Unfortunately, this job posting is expired. Please click here to view related job postings.
Company

Solutions By Design IISee more

addressAddressWashington, DC
type Form of workFull-Time
CategoryInformation Technology

Job description

Job Description

SBD is looking for a Cross Functional Information System Security Officer (ISSO) to join us in support of our federal client located in Camp Springs, MD. This position is hybrid, requiring onsite work in Camp Springs, MD two (2) days per week.

The ISSO supports all Risk Management Framework (RMF) activities including the process managing security and privacy risk, including information system categorization; control selection, implementation, and assessment; system and common control authorizations; and continuous monitoring. This person also supports the security activities associated with evaluating, implementing, managing security practices and continued operations of new and existing technologies across the Enterprise. This person will provide oversight into all responsibilities as required and will support both but Unclassified (SBU) and For Official Use Only (FOUO) systems. The ISSO shall perform all duties and responsibilities in accordance with DHS 4300A, DHS ISSO Guide, and other applicable guidance.

Responsibilities Include:

  • Risk Management Framework (RMF) Activities:
    • Support all activities as outlined in the NIST SP 800-37, Risk Management Framework for Information Systems and Organizations. This includes the process for managing security and privacy risk that includes information security categorization; control selection, implementation, and assessment; system and common control authorizations; and continuous monitoring.
  • Security Authorization Documentation:
    • Initial development and, at least, annual reviews/updates of the FIPS 199, e-Authentication, Privacy Threshold Analysis (PTA)/Privacy Impact Analysis (PIA), Security Plan (SP), Contingency Plan (CP), and Contingency Plan Test (CPT), Interconnection Security Agreement (ISAs) and Memorandum of Agreement/Understanding (MOA/Us) and any other FISMA related security documentation.
  • Security Control Assessment Response:
    • Support all assessment activities by responding to interview questions as well as working with the system teams to gather appropriate evidence as directed by the SCA team.
  • Change Management:
    • Review all change requests for potential impact to the system security posture.
  • Continuous Monitoring:
    • Conduct audit log and account management reviews and update the Control Allocation Table and Trigger Accountability Log.
  • Configuration/Patch/Vulnerability Management:
    • Review scan results for the system assets, identify the respective remediation's for misconfigurations and weaknesses, and work with the system team to ensure timely implementation of fix.
  • Incident Response:
    • Work with the Security Operations Center (SOC) and system teams to investigate and analyze any incidents affecting assigned system(s).
  • Apply comprehensive knowledge across key tasks and high impact assignments.
  • Evaluate performance results and recommend major changes affecting short-term project growth and success.
  • Function as a technical expert across multiple project assignments.
  • Work on high priority ad-hoc request such as data calls, Senior Management Initiatives (CIO, CISO, etc.), customer mandates, etc.
  • Prepare documentation and materials to support the operations of FedRAMP compliance requirements throughout the organization.
  • Develop briefings and presentations for Government PM and Executive Management.
  • Support all Security Authorization Processes, Security Control Assessments and Ongoing Authorization activities as required and as directed by the Federal Government.
  • Ensure systems are properly patched and hardened according to DHS requirements.
  • Assist with issues and concerns related to their assigned systems.
  • Conduct research and analysis on abnormalities and provide recommendations.
  • Conduct Risk Analysis on vendors, cloud service providers, etc. as necessary to identify flaws, threats, and risks in emerging IT projects, and develop technical in-depth engineering solutions to address and mitigate these risks.
  • Provide technical security solutions and control implementation recommendations to the Agile Development teams based on industry best practice and Federal requirements.
  • Provide, prepare, and conduct security training, as needed.
  • Apply and analyze privacy laws, administrative laws, regulations and policies surrounding the Privacy Act of 1974, the E-Government Act of 2002, or the Homeland Security Act of 2002.
  • Serve as a subject matter expert on controls standards such as NIST 800-53, 800-37, 800-66, and 800-171 as well as other privacy regulations.
  • Work on the automation, monitoring and auditing of privacy controls for each system.
  • Support security and privacy requirements for internal and external system connections.
  • Support proposed collection, sharing, and maintenance of PII through privacy compliance documentation.
  • Perform comprehensive document reviews (DR) on all risk management and security operations documentation, in alignment with our client's and FISMA requirements.
  • Conduct quality assurance checks to ensure that the finished documentation meets our client's and FISMA requirements.
  • Implement a two (2) day turn around for the following artifacts: FIPS 199, E-Authentication Workbook, PTA, PIA, CP, CPT and a five (5) day turn around for the review of the Security Plan (SP).
  • Revise, edit, or update security authorization documentation and presentations.
  • Create, adapt, and follow project schedules and deadlines.
  • Develop a thorough understanding of the audience and the documentation required by meeting with colleagues and working with managers to discuss technical problems.
  • Research and build knowledge about products, services, technology, or concepts.
  • Determine the clearest and most logical way to present information and instructions for greatest reader comprehension and write and edit technical information accordingly.
  • Prepare or commission graphics and illustrations to elaborate on or complement technical writing.
  • Meet with SMEs in order to ensure that specialized topics are appropriately addressed and discussed.
  • Perform other duties as assigned by the Government.

Required Experience and Qualifications:

  • Bachelor's degree.
  • 3+ years of specialized experience in one of the following positions: Information Systems Security Officer, Information Systems Security Engineer, Information Systems Security Auditor, or Information Systems Security Manager.
  • 3+ years of experience with analyzing, assessing, and implementing corrective actions based on vulnerability management tools.
  • 3+ years of experience with leading projects, technical writing, administrative tasks, and conducting briefings.
  • Must reside within a commutable distance to our client's location in Camp Springs, MD in order to work onsite 2 days/week.
  • Must have and maintain at least one (1) active certification such as CASP, GSEC, GSLC, CISSP, CEH, CISM, CISA, or other comparable certification which must be approved in advance by our customer.
    • Proof of certification is required.
  • Must be a US Citizen able to obtain an agency-specific suitability clearance prior to starting.
  • Deep understanding of Security Regulations, such as the NIST Publications and OMB Security related documents
  • Ability to adapt to an agile environment and provide quality, professional deliverables in a short timeframe with little to no guidance from the Government.
  • Advanced Microsoft Excel and Access skills to perform extensive data mining, correlation, and reporting.
  • Experience working with NIST SP 800-53, RMF, FISMA, DHS and Department of Defense (DoD) policies.
  • Excellent oral and written communication skills; technical and business focused, with the ability to document and describe security process information collected.
  • Must be able to pass a comprehensive background check.
  • Must be fully vaccinated for COVID-19, unless a medical exemption or religious accommodation is approved. Individuals are considered fully vaccinated two weeks after their last dose of their vaccine. Confirmation of vaccine is required.


Job Posted by ApplicantPro
Refer code: 2765524. Solutions By Design II - The previous day - 2023-02-25 12:30

Solutions By Design II

Washington, DC
Popular Information System Security Officer jobs in top cities
Jobs feed

Rates and Budget Manager 3

Northrop Grumman

Maryland, United States

$142,600 - $213,800 a year

Assistant, Office Services

Baker Tilly Us, Llp

Charleston, WV

Deputy Program Manager

Leidos

Reston, VA

$108,550 - $196,225 a year

General Sales Manager

National Indoor Rv Centers

Lebanon, TN

$200,000 - $300,000 a year

Mailroom Clerk- WV

Gainwell Technologies

Charleston, WV

Account Manager - Costa Rica

Sendoso

West Virginia, United States

MANAGER FOR COUNTER PARTS DEPT.

Engine Service & Supply Co

Odessa, TX

$55,000 - $60,000 a year

Mail Room Attendant

Peakmade

Los Angeles, CA

Share jobs with friends

Senior Cloud Information Systems Security Officer

Mantech

Washington, DC

6 days ago - seen

Information Systems Security Officer (ISSO) - Level II

C3El

Washington, DC

4 weeks ago - seen

Information System Security and Privacy Officer

Synapse Business Systems

$50 - $60 an hour

Washington, DC

4 weeks ago - seen

Sr Cloud Information System Security Officer (ISSO) w/TS Clearance

Arcetyp Llc

Washington, DC

a month ago - seen

Information Security Systems Officer (ISSO)

Fusion Technology Llc

Washington, DC

a month ago - seen

Information System Security Officer - Auditor

Peraton

Washington, DC

2 months ago - seen

Junior Information Systems Security Officer (ISSO)

Ntt Data

Washington, DC

2 months ago - seen

Senior Information Systems Security Officer (ISSO)

Ntt Data

Washington, DC

2 months ago - seen

Senior Cloud Information Systems Security Officer

Mantech International Corporation

Washington, DC

3 months ago - seen

Information System Security Officer (ISSO)

Mantech International Corporation

Washington, DC

3 months ago - seen

Senior Information System Security and Privacy Officer

SAIC Motor

WASHINGTON, DC

3 months ago - seen

Information Systems Security Officer (ISSO)

Guidehouse

Washington, DC

3 months ago - seen

Information System Security Officer (ISSO)

Tria Federal

Washington, DC

4 months ago - seen

Information System Security Officer (ISSO) Secret Cleared

RCG Inc

Washington, DC

4 months ago - seen

Information System Security Officer (ISSO) - Active TS/SCI required

Advanced Decision Vectors, LLC

Washington, DC

4 months ago - seen

Junior Information Systems Security Officer

Fusion Technology LLC

Washington, DC

4 months ago - seen

Mid - Level Information System Security Officer (ISSO)

Fusion Technology LLC

Washington, DC

4 months ago - seen