Search jobs > Washington, DC > Information system security

Information Systems Security Officers

ARK solutions
Washington, DC
Full-time

Position : Information Systems Security Officers

Location : Washington, DC

Duration : 36 Months and possibility of extension

Description :

Day-to-day Responsibilities :

  • Serve as the principal advisor to the information system owner (SO), ISSM, CISO on all matters (technical and otherwise) involving the security of assigned information systems.
  • Maintain detailed knowledge and expertise required to manage the security aspects of assigned information systems.
  • Ensure that the appropriate operational cybersecurity posture is maintained for assigned CAO systems to provide confidentiality, integrity, and availability of information systems.

For each system assigned to an ISSO, the ISSO will be responsible to complete and keep updated the following security documentation :

  • Security Impact Analysis
  • Information Sensitivity Security Assessment
  • System Security Plan (SSP)
  • Plan of Action and Milestones (POA&M)
  • Information Technology Risk Acceptances
  • Configuration Management Plan
  • Supply Chain Risk Management Plan
  • Interconnection Security Agreements
  • Memorandums of Understanding
  • Information Data Exchange Agreements
  • Vulnerability Reports
  • Authorization Letters
  • Develop, update, and maintain the SSP for assigned systems.
  • Participate in planning and management of all phases of the House Risk Management Framework (RMF) Security Assessment and Authorization (SAA) process.
  • Advise system owners on all matters, technical and otherwise, involving the security of assigned IT systems.
  • In coordination with SO team, develop standard operating procedures in accordance with security control requirements.
  • Perform continuous monitoring of implemented security controls to ensure that they are implemented correctly, operating as intended and producing the desired outcome with respect to meeting the cybersecurity requirements for assigned IT systems.

Conduct continuous monitoring activities, to include : Maintenance of current ATO

o Ensuring proper sanitization of media prior to disposal

o Conducting log reviews

o Conducting periodic scans

o Conducting periodic system self-assessments

  • Work with technical teams to mitigate security control deficiencies and scan vulnerabilities for assigned IT systems.
  • Assess the cybersecurity impact of changes to assigned IT systems and document findings in a security impact analysis (SIA) report.
  • Conduct self-assessments of security controls, identify weaknesses and track remediation activities in POA&M.
  • Manage the plan of action and milestone (POA&M) process for designated IT systems to provide timely detection, identification and alerting of non-compliance issues.

In coordination with System Owner staff, create POA&Ms or remediation plans for vulnerabilities identified during risk assessments, audits, inspections, etc.

  • Provide the required system access, information, and documentation to security assessment and audit teams.
  • Participate in security assessments and audits for assigned systems and facilitate evidence and / or data collection for data requests related to assigned systems.
  • Complete required A&A activities on assigned IT systems.
  • Brief senior management and ISSM on the security status of assigned authorization boundaries.
  • Perform other duties as assigned.

Required Skills :

  • Five (5) or more years of demonstrated experience performing systems security assessments, preparing system security documentation, and / or performing security upgrades for live networks, desktop systems, servers, and enterprise data bases leading to successful security authorization of such systems.
  • Strong working knowledge and familiarity with NIST publications and privacy frameworks.
  • Demonstrated understanding of cloud service models, hybrid models, financial applications, and mobile security technologies and tools.
  • Demonstrated experience supporting an industry risk management tool executing A&A activities.
  • Bachelor’s degree in computer science, information technology, cybersecurity, or a related technical discipline required.
  • Current and maintained certification in one or more of the following IT Security disciplines : Certified in Risk and Information Systems Control (CRISC), Certified Information Security Manager (CISM) or Certified Information Systems Security Professional (CISSP) or equivalent certification required.

Preferred Skills :

Splunk Engineer experience

Education :

  • Bachelor’s degree in computer science, information technology, cybersecurity, or a related technical discipline required
  • 30+ days ago
Related jobs
00100 LEIDOS, INC.
Washington, District of Columbia

The Health and Civil Sector are actively seeking Information Systems Security Officers (ISSO) with a minimum of ten (10) years’ experience. Ensuring information system security requirement are addressed during all phases of information systems lifecycle. Develops, reviews, evaluates, and verifies se...

Palantir Technologies
Washington, District of Columbia

As the Information Systems Security Manager (ISSM), you will own the systems that enable Palantirians to productively use our USG facilities and related enclaves in support of our critical DoD missions. Serve as the principal advisor on all matters, technical and otherwise, involving the security of...

Next Step Systems – Recruiters for Information Technology Jobs Top IT Recruiting Firm
Washington, District of Columbia

Keywords: Washington DC Jobs, Systems Engineer, Systems Engineering, Atlassian Suite, Jira, Confluence, AngularJS, Postgres, Ansible, Docker, JavaScript, Linux, GitLab, Agile, Security Clearance, Washington DC Recruiters, IT Jobs, Washington DC Recruiting. Systems Engineer, TS/SCI with Full Scope Po...

ST2 ManTech Advanced Systems Intl
Washington, District of Columbia

Hold at least one of the following certifications: Certified Information Systems Security Professional (CISSP), Global Information Security Professional (GISP), or the CompTIA Advanced Security Practitioner (CASP) or Information Assurance Management (IAM) Level II proficiency. Hold at least one of t...

00100 LEIDOS, INC.
Washington, District of Columbia

The Health and Civil Sector is actively seeking Information Systems Security Engineers (ISSE) with a minimum of five (5) years’ experience. Document the various security control implementations as well as gather the artifacts that support the Risk Management Framework (RMF) and ICD 503 Security Accr...

ST2 ManTech Advanced Systems Intl
Washington, District of Columbia

Information Systems Security Engineer. The Information Systems Security Engineer (ISSE) performs activities associated with the maintenance and updates of software in response to IAVAs, patches, and version updates IAW program requirements and associated vendor licenses. They recommend system-level ...

Next Step Systems – Recruiters for Information Technology Jobs Top IT Recruiting Firm
Washington, District of Columbia

Web Developer, TS/SCI with Full Scope Poly Security Clearance Required, Washington, DC. JavaScript, CSS, Express, Gitlab, Programmer, Programmer Analyst, Software Engineer, Software Developer, Security Clearance, Washington DC Recruiters, IT Jobs, Washington DC Recruiting. Home»Web Developer, TS/SCI...

RIVIDIUM
Washington, District of Columbia

Ability to integrate information security requirements into the acquisition process; using applicable baseline security controls as one of the sources for security requirements; ensuring a robust software quality control process; and establishing multiple sources (e. Prefer an accredited Computer Sc...

ST2 ManTech Advanced Systems Intl
Washington, District of Columbia

Hold at least one of the following certifications: Certified Information Systems Security Professional (CISSP), Global Information Security Professional (GISP), or the CompTIA Advanced Security Practitioner (CASP) or other certifications exemplifying skill sets such as those described in DoD Instruc...

OneZero Solutions
Washington, District of Columbia

OneZero Solutions is on contract to provide division-wide support for Federal Information Security Modernization Act (FISMA) compliance, execution of the Risk Management Framework (RMF) process to achieve and maintain Authority to Operate (ATO) security authorizations, and deliver cyber security com...