Intermediate ISSO
On-siteArlington, Virginia, United States or Arlington, Texas, United States
Job Summary
Conduct vulnerability assessments, risk assessments, and network security evaluations to protect the confidentiality, integrity, and availability of sensitive information. Design and implement security solutions while managing Plan of Action and Milestones (POA&M), system authorizations, and configuration management. Perform product evaluations to recommend technologies that improve the customer's security posture and assist in designing business impact analyses, contingency plans, and privacy documentation. Execute testing and audit log reviews to evaluate current security measures, applying NIST Cybersecurity Framework and FISMA audit requirements. Requires BS/BA in a technology-related discipline and 3+ years of relevant experience.
Required Qualifications
- BS/BA in Computer Science, Information Systems, Engineering, Business, Physical Science, or other technology-related discipline
- 3+ years of relevant experience
- Experience with RMF and applying the NIST Cybersecurity Framework
- Substantial knowledge of federal information system security policy, industry best practices, security control assessments, Plan of Action and Milestones (POA&M) management, system authorizations, configuration management, and system analysis
- Experience designing and implementing solutions for protecting the confidentiality, integrity, and availability of sensitive information
- Experience using JCAM
- Solid understanding and application of NIST Special Publications including SP 800-53, SP 800-137, SP 800-171, and SP 800-37
- Solid understanding of FISMA audit requirements
- Solid understanding of IT audit requirements
- Ability to work with cooperatively and at a technical level with developers, engineers, and managers on system teams
- Knowledge of computer networking concepts, protocols, and network security methodologies
- Knowledge of risk management processes and tools (e.g., methods and tools for assessing and mitigating risks)
- Knowledge of laws, regulations, policies, and ethics as they relate to cybersecurity and privacy in a federal environment
- Knowledge of current and past cybersecurity threats and vulnerabilities
Hiring someone like this?
Get your role in front of qualified candidates on Sorce.