Information Systems Security Officer
TS/SCI with Poly Clearance Required
As the ISSO, you will serve on a team responsible for the Authorization and Assessment process under the Risk Management Framework for new and existing information systems and will be expected to maintain Authority to Operate compliance for all assigned systems.
Responsibilities:
- Provide guidance and technical expertise on all matters that impact or effect the security of the information system.
- Assist in the development and execution of an enterprise level continuous monitoring program to minimize security risks and ensure compliance with that program on a routine basis.
- Developing, updating, and submitting the System Security Plan and other required documentation that make up the Security Authorization Package.
- Conduct configuration management for security-relevant changes to software, hardware, and firmware.
- Perform and deliver security impact analyses of changes to the system or its environment of operation.
- Assess the effectiveness of system security controls on an ongoing basis to determine system security status.
- Maintain and enforce IT security policies and implementation guidelines for customer systems in diverse operational environments.
- Provides configuration management for security-relevant information system software, hardware, and firmware.
Requirements:
- 6 + years of experience required
- The security authorization processes and procedures knowledge as defined in the RMF in NIST SP800-37 and familiarity with the ICD503, CNSSI1253, SP800-53, etc.
- Experience with hardware/software security implementations.
- Knowledge of different communication protocols, encryption techniques/tools, and PKI and authorization services.
- Familiarity with security incident management, experience collaborating with Incident Response Teams, and able to provide viable recommendations for the resolution or computer security incidents and vulnerability compliance.
Required Certifications:
- DoD 8570.1 compliant IAM Level I certification, such as the CompTIA Security+ certification.
- A higher-level certification, such as GSLC, CAP, CASP, CISM and/or CISSP will also be accepted.
Apply Now