Jobs · Information Technology · Virginia

Information System Security Officer (ISSO)

KBR Careers · Alexandria, VA · Today
Information Technology$125k–$155k/yrFull-time

About the role

The successful candidate will provide support to the Test Resource Management Center’s (TRMC) All Domain Test Range (ADTR) and INDOPACOM Pacific-Rim Multi-Domain Training and Experimentation Capability Team, Joint Mission Environment Test Capability (JMETC) Secret Network (JSN) Node, JMETC Multiple Independent Levels of Security Network (JMN) Node, Secret Defense Research and Engineering Network (SDREN), Defense Research and Engineering Network (DREN).

Responsibilities

  • Develop, implement, and maintain security policies, procedures, and standards to safeguard organizational information systems.
  • Conduct regular security assessments, vulnerability scans, and penetration testing to identify and mitigate potential threats.
  • Monitor security alerts and logs to respond to incidents in a timely manner, ensuring compliance with DoD regulations.
  • Manage Privileged Access Management (PAM) solutions to ensure secure access control for sensitive systems and data.
  • Filter and generate reports from Security Information and Event Management (SIEM) tools to provide insights into security incidents and trends.
  • Respond to JFHQ-DODIN issued orders, such as Cyber Task Orders (CTO).
  • Participate in DoD mandated Zero Trust efforts (initiatives, planning, testing and implementation).
  • Administer Windows and Linux servers, ensuring optimal performance, security and uptime.
  • Manage Active Directory for user account provisioning, authentication, and access control, ensuring compliance with organizational security policies.
  • Implement and maintain STIGs to harden system configurations and reduce vulnerabilities across all server environments.
  • Oversee the virtualization of servers using VMware, Hyper-V, or similar technologies, ensuring secure and efficient resource allocation.
  • Manage cloud-based services and applications, ensuring they adhere to security policies and best practices.
  • Apply RMF principles to assess and manage risk associated with information systems, including categorization, selection of security controls, implementation, assessment, authorization, and continuous monitoring.
  • Collaborate with stakeholders to ensure all systems are RMF-compliant and maintain relevant documentation.
  • Develop and conduct security training programs for staff to enhance awareness of information security best practices and organizational policies.
  • Function as a security advisor to other departments, providing guidance on secure system design and implementation.
  • Document and report on security processes, incidents, and remediation efforts.

Qualifications

  • Education: Bachelor’s degree in Computer Science, Information Technology, Cybersecurity, or a related field.
  • Certifications: CISSP, CISM, CASP, Security+
  • Experience: Minimum 10 years of system administration or cybersecurity-related experience, specifically within DoD environment.
  • Technical Skills: Proficient in Windows server and Linux server management, including installation, security policies, configuration, and troubleshooting.

Desired Qualifications

  • Advanced degrees or certifications (CISSP, CISM, CASP, Security+)
  • Virtual Desktop Infrastructure (Horizon, UAG)
  • Provision and Maintain VM pools
  • Client Support (Solid understanding and experience supporting zero/thin clients)
  • Risk Management System Support (Experience supporting systems within a DoD Risk Management Framework (RMF) accredited environment)
  • SIEM Solutions (Splunk, SolarWinds, etc.)
  • Skills: Coordination, Communication and Presentation skills
  • Layer 2/3 Networking experience
  • Firewall experience
  • DoD 8570 certifications: Security+, CISSP, Computing Environment
  • DoD Network experience: Experience working with DoD Wide Area Networks and familiarity with various network architectures and common protocols to include:
  • Experience working with Defense Research and Engineering Network (DREN)
  • Experience working with the Secret Defense Research and Engineering Network (SDREN)
  • EPO (Trelix) experience – policy, agent updates, compliance dashboards
  • ACAS experience – scanning, reporting, compliance dashboards

Similar jobs