Information Systems Security Officer managing security oversight of federal systems. Conducting assessments and addressing cybersecurity risks in government projects.
Responsibilities
Conduct security assessment, and information system security oversight activities in accordance with NIST 800.53 that support systems from the perspective RMF requirements.
Review systems to identify potential security weaknesses and recommend improvements to amend vulnerabilities, implement changes, and document upgrades.
Maintain responsibility for managing cybersecurity risk from an organizational perspective.
Identify organizational risks, prioritize those risks, and maintain a risk registry for escalating and presenting those risks to senior leadership.
Provide security guidance and IS validation using the National Institute of Standards and Technology (NIST) RMF, DoC, and local security policies.
Provide configuration management (CM) recommendations for information system security software, hardware, and firmware and coordinating changes and modifications with the ISSM, Security Control Assessor (SCA), and Authorizing Official (AO).
Maintain vulnerability scanning tool compliance, such as HBSS or ACAS, and patch management, such as IAVM to ensure IT staff pushes patches to all systems in an effort to maintain compliance with all applicable directives, manage system changes, and assess the security impact of those changes.
Support security authorization activities, including transitioning from the legacy Information Assurance Certification and Accreditation Process (DIACAP) to compliance with the DoC RMF.
Provide subject matter expertise for cyber security and trusted system technology.
Apply advanced technical knowledge and analysis of specialized functional areas in task requirements to develop solutions to complex problems.
Research, write, review, disposition feedback, and finalize recommendations regarding cyber security policy, assessment and authorization assessments (A&As), security test and evaluation reports, and security engineering practices and processes.
Conduct research and write risk assessment reports to include risk thresholds, evaluation, and scoring.
Support analysis of the findings and provide expert technical guidance for mitigation strategies, including implementation advice on the cyber security risk findings, and other complex problems.
Requirements
Bachelor’s Degree.
A minimum of five (5) years experience as an Information Assurance (IA) Analyst, ISSE, ISSO, or similar role in ATO package development, including generating security documentation for requirements, security control assessment, STIG and IAVA compliance, Standard Operating Procedures, test results, etc.
eMASS experience.
Professional security certification such as: CCNA Security, CySA+, GICSP, GSEC, CompTIA Security+ CE, SSCP, or higher.
Strong desktop publishing skills using Microsoft Word and Excel.
Experience with industry writing styles such as grammar, sentence form, and structure.
Ability to multi-task in a deadline-oriented environment.
Benefits
Health, Dental, and Vision
Life Insurance
401k
Flexible Spending Account (Health, Dependent Care, and Commuter)
Paid Time Off and Observance of State/Federal Holidays
Security Engineer providing application security guidance for YUM! e - commerce and mobile apps. Collaborate with teams to identify and remediate security vulnerabilities effectively in various applications.
Information Security Officer responsible for cybersecurity strategies and compliance in an IT service provider for food and beverage industry. Developing security standards, managing incidents, and collaborating with leadership.
Senior Security Engineer responsible for implementing security systems and conducting incident response at Emburse. Collaborating with teams to identify and mitigate security threats.
Cybersecurity Engineer guiding systems through the Risk Management Framework at Skyward Federal. Ensuring compliance with DoD cybersecurity requirements and maintaining secure technologies.
Cybersecurity Intern at Thndr. Gain hands - on experience in securing cloud - native infrastructure and applications while collaborating with senior security engineers.
Account Executive driving new business growth for Strider Technologies via strategic client relationships. Transforming open - source data into actionable insights to protect from nation - state risks.
Senior Security Engineer leading security initiatives to protect customer data at an AI - native legal tech company. Collaborating across functions to ensure compliance and security best practices.
Working Student in Information Security at Allianz Direct supporting security monitoring and managing vulnerability assessments. Collaborating with cross - functional teams to enhance cybersecurity posture and awareness.
Enterprise Security Implementation Specialist at Vodafone supporting customers in implementing security solutions. Responsibilities include onboarding, incident management, and ensuring service quality with Fortinet and Zscaler products.