Logo
DAn Solutions Inc

Information Systems Security Officer IV

DAn Solutions Inc, Herndon, Virginia, United States, 22070


REQUIRES AN ACTIVE/EXISTING TS/SCI WITH CI POLYGRAPH - NO REMOTE WORK MUST WORK ON SITEJob Description:ISSO responsibilities for new or existing system(s) may include:•Defines information security requirements and their integration into information systems and its technology component through purposeful security design.•Develops and implements security designs to ensure that the hardware, operating systems and software applications adequately address cyber security requirements and Security Controls Traceability Matrix (SCTM).•Identify points of vulnerability, non-compliance with established Information Assurance (IA) standards and regulations and recommend mitigation strategies.•Implement, validate Security Technical Implementation Guide (STIG) requirements and/or perform SRG assessments for all development and implementation projects.•Develop, customize, and configure Splunk applications and dashboards.•Develop Security Test Procedure (STP), conducts self-assessments to verify compliance with required configuration guidance and support A&A testing and validation of security designs.•Conducting risk analysis reviewing ACAS, CVEs, plugins, CWEs, research, collaborate with System Administrators to mitigate identified vulnerabilities and/or author Plans of Actions and Milestones (PO&AM) as needed.•Execution of continuous monitoring efforts responds to data calls, scan requests, and various weekly and monthly security metrics reporting requirements.•Validate control implementations provide enforcement of the require data access and network flow restrictions align with the continuous monitoring strategy.•Participates in Agile Planning Events to provide technical input.•Support government activities and reporting to appropriate IC and DoD authorities (i.e., USCYBERCOM, IC-SCC)•Support security authorization activities in compliance with the customer Information System Certification and Accreditation Process following the NIST Risk Management Framework (RMF), CNSSI No 1243 and other prescribed business processes for security engineering.•Assist architects and systems developers in the identification and implementation of appropriate information security functionality to ensure uniform application of Agency security policy and enterprise solutions.•Apply system security engineering expertise in one or more of the following to: system security design process; engineering life cycle; information domain; cross domain solutions; commercial off-the-shelf and government off-the-shelf cryptography; identification; authentication; and authorization; system integration; risk management; intrusion detection; contingency planning; incident handling; configuration control; change management; auditing; certification and accreditation process; principles of IA (confidentiality, integrity, non-repudiation, availability, and access control); and security testing.

Required Qualifications:•Must be a US Citizen•Active TS/SCI security clearance with the ability to obtain polygraph is required•8 years of relevant experience and a Bachelor's degree appliable to the position from an accredited college or university is required. A Master's degree relevant to the position may be substituted for two (2) years of additional experience. Four (4) years of additional ISSO experience may be substituted for a bachelor's degree.•Must hold active Security+, CISSP, CISA, or equivalent certifications (DoD 8570 IAM 2 equivalent)•Experience and in-depth working knowledge of FISMA and NIST Information Security Guides•Understanding of FISMA, NIST, and Office of Management and Budget (OMB) Federal Information System requirements•Demonstrated experience with DISA Security Technical Implementation Guide (STIG) implementation and Security Content Automation Protocol (SCAP) tool usage•Provide guidance on vulnerability and malware remediation.•Experience analyzing vulnerabilities, establishing cause and impact, and identifying the corrective action needed to eliminate and prevent the event from happening in the future.•Advanced written and verbal communication skills

Desire Qualifications:•Experience with effective policy, instruction, and development for Federal or DoD Information Security Programs•Experience with performing Security Control Assessment in compliance with NIST SP 800- 37, NIST SP 800-53, NIST SP 800-53A, and other NIST 800 guide series•Experience with risk analysis and assessment determinations incorporating system/mission owner, and unique operational constraints•CSAM tool experience is preferred•Understanding of FISCAM compliance•Experience with Amazon Web Services (AWS)•Experience with Xacta•Current polygraphDAn Solutions is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, or protected veteran status and will not be discriminated against on the basis of disability. If you are an individual with a disability and would like to request a reasonable accommodation as part of the employment selection process, please contact Human Resources at (703) 542-4554 or email info@dansolutions.com.