Scientific Research Corporation-posted 9 days ago
$87,000 - $144,900/Yr
Full-time • Mid Level
Onsite • Peterson AFB, CO
1,001-5,000 employees

SRC is seeking an Information Systems Security Officer (ISSO) with RMF experience who has deep expertise in security assessment documentation to support USSPACECOM systems and efforts to achieve their Authorization to Operate (ATO). This position is located at the client site at the Bayfield building in Colorado Springs, CO. The scope of this position includes full life-cycle Assessment and Authorization (A&A) management through all 6 Steps of the RMF process in support of the Command-ISSM. In this role, you’ll conduct security assessment, and information system security oversight activities in accordance with NIST 800.53 R5 that support systems from the perspective RMF requirements. SRC brings motivated, highly skilled, and creative people together to solve the government’s most dynamic problems with cutting-edge technology. To carry out our mission, we are seeking candidates who are excited to contribute to government innovation, appreciate collaboration, and can anticipate the needs of others. Here at SRC, we offer an environment in which our employees feel supported, and we encourage professional growth through various learning opportunities.

  • Reviewing systems to identify potential security weaknesses and recommending improvements to amend vulnerabilities, implement changes, and document upgrades
  • Maintaining responsibility for managing cybersecurity risk from an organizational perspective
  • Identifying organizational risks, prioritizing those risks, and maintaining a risk registry for escalating and presenting those risks to senior leadership
  • Providing security guidance and IS validation using the National Institute of Standards and Technology (NIST) RMF, and local security policies
  • Providing configuration management (CM) recommendations for information system security software, hardware, and firmware and coordinating changes and modifications with the ISSM, Security Control Assessor (SCA), and Authorizing Official (AO)
  • Maintaining vulnerability scanning tool compliance, such as Trellix (HBSS) or ACAS (Nessus), and patch management, such as IAVM to ensure IT staff pushes patches to all systems in an effort to maintain compliance with all applicable directives, manage system changes, and assess the security impact of those changes
  • Providing subject matter expertise for cybersecurity and trusted system technology
  • Applying advanced technical knowledge and analysis of specialized functional areas in task requirements to develop solutions to complex problems
  • Research, write, review, disposition feedback, and finalize recommendations regarding cybersecurity policy, assessment and authorization assessments (A&As), security test and evaluation reports, and security engineering practices and processes
  • Conduct research and write risk assessment reports to include risk thresholds, evaluation, and scoring
  • Supporting analysis of the findings and provide expert technical guidance for mitigation strategies, including implementation advice on the cybersecurity risk findings, and other complex problems
  • Bachelor’s degree
  • A minimum of five (5) years experience as an Information Assurance (IA) Analyst, ISSE, ISSO, or similar role in ATO package development, including generating security documentation for requirements, security control assessment, STIG and IAVA compliance, Standard Operating Procedures, test results, etc.
  • eMASS experience
  • Professional security certification such as: CCNA, CySA+, GICSP, GSEC, CompTIA Security+ CE, SSCP, or higher
  • Strong desktop publishing skills using Microsoft Word, Excel, Visio, and Adobe
  • Experience with industry writing styles such as grammar, sentence form, and structure
  • Ability to multi-task in a deadline-oriented environment
  • SRC IS A CONTRACTOR FOR THE U.S. GOVERNMENT. THIS POSITION WILL REQUIRE U.S. CITIZENSHIP AS WELL AS A U.S. GOVERNMENT SECURITY CLEARANCE AT THE TOP SECRET / SCI LEVEL
  • CISSP, CASP, or a similar certificate is preferred
  • Master's degree in cybersecurity or related field
  • Strong initiative, detail orientation, organizational skills, and aptitude for analytical thinking
  • Demonstrated ability to work well independently and as a part of a team
  • Excellent work ethic and a high commitment to quality
  • SRC offers a generous benefit package, including medical, dental, and vision plans, 401(k) with a company match, life insurance, vacation and sick paid time off accruals starting at 10 days of vacation and 5 days of sick leave annually, 11 paid holidays, tuition reimbursement, and a work environment that encourages excellence and more.
© 2024 Teal Labs, Inc
Privacy PolicyTerms of Service