ISSO
On-siteFort Bragg, North Carolina, United States
Job Summary
Create and maintain the Authority to Operate (ATO) for assigned USARC information systems in accordance with the Risk Management Framework (RMF). Perform assessment and authorization (A&A) tasks, prepare SA&A packages, and interpret NIST and Department of War cybersecurity guidance. Engage in enterprise cybersecurity engineering, document RMF controls and vulnerabilities using eMASS and XACTA, and support DISA security change requests. Identify, collect, and report cybersecurity incidents while developing briefings on system security posture for senior management. Requires a Secret clearance, 10 years of security experience, and proficiency with tools like Tenable Nessus and STIG Viewer.
Required Qualifications
- Bachelor's degree in an information technology related field
- Master's level certification (CISSP, CISM, etc.)
- At least ten (10) years of direct experience in computer and systems security
- Experience performing assessment and authorization tasks within the federal government in accordance with the Risk Management Framework (RMF)
- Ability to meet DoD 8140 requirements
- Active Secret security clearance
Desired Qualifications
- Working knowledge of common DoW IT and cybersecurity tools, including ACAS, ESS, Trellix, DISA STIGs, Forescout, Cisco ISE, Active Directory, and MECM
- Proficiency with A&A/RMF workflow tools such as eMASS and XACTA
- Knowledge of Information Certification & Accreditation Regulations, FISMA, and NIST 800-series guidance, and the SA&A process in alignment with the RMF
- Experience with DOD 8510 (DIACAP and RMF), DoD 6510 and 8500 series instructions, IAVMs, and related Federal/DoD policies and regulations
- Familiarity with network monitoring and intrusion/malware detection using host- and network-based intrusion detection systems (IDS) and log management applications
- Familiarity with vulnerability scanning and management using Tenable Nessus and reviewing scan reports
- Strong analytical and problem-solving skills for resolving security issues and identifying trends and false positives in operational reports
- Excellent verbal and written communication skills, including competence in developing and delivering briefings to senior management
- Strong organizational and time management skills with the ability to balance multiple priorities and complete tasks on time
- Ability to work independently and as part of a team, and to maintain a professional appearance and demeanor
Hiring someone like this?
Get your role in front of qualified candidates on Sorce.