RFP Attachment 2 - IA RMF IDIQ Labor Categories_v1_04-16-2024.xlsx
XLSX spreadsheet 32 KB Posted
- Attached to
- USCG Information Assurance (IA) Risk Management Framework (RMF) Support Services Federal contract opportunity
- Solicitation number
- 70Z04424RESDIAB01
About this file
This document is an RFP Attachment containing labor category descriptions for an Indefinite Delivery/Indefinite Quantity (IDIQ) contract for the U.S. Coast Guard's Information Assurance Risk Management Framework (IA RMF) Support Services.
The RFP outlines the labor category requirements across three proficiency levels (Basic, Intermediate, and Advanced) for positions such as Program Manager, Project Manager, Program Analyst, Security Control Assessor, Information System Security Officer, Information System Security Engineer, Database Specialist, Data Analyst, Technical Writer, and Cybersecurity Subject Matter Expert. Each labor category defines the required education, certifications, and years of experience. The RFP also includes a degree substitution table and a list of approved baseline cybersecurity certifications. This attachment provides the detailed qualifications for the personnel that will be supporting the IA RMF contract.
View the file
Other files for this federal contract opportunity
| File | Type | Posted |
|---|---|---|
| SF-30_0004_RMF RFP 70Z04424RESDIAB01.pdf | ||
| 0004 Questions - RFP 70Z04424RESDIAB01_06-03-2024.xlsx | XLSX spreadsheet | |
| RFP Attachment 1 - IA RMF IDIQ Scope of Work__v3-4_06-03-2024.pdf | ||
| IA-RMF_RFP-70Z04424RESDIAB01_v18_06-03-2024.pdf | ||
| SF-30_0003_RMF RFP 70Z04424RESDIAB01.pdf | ||
| SF-30_0002_RMF RFP 70Z04424RESDIAB01.pdf | ||
| SF-30_0001_RMF RFP 70Z04424RESDIAB01.pdf | ||
| RFP Attachment 1 - IA RMF IDIQ Scope of Work__v3-3_04-16-24.pdf | ||
| IA-RMF_RFP-70Z04424RESDIAB01_v17_04-16-2024.pdf | ||
| RFP Exhibit 2 - Question and Answer Form - v1_04-16-2024.xls | XLS spreadsheet |
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
General Information
| Proficiency Determination Guide | Proficiency Level Comparison | ||
| General: Proficiency levels describe the levels of a capability required to perform work successfully. | Level Indicator | Also Known As | Also Known As |
| Basic - The role requires an individual to have familiarity with basic concepts and processes and the ability to apply these with frequent, specific guidance. An individual must be able to perform successfully in routine, structured situations. | Level I | Junior or Entry-Level | Basic |
| Intermediate - The role requires an individual to have extensive knowledge of basic concepts and processes and experience applying these with only periodic high-level guidance. An individual must be able to perform successfully in non-routine and sometimes complicated situations. | Level II | Journeyman or Mid | Intermediate |
| Advanced - The role requires an individual to have an in-depth understanding of advanced concepts and processes and experience applying these with little to no guidance. An individual must be able to provide guidance to others. An individual must also be able to perform successfully in complex, unstructured situations. | Level III | Senior | Advanced |
Because of the specialized skills required for highly adaptive cybersecurity work, experience is often substituted for degree or degree for experience as shown in the substitution table. All experience and education shall be in a technical field related to the labor category being proposed and degrees will be from accredited institutions.
| Degree Substitution Table | ||||
| Degree | Related Work Experience Substitution | Related Degree and Experience Substitution | ||
| Associate's | 2 year’s work experience may be | |||
| substituted for an Associate’s Degree | 2 year’s work experience may be |
substituted for an Associate’s Degree Bachelor's 4 year’s work experience may be substituted for a Bachelor’s Degree Associate’s Degree plus 2 years work experience may be substituted for a Bachelor’s Degree
| Master's | 6 year’s work experience may be substituted for a Master’s Degree | Bachelor’s Degree plus 2 years work experience may be substituted for a Master’s Degree |
| Doctorate | 10 year’s work experience may be substituted for a Doctorate Degree | Bachelor’s Degree plus 6 years work experience, or a Master’s Degree plus 4 years work experience may be |
substituted for a Doctorate
Baseline Certifications
Approved Baseline Certifications (8570.01M) Reference Site: https://public.cyber.mil/wid/dod8140/dod-approved-8570-baseline-certifications/ NOTE: All of the 8570 certifications carried over to the 8140 Workforce Qualification and Management Program, so are listed here.
IAT Level I2 IAT Level II2 IAT Level III This table provides a list of DoD approved IA baseline certifications aligned to each category and level of the IA Workforce. Personnel performing IA functions must obtain one of the certifications required for their position, category/specialty and level to fulfill the IA baseline certification requirement. Most IA levels within a category or specialty have more than one approved certification and a certification may apply to more than one level.
An individual needs to obtain only one of the “approved certifications”; for his or her IA category or specialty and level to meet the minimum requirement. For example, an individual in an IAT Level II position could obtain any one of the seven certifications listed in the IAT Level II cell.
Higher level IAT and IAM certifications satisfy lower level requirements. Certifications listed in Level II or III cells can be used to qualify for Level I. However, Level I certifications cannot be used for Level II or III unless the certification is also listed in the Level II or III cell. For example:
The A+ or Network+ certification qualify only for Technical Level I and cannot be used for Technical Level II positions.
The System Security Certified Practitioner (SSCP) certification qualifies for both Technical Level I and Technical Level II. If the individual holding this certification moved from an IAT Level I to an IAT Level II position, he or she would not have to take a new certification.
Higher level CCSP and IASAE certifications do not satisfy lower level requirements
1. This category is equivalent to the CND-SP CATEGORY cited in the DoD 8570.01-M. The name was changed from CND-SP to CSSP to reflect current terminology in the DoD Instruction 8530.01 “Cybersecurity Activities Support to DoD Information Network Operations.
2. CCNA-Security was retired by Cisco, modified, and rebranded as simply “CCNA.” If you possessed the CCNA-Security and were in a position that required that certification when it was retired, you may be eligible for a waiver to cite the rebranded CCNA as a qualifying baseline certification. See the DoD CIO CCNA Security Waiver on the DoD Cyber Workforce Documents website for additional information.
** CySA+ is a CompTIA certification formerly listed as CSA+. The exam and the official name of the certification remain the same, only the acronym has changed.
*** CGRC (Certified in Governance, Risk and Compliance) is an (ISC)2 certification formerly listed as CAP (Certified Authorization Professional). Only the name of the certification has changed, and was effective February 15, 2023.
A+ CE
CCNA-Security
CND
Network+ CE SSCP CCNA-Security CySA+ **
GICSP
GSEC
Security+ CE
CND
SSCP CASP+ CE
CCNP Security
CISA
CISSP (or Associate)
GCED
GCIH
CCSP
| IAM Level I | IAM Level II | IAM Level III |
| CGRC*** |
CND
Cloud+
GSLC
Security+ CE
HCISPP CGRC***
CASP+ CE
CISM
CISSP (or Associate)
GSLC
CCISO
HCISPP CISM
CISSP (or Associate)
GSLC
CCISO
| IASAE I | IASAE II | IASAE III |
| CASP+ CE |
CISSP (or Associate)
CSSLP CASP+ CE
CISSP (or Associate)
CSSLP CISSP-ISSAP
CISSP-ISSEP
CCSP
| CSSP Analyst1, 2 | CSSP Infrastructure Support1 | CSSP Incident Responder1, 2 |
| CEH |
CFR
CCNA Cyber Ops CCNA-Security CySA+ **
GCIA
GCIH
GICSP
Cloud+
SCYBER
PenTest+ CEH CySA+ **
GICSP
SSCP
CHFI
CFR
Cloud+
CND CEH
CFR
CCNA Cyber Ops CCNA-Security
CHFI
CySA+ **
GCFA
GCIH
SCYBER
PenTest+
| CSSP Auditor1 | CSSP Manager1 |
| CEH |
CySA+ **
CISA
GSNA
CFR
PenTest CISM
CISSP-ISSMP
CCISO
Labor Categories
| Labor Category | Labor Category Description | Proficiency Level -> | Level I | |||||
| (Basic) | Level 2 | |||||||
| (Intermediate) | Level III | |||||||
| (Advanced) | Minimum Experience | |||||||
| (All Proficiency Levels) | DCWF Reference | |||||||
| Program Manager | Serves as the contract manager and administrator over the entire contract effort including IDIQ and task/delivery orders. Acts as the primary interface and point of contact with Government program authorities and representatives on technical and contract administration issues. Manages contract support operations involving personnel at diverse locations. Organizes, directs, and coordinates planning and production of all contract support activities. Must have demonstrated communications skills with all levels of management. Interfaces with Government managers including the Contracting Officers (KO) and the Contracting Officer's Representatives (COR). Under stringent timeframes, assembles and recruits personnel necessary to perform assigned tasks. Establishes and alters (as necessary) management structure to effectively direct contract support activities. Assigns, schedules, and reviews work of subordinates. Ensures conformance to contract and task order specifications and contract provisions. Interprets policies, purposes, and goals of the organization for subordinates. Must be capable of negotiating and making binding decisions for the company. Supervises program operations by developing management procedures, planning and directing program execution, monitoring and reporting progress. Manages and controls financial and administrative aspects of the program with respect to contract requirements. | Foundational Qualifications for Program Manager: | Education | Bachelor's degree or higher in Computer Science, Cyber Security, Information Technology, Software Engineering, Information Systems, Computer Engineering, or other related discipline. (no substitution for education reqmt.) | Bachelor's degree or higher in Computer Science, Cyber Security, Information Technology, Software Engineering, Information Systems, Computer Engineering, or other related discipline. (no substitution for education reqmt.) | Bachelor's degree or higher in Computer Science, Cyber Security, Information Technology, Software Engineering, Information Systems, Computer Engineering, or other related discipline. (no substitution for education reqmt.) | Demonstrated capability in managing multitask contracts and/or subcontracts of various types and complexity; expertise in the management and control of funds and resources; demonstrated information technology expertise and communications skills to be able interface with all levels of management. |
Core Knowledge of:
- risk management processes (e.g., methods for assessing and mitigating risk)
- national and international laws, regulations, policies, and ethics as they relate to cybersecurity
- cybersecurity principles
- cyber threats and vulnerabilities
- computer networking concepts and protocols, and network security methodologies
| - specific operational impacts of cybersecurity lapses | 801, 751 | ||||
| AND | AND | AND | |||
| Certification | CGRC or Security+ |
AND
PMP or PgMP CGRC or CASP+
AND
PMP or PgMP CCISO or CISM or CISSP or GSLC
AND
PMP or PgMP
| AND | AND | AND | |
| Experience (years) | 1 | 3 | 5 |
Project Manager Serves as the central point of contact for task/delivery orders and interfaces with the Contracting Officer's Representatives for tasks. Establishes and enforces procedures to ensure that all tasks are performed in accordance with applicable standards and quality requirements. Assigns duties and reviews work of subordinates and subcontractors. Meets and confers with CG management officials regarding status of specific technical activities and progress. Resolves problems, issues or conflicts as required, and ensures that program schedules, performances, and deliverables are met. Foundational Qualifications for Project Manager: Education Associates degree in Computer Science, Cyber Security, Information Technology, Software Engineering, Information Systems, Computer Engineering, or other related discipline. Bachelor's degree in Computer Science, Cyber Security, Information Technology, Software Engineering, Information Systems, Computer Engineering, or other related discipline. Bachelor's degree in Computer Science, Cyber Security, Information Technology, Software Engineering, Information Systems, Computer Engineering, or other related discipline. Demonstrated information technology expertise and direct hands-on experience in the areas of Information Assurance, Cybersecurity, and project management; demonstrated communication skills to be able to interface with all levels of management; strong project management skills in addition to interpersonal, writing, and presentation skills; experience supervising and managing projects of at least 15 personnel, subordinate groups, and/or diverse locations.
Core Knowledge of:
- risk management processes (e.g., methods for assessing and mitigating risk)
- national and international laws, regulations, policies, and ethics as they relate to cybersecurity
- cybersecurity principles
- cyber threats and vulnerabilities
- computer networking concepts and protocols, and network security methodologies
| - specific operational impacts of cybersecurity lapses | 802, 751 | ||||
| AND | AND | AND | |||
| Certification | CISM or CISSP | CISM or CISSP | CCISO or CCSP or CISA or CISM or CISSP or CISSP-ISSEP or CISSP-ISSMP or GSLC | ||
| AND | AND | AND | |||
| Experience (years) | 1 | 3 | 5 |
Program Analyst Possess demonstrated knowledge and experience applying methodologies and principles to address client needs. Applies analytic techniques in the evaluation of task objectives and contributes to the implementation of strategic direction. Performs analyst functions including data gathering, interviewing, data modeling, testing, and creation of performance measurements to support objectives. Conducts activities in support of project team's objectives. Works closely with other members of the project team. Foundational Qualifications for Program Analyst: Education Associates degree in Computer Science, Cyber Security, Information Technology, Software Engineering, Information Systems, Computer Engineering, or other related discipline. Bachelor's degree in Computer Science, Cyber Security, Information Technology, Software Engineering, Information Systems, Computer Engineering, or other related discipline. Bachelor's degree in Computer Science, Cyber Security, Information Technology, Software Engineering, Information Systems, Computer Engineering, or other related discipline. Demonstrated experience supporting the implementation of the DIACAP, RMF, DCIS 6/3, NIST, ICD 505, and DODIIS requirements; demonstrated experience in analyzing and preparing program documents and reports; knowledge and capability in developing program requirements, documentation, financial, and/or technical requirements; strong writing and presentation skills; demonstrated communication skills to interface with all levels of management.
Core Knowledge of:
- risk management processes (e.g., methods for assessing and mitigating risk)
- national and international laws, regulations, policies, and ethics as they relate to cybersecurity
- cybersecurity principles
- cyber threats and vulnerabilities
- computer networking concepts and protocols, and network security methodologies
| - specific operational impacts of cybersecurity lapses | 805 | ||||
| OR | OR | OR | |||
| Certification | GSEC or Security+ | CGRC or CASP+ or GSNA or SSCP | CCISO or CCSP or CISA or CISM or CISSP or GSLC | ||
| AND | AND | AND | |||
| Experience (years) | 0 | 0 | 2 |
Security Control Assessor Conducts independent comprehensive assessments of the management, operational, and technical security controls and control enhancements employed within or inherited by an information technology (IT) system to determine the overall effectiveness of the controls. Foundational Qualifications for SCA: Education Associates degree in Computer Science, Cyber Security, Information Technology, Software Engineering, Information Systems, Computer Engineering, or other related discipline. Bachelor's degree in Computer Science, Cyber Security, Information Technology, Software Engineering, Information Systems, Computer Engineering, or other related discipline. Bachelor's degree in Computer Science, Cyber Security, Information Technology, Software Engineering, Information Systems, Computer Engineering, or other related discipline. Demonstrated experience in determining how a security system should work including its resilience and dependability capabilities; Demonstrated experience in discerning the protection needs of information systems, networks, and platform information technology; Demonstrated experience in applying the principles of confidentiality, integrity, and availability.
Core Knowledge of:
- risk management processes (e.g., methods for assessing and mitigating risk)
- national and international laws, regulations, policies, and ethics as they relate to cybersecurity
- cybersecurity principles
- cyber threats and vulnerabilities
- computer networking concepts and protocols, and network security methodologies
| - specific operational impacts of cybersecurity lapses | 612 | ||||
| AND | AND | AND | |||
| Certification | CGRC or CASP+ or Cloud+ or CYSA+ or PenTest+ | CGRC or CASP+ or Cloud+ or CYSA+ or PenTest+ | CCISO or CISA or CISM or CISSP or CISSP-ISSEP or GSLC or GSNA | ||
| AND | AND | AND | |||
| Experience (years) | 1 | 3 | 5 |
Information System Security Officer Analyzes and defines security requirements. Performs risk analysis and security contol assessment and audit services, develops analytical reports as required. May be required to perform or assist in one or more of the following areas: Risk and Vulnerability Assessments; scanning; assessment of system security for compliance of applications; security of computer network hardware; operating system utility/support software; disaster recovery; incident response; application assessment; vulnerability threat management; cloud security; contingency planning; social engineering; and the development of security procedures. Possess and apply expertise on multiple complex work assignments. Foundational Qualifications for ISSO: Education Associates degree in Computer Science, Cyber Security, Information Technology, Software Engineering, Information Systems, Computer Engineering, or other related discipline. Associates degree in Computer Science, Cyber Security, Information Technology, Software Engineering, Information Systems, Computer Engineering, or other related discipline. Bachelor's degree in Computer Science, Cyber Security, Information Technology, Software Engineering, Information Systems, Computer Engineering, or other related discipline. Demonstrated experience in discerning the protection needs of information systems, networks, and platform information technology; Demonstrated experience in applying the principles of confidentiality, integrity, and availability; Demonstrated experience implementing the RMF process especially for system categorization and control selection, implementation, and assessment, as well as continuous monitoring.
Core Knowledge of:
- risk management processes (e.g., methods for assessing and mitigating risk)
- national and international laws, regulations, policies, and ethics as they relate to cybersecurity
- cybersecurity principles
- cyber threats and vulnerabilities
- computer networking concepts and protocols, and network security methodologies
| - specific operational impacts of cybersecurity lapses | 622, 722, 511 | ||||
| AND | AND | AND | |||
| Certification | CGRC or CASP+ or CCISO or CCSP or CISM or CISSP or Cloud+ or SSCP or CSSLP | CGRC or CASP+ or CCISO or CCSP or CISM or CISSP or Cloud+ or SSCP or CSSLP | CISSP-ISSMP or GSLC | ||
| AND | AND | AND | |||
| Experience (years) | 1 | 3 | 5 |
Information System Security Engineer Provides technical input, recommendations, and assistance with the implementation of both higher and granular-level cyber security approaches, methods, and solutions that incorporate and maintain compliance to requirements resulting from laws, regulations, and other pertinent guidance. May be required to perform or assist in one or more of the following areas: Risk and Vulnerability Assessments; Cyber Hunting activities; conducting scanning; assessment of system security for compliance of applications; security of computer network hardware; operating system utility/support software; disaster recovery; incident response and digital forensics; vulnerability threat management; cloud security; contingency planning; social engineering; and the development of security procedures. Possess and apply expertise on multiple complex work assignments. Foundational Qualifications for ISSE: Education Associates degree in Computer Science, Cyber Security, Information Technology, Software Engineering, Information Systems, Computer Engineering, or other related discipline. Associates degree in Computer Science, Cyber Security, Information Technology, Software Engineering, Information Systems, Computer Engineering, or other related discipline. Bachelor's degree in Computer Science, Cyber Security, Information Technology, Software Engineering, Information Systems, Computer Engineering, or other related discipline. Demonstrated experience in Information Security (INFOSEC); computer security; cryptography; network security; assessment and authorization; incident response investigations; risk analysis; threat and vulnerability scanning, analysis, and management. Demonstrated experince with system and security engineering principles such as secure architecture, design, and development, and defense in depth. Demonstrated communication skills to interface with all levels of management, as well as appropriate use of style and language for audience.
Core Knowledge of:
- risk management processes (e.g., methods for assessing and mitigating risk)
- national and international laws, regulations, policies, and ethics as they relate to cybersecurity
- cybersecurity principles
- cyber threats and vulnerabilities
- computer networking concepts and protocols, and network security methodologies
| - specific operational impacts of cybersecurity lapses | 652, 511, 541 | ||||
| AND | AND | AND | |||
| Certification | GSEC or Security+ | CASP+ or CCSP or Cloud+ or CSSLP | CISSP-ISSAP or CISSP-ISSEP | ||
| AND | AND | AND | |||
| Experience (years) | 1 | 3 | 5 |
Database Specialist Provides all activites related to the administration of computerized databases. Designs, creates, administers, and maintains databases and/or data management systems that allow for the storage, query, and utilization of data. Includes maintenance of database dictionaries, overall monitoring, and integration of data feeds. Projects long-range requirements for database administration and design to meet end-user needs. Foundational Qualifications for Database Specialist: Education Associates degree in Computer Science, Cyber Security, Information Technology, Software Engineering, Information Systems, Computer Engineering, or other related discipline. Bachelor's degree in Computer Science, Cyber Security, Information Technology, Software Engineering, Information Systems, Computer Engineering, or other related discipline. Bachelor's degree in Computer Science, Cyber Security, Information Technology, Software Engineering, Information Systems, Computer Engineering, or other related discipline. Demonstrated experience in establishing data security controls, maintaining databases, and optimizing database performance.
Core Knowledge of:
- risk management processes (e.g., methods for assessing and mitigating risk)
- national and international laws, regulations, policies, and ethics as they relate to cybersecurity
- cybersecurity principles
- cyber threats and vulnerabilities
- computer networking concepts and protocols, and network security methodologies
| - specific operational impacts of cybersecurity lapses | 421, 431 | ||||
| AND | AND | AND | |||
| Certification | GSEC or Security+ | Security + or Cloud+ or SSCP | CASP+ or CCNP Security or CISA or CISSP or CISSP-ISSAP or CISSP-ISSEP | ||
| AND | AND | AND | |||
| Experience (years) | 1 | 3 | 5 |
Data Analyst Analyzes and interprets data from multiple disparate sources and builds visualizations and dashboards to report insights. Conducts quality control of databases to ensure accurate and appropriate use of data. Foundational Qualifications for Data Analyst: Education Associates degree in Computer Science, Cyber Security, Information Technology, Software Engineering, Information Systems, Computer Engineering, or other related discipline. Bachelor's degree in Computer Science, Cyber Security, Information Technology, Software Engineering, Information Systems, Computer Engineering, or other related discipline. Bachelor's degree in Computer Science, Cyber Security, Information Technology, Software Engineering, Information Systems, Computer Engineering, or other related discipline. Demonstrated experience in the following areas: conducting queries and developing algorithms to analyze data structures; generating queries and reports; identifying data patterns/relationships; statistics and associated techniques; use of data analysis tools and writing scripts. Demonstrated communications skills to interface with all levels of management. Strong interpersonal skills to include approachability, effective listening, and appropriate use of style and language for the audience.
Core Knowledge of:
- risk management processes (e.g., methods for assessing and mitigating risk)
- national and international laws, regulations, policies, and ethics as they relate to cybersecurity
- cybersecurity principles
- cyber threats and vulnerabilities
- computer networking concepts and protocols, and network security methodologies
| - specific operational impacts of cybersecurity lapses | 422, 431 | ||||
| AND | AND | AND | |||
| Certification | GSEC or Security+ | Security + or SSCP | CCISO or CISM or CISSP or GSLC | ||
| AND | AND | AND | |||
| Experience (years) | 1 | 3 | 5 |
Technical Writer Gathers, analyzes, and composes technical information required to prepare technical and cybersecurity documentation. Writes and maintains technical documentation in support of the RMF process and cybersecurity program. Reviews content of documentation for quality and conformance with standards. Conducts research and ensures the use of proper technical terminology. Interviews technical resource personnel for content and performs content validation. Translates technical information into clear, readable documents to be used by technical and non-technical personnel. Foundational Qualifications for Technical Writer: Education Associates degree in Computer Science, Cyber Security, Information Technology, Software Engineering, Information Systems, Computer Engineering, English, or other related discipline. Associates degree in Computer Science, Cyber Security, Information Technology, Software Engineering, Information Systems, Computer Engineering, English, or other related discipline. Associates degree in Computer Science, Cyber Security, Information Technology, Software Engineering, Information Systems, Computer Engineering, English, or other related discipline. Demonstrated experience in producing and/or editing technical documentation and reports, consolidating technical input and analyses, generating a logical, understandable flow of information, and writing for technical and non-technical audiences.
Core Knowledge of:
- risk management processes (e.g., methods for assessing and mitigating risk)
- national and international laws, regulations, policies, and ethics as they relate to cybersecurity
- cybersecurity principles
- cyber threats and vulnerabilities
- computer networking concepts and protocols, and network security methodologies
| - specific operational impacts of cybersecurity lapses | 411 | ||||
| AND | AND | AND | |||
| Certification | A+ or Network+ or Security+ | CND or GICSP | CASP+ or CCNP Security or CISA or SSCP | ||
| AND | AND | AND | |||
| Experience (years) | 1 | 3 | 5 |
Cybersecurity Subject Matter Expert Serve as a technical expert in areas relevant to a particular project. Produce and/or review substantive and/or complex technical documentation reflecting detailed knowledge of technical areas as identified in the statement of work/performance work statement. Documentation subjects include but are not limited to systems design, system architecture, feasibility studies, and system specifications. Provides insight and guidance regarding strategic, tactical, and operational cybersecurity plans. Resolves complex problems, which require an in-depth knowledge of subject matter to specialized solutions. Confers with management team and leads in the outline and development of cybersecurity strategies and solutions. Analyzes and assesses systems and architecture requirements and recommends cybersecurity solutions. Assists in developing strategic cybersecurity plans and concepts. Advises on the impact of new cybersecurity legislation, mandates, regulations, or new technologies and industry best-practices that are relevant to the USCG. Foundational Qualifications for Cybersecurity SME: Education Bachelor's degree in Computer Science, Cyber Security, Information Technology, Software Engineering, Information Systems, Computer Engineering, or other related discipline. (no substitution for education reqmt.) Bachelor's degree in Computer Science, Cyber Security, Information Technology, Software Engineering, Information Systems, Computer Engineering, or other related discipline. (no substitution for education reqmt.) Bachelor's degree in Computer Science, Cyber Security, Information Technology, Software Engineering, Information Systems, Computer Engineering, or other related discipline. (no substitution for education reqmt.)
Possesses requisite knowledge and expertise so recognized in the professional cybersecurity community that the individual is considered "expert" and a technical leader in the cybersecurity areas being addressed. Demonstrates exceptional oral and written communication skills.
Core Knowledge of:
- risk management processes (e.g., methods for assessing and mitigating risk)
- national and international laws, regulations, policies, and ethics as they relate to cybersecurity
- cybersecurity principles
- cyber threats and vulnerabilities
- computer networking concepts and protocols, and network security methodologies
| - specific operational impacts of cybersecurity lapses | 652, 722, 752 | ||||
| AND | AND | AND | |||
| Certification | GSEC or Security+ | CASP+ or CCSP or CISSP or Cloud+ or CSSLP | CISSP-ISSAP or CISSP-ISSEP | ||
| AND | AND | AND | |||
| Experience (years) | 4 | 6 | 8 |
File details come from the government source that posted it. Updated .