Information System Security Officer
MIT Lincoln Laboratory · Colorado Springs, CO · 1 mo ago
Information Technology$78k–$102k/yrFull-time
About the role
The Security Services Department’s overall mission is to identify and counter security threats to the MIT Lincoln Laboratory’s mission of developing game-changing technology in support of National Security, including guarding against compromise by foreign intelligence agencies and insider threats.
Responsibilities
- Assist and Support necessary compliance activities (e.g., ensure that cyber system security configurations guidelines are followed, compliance monitoring occurs).
- Continuously validate the organization against cybersecurity policies/guidelines/procedures/regulations/laws to ensure compliance.
- Ensure that plans of actions and milestones or remediation plans are in place for vulnerabilities identified during risk assessments, audits, inspections, etc.
- Promote awareness of security issues among management and ensure sound security principles are reflected in the organization's vision and goals.
- Conduct continuous monitoring and track audit findings and provide countermeasure and mitigation recommendations to ensure that appropriate actions are taken to secure critical R & D data.
- Recommend resource allocations required to securely operate and maintain an organization's cybersecurity requirements.
- Provide technical documents, incident reports, findings from computer examinations, summaries, and other situational awareness information to key stakeholders.
- Recognize a possible security violation and take appropriate action to report the incident, as required.
- Aid in the development and maintenance of System Security Plans (SSP) and associated artifacts such as the Plan of Action & Milestones (POA&M), Risk Assessment Report, and Continuous Monitoring Strategy.
- Ensure systems are operated, maintained, and disposed of in accordance with organization security policies and procedures.
- Provide periodic cybersecurity reviews of network, system, and application vulnerability scanning, configuration assessment, and remediation.
- Lead and align information technology (IT) security priorities with the security strategy.
- Prepare for and participate in periodic organization compliance assessments.
- Interpret patterns of noncompliance to determine their impact on levels of risk and/or overall effectiveness of the enterprise's cybersecurity program.
Requirements
- A current Top Secret Clearance with SCI eligibility
- Must be a U.S. Citizen
- Successfully pass a background check and consent to undergo a government polygraph examination
- Demonstrated experience with vulnerability scanning and auditing tools and processes is required
- Excellent written and verbal communication skills are required
- Demonstrated understanding of the following security frameworks is required:
- NIST 800-53 / Risk Management Framework (RMF)
- Intelligence Community Directive (ICD) 503
- National Industrial Security Program Operating Manual (NISPOM) Chapter 8
- DoD Manual 5205.07 Volumes 1- 4
Qualifications
- A minimum of 4 years of IT security experience in DoD cybersecurity is preferred
- Possess a DoD 8570.01-M IAM I baseline certification (e.g. CompTIA Security+), or be able to obtain one within 6 months of hire
- Technical experience, skills, and course work completed towards an undergraduate degree, or industry IT certifications may be considered in lieu of education or DoD security experience requirements
- Experienced in auditing, configuration and vulnerability management
- Experience and familiarity with multiple operating systems such as Windows Server 2012, 2016, 2019, and 2022 Windows 10 and 11, Red Hat Enterprise Linux, Ubuntu, Mac, etc.
- Experience with virtualization and Cloud technologies is preferred
- Ability to integrate information security requirements into the acquisition process; using applicable baseline security controls as one of the sources for security requirements; ensuring a robust software quality control process; and establishing multiple sources (e.g., delivery routes, for critical system elements).
- Technical experience securing networks and systems utilizing DISA STIGs and/or SRGs is highly desired
Benefits
- Comprehensive health, dental, and vision plans
- Mitigant-funded pension
- Matching 401K
- Paid leave (including vacation, sick, parental, military, etc.)
- Tuition reimbursement and continuing education programs
- Mentorship programs
- A range of work-life balance options
Pay
Hiring Range: $78,300 - $102,000
Schedule
Flexible schedule and hybrid remote work arrangements are encouraged.