Information Systems Security Officer (ISSO)
$150,000–$200,000 year
On-siteChantilly, Virginia, United States
Job Summary
Maintain an efficient operational security posture by interfacing with government customers and accrediting authorities to support authorization and accreditation activities. Prepare and review Risk Management Framework documentation, including System Security Plans, Authorization to Operate packages, and Risk Assessment Reports. Conduct periodic reviews of information system policies, coordinate security assessments and tests, and manage due diligence for hardware and software requests. Ensure proper incident response measures when vulnerabilities are discovered and provide configuration management for security software, hardware, and firmware.
Required Qualifications
- Familiarity with conducting research and analysis
- Thorough understanding and application of network security principles, practice, and implementations
- Familiarity with controlling, labeling, virus scanning, and appropriately transferring data (uploading/downloading) between information systems at varying classification levels
- Excellent communication, interpersonal, and collaboration skills to build rapport with the military personnel, civilians, and other contractors at all levels
- Thorough working knowledge of all applicable, IC, DoD policies, procedures and operating instructions related to Information Technology, Information Assurance, Information Management (IT/IA/IM)
- Working knowledge of cross-functional integration of information systems into a physical security environment
- Working knowledge of system functions, security policies, technical security safeguards, and operational security measures
- Understanding of system methodologies including but not limited to client server, web hosting, web content servers, policy servers, directory servers, firewalls, WAN, LAN, switches, and routers
- Expert in detecting and preventing computer security compromises in a networked environment
- Expertise with configuration management, system maintenance, and integration testing
- Expert in the use of tools used to prevent and/or negate malicious code
- Understanding of Commercial Off-The-Shelf (COTS) tools that scan at the physical layer of all removable and fixed media types including but not limited to: (CDs, hard drives, thumb drives, Zip/Jazz, etc.)
- Expertise in forensics chain of custody and evidentiary preservation
- Ability to troubleshoot technical configurations and make recommendations on the protection of classified and sensitive data
- Demonstrated ability to translate technical information and information technology jargon into plain English
- Ability to apply a risk management philosophy when faced with security challenges and the ability to articulate the pros and cons in a clear concise manner
- Demonstrated proficiency with the following computer operating systems (e.g. Microsoft Windows, LINUX, UNIX, Mac OS, etc.)
- Analytical ability to decipher complex technical configuration management documents
- Proficient in maintaining databases
- Strong ability to elicit, articulate, and document information in a well-organized manner
- Demonstrated experience with Microsoft Office Suite
- Demonstrated ability to correlate audit results between various systems and/or users and notify the Information Systems Security Manager (ISSM) of any discrepancies
- Demonstrated proficiency in successfully guiding complex information systems through assessment and authorization control gates
- Expert ability to establish and maintain effective internal and external working relationships with government and contractor program manager, security professionals, and mission partners
- Associate's degree and 8+ years of relevant experience, or Bachelor's degree and 6+ years of relevant experience, or Master's degree and 4+ years of relevant experience
- An active CASP+, CISA, CISSP, GCED, or GCIH or must be willing to obtain / maintain within 6 months of hire
- U.S. Citizenship
- Active Top Secret/Sensitive Compartmented Information (TS/SCI) clearance
- Active Counterintelligence (CI) or Full Scope (FS) Polygraph
Desired Qualifications
- Ability to decipher and explain in clear language Intelligence Community Directive (ICD) 503
- Demonstrated ability to work independent of close supervision
- Ability to effectively provide ISSO guidance to Level 1 and Level 2 ISSOs
Hiring someone like this?
Get your role in front of qualified candidates on Sorce.