Information Systems Security Officer (Special Programs)
Manage security programs to meet ARL : UT's Risk Management Framework requirements for National Security computing environments as defined by the National Institute of Standards and Technology 800-Series, Committee on National Security Systems Instructions, Intelligence Community Directives, and Joint Special Access Programs Implementation Guide (JSIG).
Responsibilities include :
- Risk Management Framework (RMF) Body of Evidence (BoE) development and maintenance : Advise the information system owner regarding security considerations in the information system development life cycle. Develop and maintain documentation for Assessment and Authorization (A&A) in accordance with applicable policies, procedures, and operating instructions to include System Security Plans (SSP), Security Controls Traceability Matrix (SCTM), and Plan of Actions and Milestones (POA&M). Participate in risk assessments to evaluate the sensitivity of the system. Participate in assessment of system safeguards and program elements.
- Information Security Auditing : Provides technical expertise and oversight to manage the daily administration of security protection measures on the information systems assigned. Conduct Information System audits using approved auditing techniques / tools.
- Information Technology (IT) Support : Provide support for IT government owned systems and system components to ensure that computer hardware and software, as well as networks and servers work consistently and correctly. Duties include diagnosing connectivity or system access issues, placing helpdesk tickets with government system administrators, and providing direct support to users across the organization.
- Information System Administration : Responsible for account administration for government owned systems that reside within ARL closed areas. Duties include account requests, account tracking, and account troubleshooting for system user accounts.
- Other related functions as assigned.
Required qualifications include :
HS / GED.Three years of information assurance experience in Windows / Linux systems.Experience developing and implementing information assurance policy.Strong communication, critical thinking, and problem-solving skills with the ability to prioritize projects.Experience supporting various system configurations. Experience with auditing various OS and networks.Experience with IT troubleshooting of system components to include workstations, printers, video teleconference (VTC) equipment, and thin clients.Relevant education and experience may be substituted as appropriate.US Citizen. Selected applicant is subject to government security investigation and must meet eligibility requirements for access to classified information at level appropriate to project requirements. Employment is contingent on selected applicant submitting application for access and receiving notification of eligibility within a time period specified in the job offer. Employment must begin within 30 days of confirmation of eligibility. Eligibility for access to classified information must continue without interruption during employment. Employment will be contingent on selected applicant obtaining a DoDM 8570.01 compliant certification, equivalent to IAT Level II within 6 months of start date. Continued compliant certification, equivalent to IAT Level II is required during employment.
Preferred qualifications include :
Bachelor's Degree : Computer Science, Information Systems Management, or related field.Eligibility for immediate access to classified information at the level appropriate to the project requirements of the position.Six years of experience in information assurance in a National Security computing environment.Three years' experience with the Risk Management Framework methodology.Knowledge of Special Access and Sensitive Compartmented Information programs and government regulations.Experience with policy creation and documentation preparation and maintenance.Windows Operating System and Linux Operating System certifications. Experience conducting security audits of information systems. SIEM Tool experience (ArcSight, Splunk, Wireshark, etc.).Salary range : $67,128 - $88,914+ / negotiable depending on qualifications.
Working conditions include :
Standard office conditions.Repetitive use of a keyboard at a workstation.Use of manual dexterity.Some weekend, evening and holiday work.Possible interstate / intrastate travel.Required materials include :
Resume / CV.3 work references with their contact information; at least one reference should be from a supervisor.Letter of interest.