Information System Security Officer (ISSO)

General Dynamics Information Technology
2d$89,250 - $120,750Onsite

About The Position

Responsibilities: Performs Cybersecurity activities for a large Program; coordinates with government Program staff, USAF, and other government agencies to assist in the creation, dissemination, direction, and auditing of program policy, standards, and operating procedures. Support the government ISSMs in the development and staffing of documentation related to the Authorization to Operate (ATO), Authorization to Connect (ATC), Interim Authorization to Test (IATT), Plans of Action & Milestones (POA&Ms), etc. Assist in the development and execution of any required Security Test and Evaluation (ST&E) plans. Produce and provide A&A materials (to include engineering project briefs and outstanding RMF actions? for DoD IT packages by phase, including expiring authorizations and the resolution of issues impacting those packages). Provide USG with a review of architecture documentation, security impact analysis, and risk mitigation/acceptance to support RMF for DoD IT authorization. Provide security design management control of build processes for servers, services, and end points. Comply with hosting facility ATOs where the MPCO IS are dependent on them. Ensure good cybersecurity and vulnerability management practices are developed, implemented, and enforced. Conduct network and system audits for vulnerabilities using Security Technical Implementation Guides (STIGs), DISA SCAP, ACAS vulnerability scanner, ESS Policy Auditor to mitigate those findings for Linux, Windows, Cisco, Juniper, VMWare and other associated operating systems and technologies. Implement the Continuous Monitoring program by creating, tracking, reviewing, and closing Plan of Action and Milestones (POA&Ms) and Risk Acceptances and assist in conducting solution identification to assist in problem remediation and resolution. Communicate tactical and strategic threat information to Government leaders, Cybersecurity-Ops and A&A Staff to assist them in making cyber risk decisions and to mitigate threats. Carries out DoD Risk Management Framework (RMF) in accordance with DoD 8510 to ascertain information systems' security posture by utilizing security control validation activities and coordinating security testing. Coordinates with AFRL, and USAF, and other organizations in support of audits and inspections and provides all necessary documentation as required for SAVs, ST&Es, and CCRI Evaluate change requests (firewall, systems, networks) and assess organizational risk. Ensures the integrity and protection of networks, systems, and applications by technical enforcement of organizational security policies, through monitoring of vulnerability scanning devices. Provides guidance and work leadership to less-experienced technical staff members. Maintains current knowledge of relevant technology as assigned. Process tickets in support of the program using the accepted ITSM system.

Requirements

  • 5+ years of IT experience with at least 5+ years ISSO experience.
  • Must have working knowledge of DOD Risk Management Framework (RMF)
  • Must meet DOD 8750 requirements and be eligible for IAM level II
  • Must obtain ITIL V4 Foundation within six months of hire.
  • Must possess and maintain a Top Secret/SCI Security Clearance.
  • BA/BS or the equivalent combination of education, technical training, or work/military experience.
  • Ability to work in a team-oriented, collaborative environment.
  • Ability to work efficiently in a fast-paced environment and multi-task while still ensuring high quality of work.
  • Highly organized with strong ability to prioritize work and work autonomously.
  • Excellent verbal and written communication skills
  • Great attention to detail and presentation
  • Results driven, highly efficient, energetic, and highly motivated.
  • Must possess a high degree of intelligence, competence, maturity, adaptability, resilience, integrity, and initiative.

Responsibilities

  • Performs Cybersecurity activities for a large Program
  • Coordinates with government Program staff, USAF, and other government agencies to assist in the creation, dissemination, direction, and auditing of program policy, standards, and operating procedures.
  • Support the government ISSMs in the development and staffing of documentation related to the Authorization to Operate (ATO), Authorization to Connect (ATC), Interim Authorization to Test (IATT), Plans of Action & Milestones (POA&Ms), etc.
  • Assist in the development and execution of any required Security Test and Evaluation (ST&E) plans.
  • Produce and provide A&A materials (to include engineering project briefs and outstanding RMF actions? for DoD IT packages by phase, including expiring authorizations and the resolution of issues impacting those packages).
  • Provide USG with a review of architecture documentation, security impact analysis, and risk mitigation/acceptance to support RMF for DoD IT authorization.
  • Provide security design management control of build processes for servers, services, and end points.
  • Comply with hosting facility ATOs where the MPCO IS are dependent on them.
  • Ensure good cybersecurity and vulnerability management practices are developed, implemented, and enforced.
  • Conduct network and system audits for vulnerabilities using Security Technical Implementation Guides (STIGs), DISA SCAP, ACAS vulnerability scanner, ESS Policy Auditor to mitigate those findings for Linux, Windows, Cisco, Juniper, VMWare and other associated operating systems and technologies.
  • Implement the Continuous Monitoring program by creating, tracking, reviewing, and closing Plan of Action and Milestones (POA&Ms) and Risk Acceptances and assist in conducting solution identification to assist in problem remediation and resolution.
  • Communicate tactical and strategic threat information to Government leaders, Cybersecurity-Ops and A&A Staff to assist them in making cyber risk decisions and to mitigate threats.
  • Carries out DoD Risk Management Framework (RMF) in accordance with DoD 8510 to ascertain information systems' security posture by utilizing security control validation activities and coordinating security testing.
  • Coordinates with AFRL, and USAF, and other organizations in support of audits and inspections and provides all necessary documentation as required for SAVs, ST&Es, and CCRI
  • Evaluate change requests (firewall, systems, networks) and assess organizational risk.
  • Ensures the integrity and protection of networks, systems, and applications by technical enforcement of organizational security policies, through monitoring of vulnerability scanning devices.
  • Provides guidance and work leadership to less-experienced technical staff members.
  • Maintains current knowledge of relevant technology as assigned.
  • Process tickets in support of the program using the accepted ITSM system.

Benefits

  • Our benefits package for all US-based employees includes a variety of medical plan options, some with Health Savings Accounts, dental plan options, a vision plan, and a 401(k) plan offering the ability to contribute both pre and post-tax dollars up to the IRS annual limits and receive a company match.
  • To encourage work/life balance, GDIT offers employees full flex work weeks where possible and a variety of paid time off plans, including vacation, sick and personal time, holidays, paid parental, military, bereavement and jury duty leave.
  • To ensure our employees are able to protect their income, other offerings such as short and long-term disability benefits, life, accidental death and dismemberment, personal accident, critical illness and business travel and accident insurance are provided or available.
  • We regularly review our Total Rewards package to ensure our offerings are competitive and reflect what our employees have told us they value most.

Stand Out From the Crowd

Upload your resume and get instant feedback on how well it matches this job.

Upload and Match Resume

What This Job Offers

Job Type

Full-time

Career Level

Mid Level

Number of Employees

5,001-10,000 employees

© 2024 Teal Labs, Inc
Privacy PolicyTerms of Service