Job Description
Job Description
Overview :
East Tennessee R&D facility is currently seeking qualified applicants to serve as Junior Information Systems Security Officer (ISSO). The successful candidate should have a basic understanding of all aspects of cybersecurity. The candidate will collaborate with other teams across the lab, to include Information Technology, Physical Security, Classification Office, Cybersecurity, Lab Enterprise Risk, Lab Internal Audit, and others as appropriate.
Primary Responsibilities :
- Provide assistance to the Information Systems Security Manager (ISSM) and Chief Information Security Officer (CISO) in the certification and accreditation (C&A) of systems / networks and implementation of cybersecurity requirements and procedures across the federal facility.
- Ensure systems are operated, maintained, and disposed of in accordance with DOE security policies and procedures and as outlined in applicable System Security Plans (SSPs).
- Establish and perform documented procedures for authorizing users to information systems
- Develop and maintain SSPs for system C&A.
- Identify, review, and provide analysis and recommendations to meet requirements of applicable laws, regulations, orders, and the contract, translate into policies, procedures, suggested control structures, analysis / white papers, aligning with business objectives
- Provide guidance on policies and controls to support appropriate levels of risk, facilitate risk tolerance discussions and decisions, and recommend controls based on industry standards and practices
- Participate in internal / external compliance audits, reviews, self-assessments, assessments, and data calls
- Identify, promote, and implement process improvements
Qualifications Required :
Experience in security control assessments, Master Plans, and Cybersecurity program plansStrong analytical and organizational skills as well as problem solving capabilities to understand Cybersecurity risk and exposure (legal, regulatory violations, etc.)Demonstrated experience implementing compliance frameworks (NIST, etc)Facilitation and project management knowledge, skills and abilities; lead program implementationsDemonstrated excellent interpersonal, verbal, written and presentation communication skills and demonstrated ability to interact with all levels of internal and external stakeholdersStrong customer service, networking, and teamwork skills with all levels of internal and external personnel, demonstrated ability to work with all levels of an organizationAbility to work independently and meet deadlinesHigh ethical standards and operates with integrity and professionalismMust be able to obtain and maintain a DOE Q security clearancePreferred Qualifications :
Bachelor’s degree in IT, Cybersecurity, Information Assurance, or related field and at least 5 years of experience in cybersecurity policy, risk management, governance, and compliance through a combination of education and experience may be considered for exceptional candidates.Minimum five years’ experience working in an information security, information technology or information risk management related fieldCybersecurity certifications (CISA, CISM, CRISC, CISSP, CCSP, SSCP)Incident Response CertificationPrivacy management, cybersecurity, evaluating security controls, identifying control gaps, and mitigating measures along with a strong understanding of business practices and technology conceptsThorough understanding of industry standards and regulations including PCI, HIPAA, Privacy Act, NIST 800-53, NIST Risk Management Framework, FAIRWorking knowledge of privacy regulations and impactsHighly motivated individual with an enthusiasm for governance, risk and compliance who can communicate benefits and drive successExperience gaining an Authority to Operate (ATO) for a government systemProven track record of prioritizing tasking and meeting established deadlinesActive DOE Q or TS clearanceSpecial Requirement :
This position requires the ability to obtain and maintain a clearance from the Department of Energy. As such, this position is a Workplace Substance Abuse (WSAP) testing designated position. WSAP positions require passing a pre-placement drug test and participation in an ongoing random drug testing program.