About the job
Join SMX as a Validator/Vulnerability Management Lead, where you will play a pivotal role in supporting the Unmanned Carrier Aviation Program Office (PMA-268) at the Patuxent River Naval Air Station, responsible for the innovative MQ-25 Stingray unmanned air system. This position offers the flexibility of a hybrid work environment.
Key Responsibilities:
- Evaluate and validate PMA-268 Risk Management Framework (RMF) packages, including Authorizations to Operate (ATOs) and Interim Authorizations to Test (IATTs).
- Collaborate with the Integrated Product Team (IPT) Security Systems Engineer (SSE) and Information System Security Officer (ISSO) to develop and submit the Security Assessment Plan (SAP) for approval.
- Conduct thorough execution of the SAP and summarize failed controls within the Enterprise Mission Assurance Support Service (eMASS).
- Prepare the Security Assessment Report (SAR) and recommend updates to the Plan of Actions and Milestones (POA&M) based on assessment findings.
- Ensure comprehensive traceability of all vulnerabilities from assessment results to the POA&M.
- Assist in Continuous Monitoring (ConMon) activities, including annual security reviews and system changes.
- Compile a consolidated list of mitigation strategies for POA&Ms, aiding ISSOs in addressing common non-compliant security controls.
- Lead the Vulnerability Management initiatives and establish a robust PMA-268 vulnerability management program.
- Draft a PMA Vulnerability and Patch Management Policy and coordinate the development of System-level Vulnerability and Patch Management Plans (VPMP).
- Act as the NAVAIR Rapid Response Lead for PMA-268 by attending relevant meetings, coordinating responses to received orders, and maintaining a Cyber Directive Status tracker.
- Oversee PMA-268 Portfolio VRAM records management.

