Information Systems Security Officer

York Space Systems LLC
Greenwood Village, CO, United States
$80K-$120K a year
Permanent

Salary : $80,000-$120,000 York Space Systems was founded to radically improve spacecraft affordability and reliability, transforming, and enabling next generation space mission operations worldwide.

Today, it is one of the most innovative aerospace companies, specializing in both end-to-end customer solutions and the rapid production of spacecraft platforms.

York’s complete Space Segment Solution including spacecraft production, payload integration, system integration & test, launch services, ground segment services, and mission operations enables customers to leverage York’s existing technology solutions to get rapidly and responsively to orbit.

We’re looking to expand our team across the board. York Space Systems is seeking a Senior Information Systems Security officer (ISSO) to facilitate A&A (Authorization & Assessment) efforts throughout multiple systems’ RMF lifecycle.

The selected candidate will take the lead in supporting multiple RMF accreditation efforts and will perform tasks that include determining DoD requirements, hardware / software configuration management (to include baseline configuration), risk assessments / vulnerability assessments, testing and documenting security controls, and ensuring overall compliance with DoD Cybersecurity policies.

The ideal candidate will have experience working as an ISSO or security relevant field and must be comfortable operating in a senior role and mentor for junior ISSOs.

The selected candidate will be able to speak directly with customers with little to no Information System Security Managers (ISSM) involvement and be the face of security for their selected boundaries.

Responsibilities below are inclusive ISSO duties. Responsibilities :

  • Spearhead building RMF packages within eMASS and perform continuous monitoring for the full duration of the information system lifecycle
  • Assist the ISSM in meeting their duties to support A&A activities and coordinate with system’s Security Controls Assessor (SCA) and Authorizing Official (AO)
  • Oversee day-today operations required in order to perform RMF
  • Delegate tasks and create deadlines to meet security requirements
  • Be forward facing for customer interactions which will translate into system requirements
  • Implement the Risk Management (RMF) process throughout the entire A&A lifecycle of the system(s) or multiple ATOs across different locations, supporting all efforts pre and post Authority to Operate (ATO) determination
  • Perform and review technical security assessments of the system(s) to identify points of vulnerability, non-compliance with established cybersecurity standards and regulations, and recommend mitigation strategies to maintain operational security posture for the boundary systems
  • Conduct risk analyses from vulnerability, compliance scans, penetration testing results, and / or other audit activities
  • Create and maintain Plan of Action and Milestones (POA&Ms), System Security Plans (SSPs), Security Control Traceability Matrices (SCTMs), Standard Operating Procedures (SOPs), Configuration Management Plans, Contingency Plans and Test Result / Security Impact Analyses
  • Ensure approved procedures are in place for clearing, sanitizing, and destroying various types of hardware and media
  • Conduct continuous monitoring (ConMon) activities for applicable authorization boundaries
  • Apply and maintain up to date application of Security Technical Implementation Guides (STIGs) to required components of the information systems
  • Maintain inventory and asset configuration to include change management documentation
  • Lead System level change request through formalized Configuration Control boards (CCB)
  • Ensure that the appropriate operational security posture is maintained for the information system, working in close collaboration with the information system owner and the ISSM
  • Notify ISSM when changes occur that might affect the authorization determination of the information system(s)
  • Experience in advising System Administrators to Remediate system decencies
  • Report all security-related concerns and incidents to the ISSM
  • Able to also handle security concerns in lieu of ISSM advise on security concerns IAW system procedures

Required Qualifications :

  • Bachelor’s degree or an IAM level 1 cert IE : SEC+
  • US Citizenship
  • Active Secret clearance or higher
  • 2 years’ Experience in Government digital security
  • Ability to write professional sounding documents, and compliance language
  • Ability to speak and communicate clearly

Requirements / Preferred Experience :

  • Military vets are encouraged to apply
  • Familiar with RMF package creation and maintenance artifacts to support A&A decision
  • Experience using DISA Security Technical Implementation Guides (STIGs), Security Requirements Guide (SRGs) and Security Content Automation Protocol (SCAP) to audit and securely configure network-enabled devices
  • Fundamental knowledge of DISA Enterprise Mission Assurance Support Service (eMASS)
  • Familiar with vulnerability tools and audit review tools which include audit log analysis and report generation (Nessus and Splunk experience preferred)
  • Ability to advise the ISSOs / ISSEs or relevant security personnel to remediate system deficiencies
  • Experience conducting risk analysis on products and system components through review of CVEs, plugins, CWEs
  • Experience in conducting software due diligence with COTS and GOTS solutions
  • Strong communication and documentation skills
  • Flexible and able to adapt to a rapidly changing environment
  • Positive, self-motivated individual who can complete tasks independently
  • Working knowledge of system functions, security policies, technical security safeguards, and operational security measures.

York Space Systems provides equal employment opportunities to all employees and applicants for employment and prohibits discrimination and harassment of any type without regard to race, color, religion, age, sex, national origin, disability status, genetics, military or protected veteran status, sexual orientation, gender identity or expression, or any other characteristic protected by federal, state, or local laws.

Must have permanent authorization to work in US. This policy applies to all terms and conditions of employment, including recruiting, hiring, placement, promotion, termination, layoff, recall, transfer, leaves of absence, compensation, and training.

9 days ago
Related jobs
Promoted
Parsons Company
Aurora, Colorado

Job Description:Parsons is looking for an amazingly talented Information System Security Officer to join our team! In this role you will get to maintain security operations for various specialized applications. This includes process support, analysis support, coordination support, security certifica...

Promoted
VirtualVocations
Lakewood, Colorado

A company is looking for a Journeyman Information Systems Security Specialist. ...

Promoted
NexThreat
Lakewood, Colorado

The perfect candidate will be responsible for the compliance of IT systems, applications, and networks with security policies and information protection strategies; develop, publish, and maintain Agency information security policies, standards, procedures, and guidelines. Knowledge of common informa...

Parsons Corporation
Aurora, Colorado

Familiarity with applicable IC and DoD policies, procedures and operating instructions related to Information Technology, Information Assurance, Information Management (IT/IA/IM). Develops, maintains, and implements information security standards, procedures, and guidelines for applications and data...

Lockheed Martin
Roxborough Park, Colorado

The Cybersecurity Analyst will partner with the security team, program, and government customers to perform as an Information Systems Security Officer (ISSO) in Littleton, CO. Classified Cybersecurity Analysts help secure lifesaving products and critical state-of-the-art engineering and manufacturin...

Parsons Corporation
Aurora, Colorado

Information System Security Officer. Perform assessments of systems and networks within the networking environment or enclave and identifies where those systems/networks deviate from acceptable configurations, enclave policy, or local policy. This includes process support, analysis support, coordina...

Paragon Systems
Centennial, Colorado

Protects evidence or scene of incident in the event of accidents, emergencies, or security investigations; sets up barriers and signage, and provides direction or information to others. Prepares logs or reports as required for site; writes and/or types reports and/or enters information in a computer...

DeNOVO SOLUTIONS
Aurora, Colorado

Information System Security Officer (ISSO). Yes DeNOVO Solutions, LLC is in search of a seasoned Information System Security Officer (ISSO) to enhance the efficiency of our internal operations at our headquarters in Aurora, Colorado. The ideal candidate should possess expertise in collaborating with...

Inter-Con Security Systems Inc
Edgewater, Colorado

Inter-Con is searching for aspiring individuals to join our thriving team of Security Officers. Inter-Con Security Systems, Inc. California Applicants: Pursuant to the California Consumer Privacy Act, please review the Privacy Notice for California Residents found in Section 10 of our which explains...

Parsons Corporation
Denver, Colorado

Information System Security Officers. Certified Information Systems Security Professional (CISSP) certification. Bachelor’s Degree or higher and 3 years of relevant information assurance / cybersecurity experience. Perform assessments of systems and networks within the networking environment or encl...