Information System Security Officer – Senior
$160,000–$160,000 year
On-siteSan Antonio, Texas, United States
Job Summary
Generate and maintain the complete security Body of Evidence (BoE) while leading Assessment and Authorization (A&A) activities according to Risk Management Framework processes for all multiple information systems. Lead development and maintenance of information security policies, standards, and control procedures to enable compliance with RMF. Complete Security Authorization packages, including System Security Plans, Security Assessment Reports, and Continuous Monitoring Plans within XACTA, and present executive briefings to senior management. Conduct thorough auditing of security information and events utilizing advanced tools like Splunk and NESSUS to detect and mitigate potential threats. Ensure security risk assessments are conducted on system upgrades and that security authorization boundaries are properly defined and captured. Maintain day-to-day security posture and continuous monitoring of all Information Systems, including review of vulnerability scans and verification of DISA STIGs implementation. Perform test/evaluation of required technical security controls and conduct periodic self-inspections to ensure systems operate as authorized and accredited.
Required Qualifications
- Active Top-Secret clearance with SCI or TS with the ability to acquire SCI
- 8 years of relevant experience
- In-depth knowledge of Microsoft Windows OS (client and server)
- Familiarity with Red Hat Enterprise Linux (RHEL)
- Experience with security configurations across multiple operating systems in various environments, to include Windows and Linux, utilizing Active Directory/Group Policy
- Experience in the development of technical documentation to include artifacts required to support Assessment and Authorization (A&A) under the Risk Management Framework
- Experience with XACTA, ACAS/NESSUS, Trellix, and Splunk
- Experience with DISA STIGs and DISA Viewer
- 2 years of knowledge and experience with NESSUS/ACAS and Trellix administration
- Ability to work a 40-hour work week, normally Monday through Friday
- Ability to work overtime during critical peaks and be available to meet last-minute requests for overtime if needed
- Ability to travel (5-10%) primarily within 75 miles
- Must possess or be able to obtain one of the following 8140 IAT Level II or III baseline certifications before start date: Level II certs include – CCNA Security, CySA+, CND, Security+ CE; Level III certs include – CASP CE, CCNP Security, CISA, CISSP (or Associate)
- Exceptional attention to detail
- Excellent verbal and written communication skills
- Strong critical thinking, organizational, time-management, and problem-solving skills
- Ability to work both independently and as part of a team in a dynamic environment
- Must be able to lift 50 lbs
Desired Qualifications
- Previous supervision and/or participation with Cybersecurity Assessments and Authorizations
- Familiarity and the ability to aid with the cybersecurity tools such as ForeScout, Ivanti, and Trellix
Hiring someone like this?
Get your role in front of qualified candidates on Sorce.