Information Systems Security Officer ensuring compliance with security standards for U.S. Department of Commerce systems. Conducting oversight activities and managing cybersecurity risks overall.
Responsibilities
Conduct security assessment, and information system security oversight activities in accordance with NIST 800.53 that support systems from the perspective RMF requirements.
Review systems to identify potential security weaknesses and recommend improvements to amend vulnerabilities, implement changes, and document upgrades.
Maintain responsibility for managing cybersecurity risk from an organizational perspective.
Identify organizational risks, prioritize those risks, and maintain a risk registry for escalating and presenting those risks to senior leadership.
Provide security guidance and IS validation using the National Institute of Standards and Technology (NIST) RMF, DoC, and local security policies.
Provide configuration management (CM) recommendations for information system security software, hardware, and firmware and coordinating changes and modifications with the ISSM, Security Control Assessor (SCA), and Authorizing Official (AO).
Maintain vulnerability scanning tool compliance, such as HBSS or ACAS, and patch management, to ensure IT staff pushes patches to all systems in an effort to maintain compliance with all applicable directives, manage system changes, and assess the security impact of those changes.
Support security authorization activities, including transitioning from DIACAP to compliance with the DoC RMF.
Requirements
Bachelor’s Degree.
A minimum of five (5) years experience as an Information Assurance (IA) Analyst, ISSE, ISSO, or similar role in ATO package development, including generating security documentation for requirements, security control assessment, STIG and IAVA compliance, Standard Operating Procedures, test results, etc.
eMASS experience.
Professional security certification such as: CCNA Security, CySA+, GICSP, GSEC, CompTIA Security+ CE, SSCP, or higher.
Strong desktop publishing skills using Microsoft Word and Excel.
Experience with industry writing styles such as grammar, sentence form, and structure.
Ability to multi-task in a deadline-oriented environment.
Benefits
Health, Dental, and Vision
Life Insurance
401k
Flexible Spending Account (Health, Dependent Care, and Commuter)
Paid Time Off and Observance of State/Federal Holidays
Head of Product Security leading the security strategy and engineering functions at Our Future Health. Managing a multidisciplinary security team to drive secure, trusted product development.
Information Systems Security Officer managing security oversight of federal systems. Conducting assessments and addressing cybersecurity risks in government projects.
Information Systems Security Officer ensuring compliance with RMF requirements for Dept. of Commerce systems at CGS. Involving security oversight activities, assessments, and risk management.
Information Systems Security Officer managing security assessments and A&A activities for government systems. Seeking a candidate with strong security documentation expertise and DIACAP/RMF experience.
Information Systems Security Officer conducting security assessments and managing ATO processes for government systems in Miami, FL. Seeking candidates with expertise in cybersecurity and risk management frameworks.
Information Systems Security Officer conducting security assessments and oversight for the Dept. of Commerce. Collaborating to achieve system authorization and managing cybersecurity risks and compliance.
IT Security Officer working on an initiative from the European Commission for customs modernization in the EU. Responsibilities include developing security policies, incident response, and business continuity planning.
Senior Counsel advising on national security and platform abuse legal matters at OpenAI. Collaborating with various teams to support AI system deployments.
AI Security Engineer strengthening the security of AI/ML pipelines and compliance at fintech company. Collaborating with data scientists and engineers to implement security controls across infrastructure.