Position Summary
MAG is currently looking for an Information Systems Security Officer (ISSO) to provide a variety of services leveraging the Risk Management Framework (RMF) accreditation in Ft. Bragg NC
Services are associated with validation, approval, and sustainment of cybersecurity accreditation packages. In this role, you will perform and analyze a range of ISSO activities and assist with the development and implementation of security policies.
Essential Duties and Responsibilities
Duties include, but are not limited to :
- Gather and translate customer requirements, interact with stakeholders from many areas, and lead efforts to ensure customer products and recommendations will meet customer information security policies in an ever-changing technical environment
- Categorize the IT and the information processed, store, and transmitted by the system based on an impact analysis due to a loss of Confidentiality, Integrity, and Availability (CIA) impacts
- Select an initial set of baseline security controls for the Information System (IS) based on the security categorization; overlay tailoring and supplementing the security control baseline as needed based on an organizational assessment of risk and local conditions
- Assess the security control using the appropriate methods and procedures to determine the extent to which the controls are implemented correctly, operating as intended, and producing the desired outcome
- Authorize the IS based on the determination of the risk to the organizational operations, organizational assets, or to individuals resulting from the operation of the IS and the decision that this risk is acceptable
- Monitor the security of the IS on a continuous basis including assessing control effectiveness, documenting changes to the system, conducting security impact analyses of the associated changes, and reporting the security status of the system to appropriate organizational officials on a regular basis
- Review, prepare and update RMF authorization packages Conduct assessments of information security controls to measure the effectiveness of controls and identify any gaps
- Manage remediation efforts and report on the status of control deficiencies
- Provide security expertise to business units and key stakeholders
- Provide timely status updates / reporting on assessments and assigned projects
- Travel as necessary for customer projects, technology expositions, and corporate meetings
Requirements
Minimum Requirements
Knowledge and Skills
In compliance with DoD Cyber Workforce 8570.01Experience in Information Assurance / Cybersecurity, including development, integration, and implementation of cybersecurity and program protection standards for networking, computers, and custom applicationsThorough knowledge of the Department of Defense 8510.01 Risk Management Framework (RMF) for DoD Information Technology, DoD Instruction 8500.1 Cybersecurity, DoD Directive 8140.01, Cyberspace Workforce Management, NIST 800 Special Publications, Federal Information Processing Standards (FIPS), and knowledge of current authorization practices, particularly within the DoDExperience in creating and maintaining the security configuration baselines for Windows and Linux platforms, networking equipment, cloud technologies, and custom applications (., Minimum Benchmarks : CIS, STIGS)Provide subject matter expertise, advice and assistance in the planning, implementation, and accreditation of technology and solutionsMust meet position and certification requirements outlined in DoD Directive 8570.01 M for Information Assurance Management Level 2 (IAM Level II)The minimum years of related experience required : 5Education
BS in Computer Science or Information Technology (or equivalent experience)Desired Requirements
Familiar with DIA assessments and accreditation documentation within the XACTA management platformFamiliar with eMASS - USSOCOM ENTERPRISE MISSION ASSURANCE SUPPORT SERVICES platformAbility to read, review, and consolidate ACAS scans, DISA STIGS, and Websense resultsExcellent interpersonal skills, including the ability to work on multi-functional teamsDisplay detailed knowledge and understanding of multiple technology infrastructuresAbility to serve as a principal advisor on all matters, technical and otherwise, involving the security of an ISExhibit individual initiative to influence events and achieve goals.Be proactive and a self-starter, going beyond specific job responsibilities to ensure goals and achieved or exceededOther Qualifications
US CitizenshipActive TS / SCI Clearance