Information Systems Security Officer role responsible for IT security policies and incident response. Supporting NOAA's mission with expertise in federal information security and compliance standards.
Responsibilities
Develop and implement IT security policies and procedures to safeguard NOAA's information systems and data.
Support annual training for all personnel accessing sensitive information to ensure awareness and compliance with security protocols.
Provide guidance and instruction to staff regarding their individual responsibilities within the cybersecurity framework.
Implement and manage security technologies (firewalls, encryption, vulnerability scanning) to protect NOAA’s IT resources and ensure they remain secure.
Lead efforts to respond to and investigate IT security incidents, ensuring quick, effective resolution and coordination with relevant parties.
Collaborate with NOAA departments and external agencies to ensure a unified approach to IT security across the organization.
Oversee the accreditation of NOAA’s IT systems, ensuring systems meet established security standards and guidelines.
Provide continuous monitoring of NOAA’s IT infrastructure, ensuring ongoing situational awareness and early detection of security threats.
Assess vulnerabilities and security risks within NOAA’s systems, proposing and implementing risk mitigation strategies.
Participate in ongoing Security Assessments for each application, including support for achieving and maintaining an Authority to Operate (ATO), and addressing security issues identified in the POA&M and Security Assessment Report.
Implement data masking procedures to protect Personally Identifiable Information (PII).
Requirements
Proven experience in IT security roles, preferably in a federal or governmental environment.
Experience with Cloud Responsibility Model and keeping it updated.
Tracking and following Compliance Standards via NIST.
Experience using Tenable scan utility.
Experience using ArcSight and BigFix asset inventory tools.
Project Management (Self-directed management of projects).
Technical Writing.
Knowledge of security frameworks (NIST, ISO 27001, etc.) and security tools.
Familiarity with incident response processes and vulnerability management.
Experience with security accreditation and continuous monitoring.
Strong communication and collaboration skills, with the ability to work across multiple teams and agencies.
Ability to obtain and maintain a Public Trust background check.
Benefits
Comprehensive Health Benefits (Medical, Dental, and Vision) including High Deductible Health Plan where the company pays 100% of the deductible for your family.
Flexible Spending Accounts (FSA) & Health Savings Account (HSA).
Retirement Plan with 4% match and discretionary match at year end.
Paid Time Off (PTO): 15 days of PTO accrued per year; 7 holidays + 3 Floating holidays; 2 Innovation days (paid training days).
IT Security Specialist focusing on cyber defense within a family - owned company. Responsibilities include managing firewalls, monitoring threats, and implementing security solutions.
Junior Information Systems Security Engineer at AMERICAN SYSTEMS managing DoD cyber security. Collaborating on technical issues and supporting risk management framework compliance.
Information Systems Security Engineer assisting in cyber security requirements for DoD systems. Collaborating closely with customers and ensuring compliance with the DoD Risk Management Framework.
Staff Product Security Engineer driving security innovation while ensuring compliance with federal standards at DataRobot. Leading security engineering, automation, and customer engagement for federal customers.
Auszubildende(n) zur Fachkraft für Schutz und Sicherheit in Hamburg bei proSicherheit GmbH. Modernes Sicherheitsunternehmen mit Fokus auf Sicherheit und Vertrauensaufbau.
Security staff for proSicherheit performing access controls and ensuring compliance with safety standards. Involves reporting, patrolling, and handling emergencies in Hamburg area.
Cyber Security Engineer responsible for DevSecOps and security automation at a leading Swiss IT consulting firm. Engaging in security measures across industries with a focus on collaboration and technology.
Cloud Security Architect responsible for strategic growth and development of Cloud Security solutions. Work with national clients on architecture and security concepts in Switzerland.
Information Security Manager coordinates ISMS development and security measures for Megamaris GmbH. Responsible for risk analysis and security training across 12 subsidiaries.
Security GRC Manager managing audits and compliance programs at Salesforce. Overseeing cloud security compliance and collaborating across departments for risk management.