Information Systems Security Officer
Posted on May 18, 2019 by Leidos
Employer is seeking an an Information Systems Security Officer (ISSO) within an established Information Assurance (IA) team in our San Diego, CA office.
Under the direction of the Information System Security Manager (ISSM) the ISSO specific responsibilities will include:
Establish, implement, and manage security procedures and practices in support of customer requirements and objectives.
Develop and update assessment and authorization documentation (Body of Evidence) for management and continuous monitoring of information systems.
Using knowledge of the Information System (IS) and understanding of established Information Assurance requirements validate security policies and procedures outlined in the System Security Plan (SSP), customer policies & regulations, and ensure local policies are followed.
Take corrective action to resolve problems identified and ensure systems are operated, maintained, and disposed of in accordance with established policies and procedures.
Perform security audits IAW established procedures. Develop process for the management, review, and retention of security audit data. Report audit discrepancies to the ISSM.
Author and review IS security-related documentation.
Establish system specific recovery processes to ensure security features and procedures are properly protected and restored.
Conduct ongoing security reviews and tests of systems to verify security features and controls are functional and effective. Take corrective action to resolve identified vulnerabilities.
An active DoD Secret clearance is required for consideration.
Bachelor's degree in Information Security, Information Systems, or related discipline and 2 - 4 years of direct experience; or Masters degree and 2 years of experience. Additional relevant/specialized training and experience may be substituted in lieu of degree.
Possess a current DoD 8570.01 compliant certification for IAM Level I, eg Security + w/CE, or the ability to obtain either within 6 months of employment.
Experience with DoD implementation of the Risk Management Framework (RMF) and governing directives (NIST, CNSS, DSS, etc.)
Familiarity with the Defense Security Service Assessment and Authorization Manual (DAAPM)
The qualified candidate shall have excellent customer service skills and the ability to work independently, prioritize, schedule, and complete multiple tasks.
Experience with DISA Security Technical Implementation Guides (STIG) as well as performing Security Content Automation Protocol (SCAP) scans and associated checklist
Current DoD Top Secret clearance
Comprehensive knowledge of the Defense Security Service Assessment and Authorization Manual (DAAPM), RMF (Risk Management Framework), ICD 503, NISPOM Chapter 8, and NIST 800-53 security controls.
Experience conducting security audits of information systems.
Extensive training or experience with Windows based Information Systems standards with a working knowledge of Linux & Solaris operating systems.
Current Certified Information System Security Professional (CISSP) certification
Vulnerability assessment and analysis experience utilizing SCAP, ACAS/NESSUS and DISA STIGs