Description of the job
Job Description
- Liaise with the various simulation Original Equipment Manufacturers (OEM) and stakeholders to understand and discuss, as relevant to SA&A, the system architecture of the simulators and training systems, their supported and required security controls and operational and maintenance concepts and procedures.
- Draft or review and modify Information System Security Orders for each school including specific Annexes for each of the simulators and training systems.
- Draft or review and modify SA&A related modifications to the Facility Site Plans for all affected buildings housing simulators and training systems. These include Incident Response Plans, Contingency Plans, Awareness and Training Plans, and Continuous Monitoring Plans.
- Support Subject Matter expert in initial draft or review of required Concept of Operations (CONOPS) documents for simulators, training systems, and applications.
- Draft or review and modify System Requirements Traceability documents.
- Review and make recommendations for changes to Operation and Maintenance documentation for the simulators and training systems.
- Populate the SA&A Access Database with security controls for training technologies. Ensure all documentation for applications entered either Pro B SharePoint for SA&A work or TTI Training Tracker for software.
- Perform rework of any SA&A document submissions as directed by the security establishment after their review of the SA&A submissions.
- Develop Evidence Plans used to test and validate that the documented security controls are in place and effective to ensure successful transfer of interim Authority to Operate to Authority to Operate.
- Collect and collate security controls testing evidence. These can include documents such as configuration management plans, operation manuals, computer log files, and screen shots.
- Provide support for status briefings by the NFSA and NFSP ISSOs to their chain of command and other relevant stakeholders.
- Draft Requests for Change as required.
- Maintain horizon knowledge of vendors cyber compliance.


