Designated Authority Officer (DAO)
Job Description
Aids in identifying overall security requirements for protecting data, ensuring implementation of appropriate information security controls.
Assists in performing and analyzing security planning, assessment, risk analysis, risk management processes, security control assessments, and awareness activities for systems and networking operations.
Provides assistance to ensure Information Assurance (IA) functions are integrated into the configuration management process.
Interacts with customers, IT staff, and high-level corporate officers to assist in defining and achieving required IA objectives for the organization.
Contributes to building security architecture.
Aids with the integration of legacy systems.
Contributes to the acquisition/RDT&E environment and ensures IA is incorporated into systems deployed to operational environments.
Prepares security authorization documentation.
Required
- Ten years or related work experience.
- Bachelor's Degree in Computer Science or IT Engineering (may be substituted for four years of experience).
- DoD 8570-01-M compliance with Security Authorization Professional or System Security Engineer.
- Previous work experience as an IT Risk Assessor, System Security Engineer, Information Systems Security Manager, or Data Owner's Advocate (DAO); may be substituted based on experience.
- Working knowledge of:
- System security design process, defense-in-depth/breadth, engineering life cycle, information domains, cross-domain solutions, controlled interfaces, identification, authentication and authorization, system integration, ICD 503 (formerly NISCAP), risk management, intrusion detection, contingency planning, incident handling, configuration control, change management, auditing, security authorization process, principles of IA (confidentiality, integrity, non-repudiation, availability, access control), and security testing.