Logo
The Josef Group

Information Systems Security Officer (ISSO)

The Josef Group, Columbia, Maryland, United States, 21046


Information Systems Security Officer (ISSO)As the ISSO, you will serve on a team responsible for the Authorization and Assessment process under the Risk Management Framework for new and existing information systems and will be expected to maintain Authority to Operate compliance for all assigned systems.

Responsibilities:

Maintain the appropriate operational security posture for assigned systems, programs, and/or enclaves.

Provide guidance and technical expertise on all matters that impact or effect the security of the information system.

Assist in the development and execution of an enterprise level continuous monitoring program to minimize security risks and ensure compliance with that program on a routine basis.

Developing, updating, and submitting the System Security Plan and other required documentation that make up the Security Authorization Package.

Conduct configuration management for security-relevant changes to software, hardware, and firmware.

Perform and deliver security impact analyses of changes to the system or its environment of operation.

Assess the effectiveness of system security controls on an ongoing basis to determine system security status.

Maintain and enforce IT security policies and implementation guidelines for customer systems in diverse operational environments.

Provides configuration management for security-relevant information system software, hardware, and firmware.

Requirements:

The security authorization processes and procedures knowledge as defined in the RMF in NIST SP800-37 and familiarity with the ICD503, CNSSI1253, SP800-53, etc.

Experience with hardware/software security implementations.

Knowledge of different communication protocols, encryption techniques/tools, and PKI and authorization services.

Familiarity with security incident management, experience collaborating with Incident Response Teams, and able to provide viable recommendations for the resolution or computer security incidents and vulnerability compliance.

Clearance Required:

TS/SCI with Poly

Required Certifications:

DoD 8570.1 compliant IAM Level I certification, such as the CompTIA Security+ certification. A higher-level certification, such as GSLC, CAP, CASP, CISM and/or CISSP will also be accepted.

Minimum Years of Experience:

Ten years of related work experience in the field of security authorization or six (6) with an applicable BS degree.

#J-18808-Ljbffr