Provides deployed security services across ZENITH program components for the full range of security disciplines, including personnel security, information security, operational security, program protection, compartment security, and physical security. The program has six program teams working across four customer locations. The Cyber and Information Security Specialist (ISSM) Level 3 demonstrates substantive functional knowledge of all disciplines and requires almost no guidance. This role independently and consistently demonstrates comprehensive knowledge of all disciplines and serves as a directorate level resource. The specialist will provide comprehensive Information Security (INFOSEC) assistance and oversight to customers throughout the mission space in their role supporting Sponsor Information Systems Security Managers (ISSMs). They will coordinate with the ISSOs, who are collocated with Sponsor’s Office Departments, or Programs, to ensure that INFOSEC policy and ISSM guidance is appropriately followed and documented. This role involves reviewing and analyzing systems architecture diagrams and networks, assessing security system needs, and providing corrective actions into a coherent security strategy. It supports Assessment and Authorization (A&A) requirements and processes, applying ICD 503, NISPOM, and other federal guidelines in support of systems used at contractor facilities. The role also assists in the creation of new processes to support Sponsor and partners to advance security and lower risk, such as the Cyber Reset initiative, and pilots and enhances Sponsor Front Office initiatives. Custom documentation and step-by-step processes will be created to streamline cyber risk reduction, security relevant changes, and help maintain the current understanding of Sponsor systems. The specialist will assist Sponsor systems owners and/or service providers throughout the risk management framework (RMF), including the assessment and authorization (A&A) processes. This includes providing advice on the creation of required system documentation or body of evidence, assessing security and privacy controls and data protection, and assisting the security control accessors (SCA) in performing security systems assessments. The role involves creating plans of action & milestones (POA&Ms) and/or requesting risk acceptance. It provides oversight and guidance to ensure compliance with Sponsor information security regulations and policies on various requests, builds relationships with system owners and stakeholders, and reviews and approves requests for system access, crypto, hardware orders, and waivers. The specialist facilitates the development, maintenance, and security review of AIS security plans, conducts technical exchange meetings, and advises on Sponsor’s AIS policies. They ensure documentation is complete and accurate, support the investigation of virus/malware alerts/incidents, write reports based on technical analysis, and participate in project review meetings. The role involves reviewing complex system designs for security risk and compliance, proposing resolutions, and communicating complex technical concepts clearly to both technical and non-technical audiences.
Stand Out From the Crowd
Upload your resume and get instant feedback on how well it matches this job.
Job Type
Full-time
Career Level
Senior