Cybersecurity Certification & Accreditation Analyst Lead
Remote / Online - Candidates ideally in
Virginia, St. Louis County, Minnesota, 55792, USA
Listed on 2026-03-05
Virginia, St. Louis County, Minnesota, 55792, USA
Listing for:
BMA
Remote/Work from Home
position Listed on 2026-03-05
Job specializations:
-
IT/Tech
Cybersecurity, Systems Engineer, Information Security, Security Manager
Job Description & How to Apply Below
BMA is seeking a Cybersecurity Certification & Accreditation Analyst Lead to support the DLA JETS Defense Agencies Initiative (DIA) Program Management Office (PMO) program. This is a fully remote position and contingent on contract award.
Job Summary- The Cybersecurity C&A Analyst – Lead serves as the senior technical authority supporting the DLA DAI Cybersecurity Assessment Program.
- This role provides expert leadership in Risk Management Framework implementation, Command Cyber Readiness Inspection preparation, vulnerability assessment, penetration testing, and security control validation within the DAI Oracle EBS R12.2 enterprise environment.
- Operating under consultative direction, the C&A Lead applies advanced cybersecurity principles, DISA STIG guidance, SCAP compliance standards, and DoD security regulations to design, assess, and continuously improve the security posture of the DAI system.
- The position independently analyzes exceptionally complex technical problems and develops innovative, compliant solutions to ensure DAI meets DoD cybersecurity readiness requirements.
- Primary Duties and
Responsibilities include: - Support RMF and Authorization Lifecycle Leadership.
- Serve as technical lead for RMF implementation and sustainment activities across the DAI environment.
- Develop, review, and maintain RMF artifacts.
- Provide technical direction on control inheritance, system boundary definitions, and security architecture alignment.
- Coordinate with Authorizing Officials, ISSMs, ISSOs, and system owners to ensure compliance readiness.
- Support CCRI Preparation and Vulnerability Assessments.
- Lead preparation for Command Cyber Readiness Inspections.
- Perform and oversee vulnerability assessments and analyze findings.
- Develop mitigation strategies and remediation tracking plans.
- Conduct penetration testing consistent with CEH, GPEN, or LPT standards.
- Support STIG Compliance and Security Engineering.
- Interpret and apply DISA Security Technical Implementation Guides and Security Requirements Guides.
- Develop product-specific STIG overlays for Oracle EBS R12.2 and associated infrastructure.
- Assess and validate compliance.
- Ensure SCAP-based configuration validation is properly implemented.
- Provide Oracle EBS R12.2 Security Oversight.
- Lead security evaluation of the Oracle EBS R12.2 platform.
- Support secure integration with financial, acquisition, and testing workflows.
- Evaluate security impacts of system enhancements and releases.
- Conduct Penetration Testing and Advanced Threat Analysis.
- Conduct or oversee penetration testing activities across application and network layers.
- Perform advanced threat analysis and recommend mitigation solutions.
- Analyze phishing exercises, USB detection events, and physical security testing results.
- Validate remediation of identified vulnerabilities.
- Support Cybersecurity Tool Selection and Innovation Initiatives.
- Recommend cybersecurity software tools and define tool selection criteria.
- Develop requirements for vulnerability assessment, compliance scanning, and monitoring solutions.
- Contribute to the development of new methodologies and advanced technological approaches to enhance DAI cybersecurity posture.
- Evaluate emerging cybersecurity technologies and recommend adoption where appropriate.
- Support Reporting, Risk Analysis, and Executive Briefings.
- Provide detailed technical reports.
- Present cybersecurity status to PMO leadership and executive stakeholders.
- Independently identify systemic security risks and propose strategic corrective actions.
- Support integration of cybersecurity findings into acquisition milestone reviews and audit documentation.
There is a Secret Security clearance requirement for this position.
Required Skills & Certifications- 7+ years of IT experience.
- 5+ years of cybersecurity experience.
- 5+ years of Oracle EBS R12.2 platform experience.
- Possesses one or more current penetration testing certifications such as LPT, CEPT, CEH, or GPEN.
- Proven experience performing Command Cyber Readiness Inspections, vulnerability assessments, and penetration testing.
- Served as a DISA Field Security Office certified CCRI Team Lead.
- Served as a Tenable Certified NESSUS Auditor.
- Expert knowledge…
To View & Apply for jobs on this site that accept applications from your location or country, tap the button below to make a Search.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
Search for further Jobs Here:
×