CND Web Services Systems Analyst (WSSA)

Web Services Systems Analyst for Computer Network Defense Research & Technology Program Management Office (CND R&T PMO). Develops standards for CND Data Integration. Develops reference implementations of standards-based CND data integration tools. This is a FULL TIME position (1920 hrs / yr)

Qualifications:
- Three or more years working with CND and/or network management-related tools to protect networks or ensure their continued optimized performance.

- Two or more years of developing web-service based systems to function across multiple organizational boundaries, to include XML, SOAP, WSDL, and other current web service technologies and protocols.

- Two years minimum familiarity with data modeling tools capable of developing, editing, and validating XML and UML data models for operational use (e.g. Rational Rose or Power Designer).

- Two years minimum experience working with standards bodies such as the National Institute of Standards and Technology (NIST), Internet Engineering Task Force (IETF), International Telecommunications Union (ITU), or similar bodies.

- Two years minimum experience writing XML documents for protocols in the NIST Security Content Automation Protocol (SCAP) suite, to include the Open Vulnerability and Assessment Language (OVAL), Common Vulnerability Enumeration (CVE), Common Platform Enumeration (CPE), Common Configuration Element (CCE), eXtensible Configuration Checklist Distribution Framework (XCCDF) or similar standards.

- Two years minimum working with DoD IA/CND operational constructs such as the Information Assurance Vulnerability Management System (IAVM), the Security Technical Implementation Guidance (STIG), Computer Emergency Response Teams (CERTs), Network Operations (NetOps), formal risk management processes, IA/CND metrics, red-teaming, blue-teaming, and asset management systems. Familiarity should be current (i.e. experience should be within the last 18 months and extend for at least 3 years).

- Two years minimum experience designing, building, or operating IA/CND systems including: the Vulnerability Management System (VMS), Ports and Protocols Management System (PPMS), Security Configuration Compliance Validation Initiative (SCCVI), Security Compliance Remediation Initiative (SCRI), Joint CERT Database (JCD), Host-Based Security System (HBSS) or their service and commercial equivalents.