PRINCIPAL INFORMATION SYSTEM SECURITY OFFICER (ISSO)

Tau Six, LLC
Lakewood, WA, United States
Full-time

Principal Information System Security Officer (ISSO)

  • Washington, DC
  • Full-Time
  • Principal Information System Security Officer (ISSO)

Tau Six, an agile small company delivering cutting edge cybersecurity and systems integration services to the US National Security market, has an immediate need for a Principal Information Systems Security Officer (ISSO) for a Department of Defense customer.

In this role you have the opportunity to work with a cross-functional team in multiple technical areas to include operations, engineering, security, and systems development to deliver secure solutions to our national security customers.

We are seeking a motivated, career and customer-oriented experienced senior Information Systems Security Officer (ISSO) to join our team in the Washington, DC area.

The selected candidate will ensure that the appropriate operational security posture is maintained for assigned information systems and as such, works in close collaboration with the Information System Security Manager (ISSM), the Chief Information Security Officer (CISO) staff, and the Information System Owner (ISO).

You will ensure that cyber security requirements are effectively integrated into information systems' operations, management, and documentation.

As a Principal Information System Security Officer, you will provide critical systems, application and infrastructure support to our Department of Defense customer.

You have the opportunity to work with a team across multiple technical areas to include operations, engineering, security, and systems development.

This is a great opportunity for technical and professional growth.

CLEARANCE REQUIRED : Active Top Secret US Government clearance

All Tau Six employees will need to meet the requirements set forth in Executive Order 14042 and the Safer Federal Workforce Task Force Guidance requiring all covered contractor personnel to be fully vaccinated against COVID-19.

Responsibilities :

  • Responsible for elements of physical and environmental protection, personnel security, incident handling, and security training and awarenessEnsure systems are operated, maintained, and disposed of in accordance with security policies and procedures
  • Ensure all users have the requisite security clearance, authorization, need-to-know, and are aware of their security responsibilities before being granted access to the system, and periodically thereafter
  • Create and maintain existing information system security documentation, including SSP, SCTM, and Security Configuration Guide
  • Write implementation and design documents describing how security features are implemented
  • Prepare system documentation for assessment in accordance with the Risk Management Framework (RMF) and NIST Special Publications (800-37, 800-53 and others);

identify deficiencies and provide recommendations for solutions; track findings with Plan of Action and Milestones (POA&M) through mitigation and / or risk acceptance

  • Create security policies and maintain existing information system security documentation
  • Conduct periodic and continuous reviews of the system to ensure compliance with the authorization package
  • Work with the IA team to perform basic system administration and maintain various IA tools, including audit collection and reporting systems, vulnerability management programs, and other continuous monitoring capabilities
  • Participate in the change management process, including reviewing Change Requests and assisting in the assessment of security impact of proposed changes
  • Conduct daily, weekly and monthly audit review and management of the audit collection system
  • Continuously review and evaluate best practices for implementing a comprehensive audit program
  • Implement vulnerability management programs, including tracking and addressing IAVAs and security patches, accessing applicability to existing systems, and ensuring closure
  • Implement media control and data transfer policies
  • Provide direction and guidance to less experienced IA personnel
  • Remain sensitive to security infractions and assist in security investigations and responses as requested
  • Work on project teams responsible for engineering and packaging releases to integrate within the customer's production IT environment
  • Monitor system recovery processes to ensure security features and functions are properly restored and functioning correctly following an outage
  • Work in close coordination with the ISSM, you will play an active role in monitoring assigned systems and their environment of operation to include developing and maintaining the System Security Plan (SSP) and Security Controls Traceability Matrix (SCTM), managing and controlling changes to the system, and assessing the security impact of those changes.

Positions Requirements :

Associate's degree (preferably in telecommunications, computer science, information systems management, electrical engineering, computer engineering or similar field of study) and nine years experience with information networks and related security concerns;

or a Bachelor's degree with 7+ years experience

Strong background and extensive experience with RMF, ICD 503, JSIG, NIST SP800-53 or DCID 6 / 3; knowledge of current authorization practices, particularly within the DoD.

Extensive background with DITSCAP / DIACAP may be substituted in some cases.

Some experience with security efforts related to modern Windows, Linux, UNIX, Cisco, SQL or Oracle databases, and virtual computing.

This might also include some system administration work with an emphasis on security control implementation.

  • Experience implementing and using various IA tools including vulnerability assessment, patch management, audit collection, audit review, audit management, and end point protection
  • Analytical skills and be capable of quantifying risk to enterprise systems and level of compliance with security policy
  • DoD 8570.1 / DoD 8140.01 certification (IAT Level II or III, IAM level I, II or III, IASAE Level I, II, or III). Security+ or equivalent required at a minimum;

CAP, CASP, CISSP, or CISM desired

  • ITIL v3.0 or Foundation Certifications desired
  • Communicate well, both orally and in writing

Security Requirements :

US Citizenship and active TS clearance

30+ days ago
Related jobs
Promoted
ManTech International
Lakewood, Washington

Hold at least one of the following certifications: Certified Information Systems Security Professional (CISSP), Global Information Security Professional (GISP), or the CompTIA Advanced Security Practitioner (CASP) or other certifications exemplifying skill sets such as those described in DoD Instruc...

Promoted
The National Highway Traffic Safety Administration
Lakewood, Washington

Assist the Cybersecurity and IT security compliance of NHTSA IT cybersecurity program by supporting cybersecurity in the system engineering process, supporting Risk Management Framework (RMF) task(s) in accordance with NIST Special Publication 800-37, including supporting cybersecurity assessments a...

Promoted
ManTech International
Lakewood, Washington

Hold Aat least one of the following certifications: Certified Information Systems Security Professional (CISSP), Global Information Security Professional (GISP), or the CompTIA Advanced Security Practitioner (CASP) or other certifications exemplifying skill sets such as those described in DoD Instru...

Inter-Con Security Systems Inc
Tacoma, Washington

As an Unarmed Security Officer, you will be part of a highly trained security team that supports critical facilities and infrastructure, public venues that required an enhanced presence and personal protective services. In many cases our clients desire a softer security plan that meets their values ...

Promoted
ManTech International
Lakewood, Washington

Hold at least one of the following certifications: Certified Information Systems Security Professional (CISSP), Global Information Security Professional (GISP), or the CompTIA Advanced Security Practitioner (CASP) or other certifications exemplifying skill sets such as those described in DoD Instruc...

CGI
Washington, United States

Work as part of a team reviewing and assessing Risk Management Framework (RMF) authorization body of evidence for classified information systems, to include System Security Plan (SSP), Security Control Traceability Matrix (SCTM), Continuous Monitoring Plan, Incident Response Plan, Access Control Pla...

Highmark Health
WA, Working at Home, Washington

The Principal Information Security Architect - Healthcare Delivery Technology serves as the most senior security architect and advanced technology analyst for healthcare delivery systems and IOT in the company. The Open Group Architecture Framework Certification (TOGAF), Certified Information Securi...

Department of Corrections Executive Leadership
Washington

...

Bank of America
Washington

The Senior Technology Information Security Officer will be a member of the Business Information Security Officer's (BISO) organization and work closely with the line of business Front Line Units (FLU) / Operations (Ops) executives. Contribute to the ongoing information security initiatives and impro...

Inter-Con Security Systems Inc
Tacoma, Washington

As an Unarmed Security Officer, you will be part of a highly trained security team that supports critical facilities and infrastructure, public venues that required an enhanced presence and personal protective services. In many cases our clients desire a softer security plan that meets their values ...