what sets us apart! Telos offers an excellent compensation package with benefits that include generous paid time off, medical, dental, vision, tuition reimbursement, and 401k. Our employees enjoy more than just a great work environment!
This position will be based at Virginia Beach, VA.
Responsibilities:
The Information System Security Specialist II provides cybersecurity compliance and accreditation support for Navy information systems under the Naval Surface Warfare Center Dahlgren Division (NSWCDD). The role ensures information systems meet all DoD cybersecurity and Risk Management Framework (RMF) requirements throughout the system lifecycle — from design and implementation through sustainment and re-accreditation.
The position supports both afloat and shore-based systems, working closely with engineers, system administrators, and program managers to identify vulnerabilities, develop mitigation strategies, and maintain Authorization to Operate (ATO) compliance.
Key Responsibilities
Accreditation & Compliance Support
• Develop, maintain, and update RMF documentation including Security Plans (SP), POA&Ms, Risk Assessments, and Continuous Monitoring Strategies.
• Support preparation, submission, and tracking of Assessment and Authorization (A&A) packages using tools such as eMASS.
• Review and apply DISA Security Technical Implementation Guides (STIGs) and Security Requirements Guides (SRGs) to ensure systems meet DoD compliance standards.
• Participate in A&A and cybersecurity readiness reviews, providing technical recommendations to system owners.
• Ensure all assigned systems maintain an active Authorization to Operate (ATO) and adhere to DoD, NAVSEA, and SECNAV cybersecurity policies.
Cybersecurity Engineering and Risk Management
• Conduct risk assessments and vulnerability analyses using automated scanning and compliance tools (e.g., ACAS, STIG Viewer, SCAP, Security Content Automation Protocol).
• Identify, document, and assist in remediation of system vulnerabilities and security incidents.
• Contribute to cybersecurity architecture planning, ensuring implementation of secure configurations, least privilege, and zero-trust principles.
• Review and maintain Interconnection Security Agreements (ISAs) and other boundary documentation to ensure continuous authorization alignment.
• Support implementation of Defense-in-Depth and supply chain risk management strategies.
Operations & Maintenance
• Provide ongoing cybersecurity monitoring and auditing support for operational systems.
• Track and report system vulnerabilities in accordance with Navy’s Vulnerability Remediation Asset Management (VRAM) system.
• Coordinate with system owners and administrators to ensure timely implementation of IAVAs, security patches, and configuration updates.
• Assist in incident response procedures and forensic investigations, documenting findings and mitigation actions