Information Systems Security Officer
Core
Ensure operational security posture for classified information systems through accreditation, maintenance, auditing, and compliance with security plans and policies.
Role type
Senior IC Information Systems Security Officer (ISSO)
Builds
Classified networks and systems compliant with RMF/ATO and DoD cyber security requirements
Domain
Defense contracting / Information Assurance
Deliverable
production ML models | product features | dashboards & analysis | research | client delivery | infrastructure | physical/clinical work -> infrastructure (security controls, documentation, audits)
Required skills
Risk Management Framework (RMF), Authorization to Operate (ATO), System Security Plans (SSP), Risk Assessment Reports (RAR), Standard Operating Procedures (SOP), Plan of Actions and Milestones (POA&Ms), vulnerability scanning, SIEM, Data Loss Prevention (DLP), hardening tools, Nessus, SCAP Compliance Checker, USB Device Control, STIGs, Windows GPOs, PowerShell scripting, data transfer procedures, device classification risk assessment
Preferred skills
COMSEC experience, Bachelor's degree in IT/CIS, 5+ years Information Assurance experience
Technologies
Nessus, SCAP Compliance Checker, USB Device Control, Windows GPOs, PowerShell
Responsibilities
Prepare and maintain RMF documentation (ATO packages, SSPs, RARs, SOPs, POA&Ms); Perform regular auditing and continuous monitoring of bootable IS; Maintain complete inventory of IS software and hardware; Coordinate with ISSM, SCA, and AO for configuration management changes; Identify and assess device classification risks; Schedule and maintain records of auditing, patching, and scanning; Work with System Administrators to configure IT components per DISA STIGs; Ensure proper operation, maintenance, and disposal of IS.
Seniority
Senior, hands-on IC