Information Systems Security Officer
E&M Technologies, Inc. is dedicated to recruiting and developing diverse, high-performing talent who are passionate about what they do. Our employees are unified in a shared dedication to our customers’ mission and quest for professional growth. E&M provides an inclusive, engaging environment designed to empower employees and promote work-life success.
About the role
Join our team in Colorado Springs, CO in support of the North American Aerospace Defense Command (NORAD). NORAD is a United States and Canada bi-national organization charged with the missions of aerospace warning, aerospace control, and maritime warning for North America. Aerospace warning includes the detection, validation, and warning of attack against North America whether by aircraft, missiles, or space vehicles, through mutual support arrangements with other commands.
Play a key role in ensuring the cybersecurity posture of mission-critical systems within the NISSC II portfolio. Have responsibility for maintaining compliance with Risk Management Framework (RMF) requirements and supporting Assessment and Authorization (A&A) efforts to ensure systems maintain an active Authorization to Operate (ATO). Perform security analyses of threats, vulnerabilities, and system environments while collaborating with government, supplier, and internal stakeholders to implement security measures that safeguard mission systems.
Responsibilities
- Apply Risk Management Framework (RMF) processes and principles in compliance with National Institute of Standards and Technology (NIST) Special Publication (SP) 800 series.
- Develop and/or contribute to the RMF Body of Evidence, including creation and maintenance of applicable artifacts and documentation for security control implementation and assessment.
- Perform NIST SP 800-53 control assessments for Secret systems, including assessment of technical, operational, and management security controls.
- Utilize Department of Defense RMF tools eMASS to document assessment results, track vulnerabilities, manage POA&Ms, and report compliance status.
- Perform continuous assessments of systems and network security measures to identify potential risks, vulnerabilities, and threats.
- Develop effective risk prevention strategies and mitigation plans to protect organizational assets.
- Interpret and apply cybersecurity policies to operational systems and provide informed recommendations.
- Utilize security-relevant tools such as Assured Compliance Assessment Solution (ACAS) and Endpoint Security Solution (ESS) to identify vulnerabilities, assess risks, and recommend actionable mitigations.
- Use Security Content Automation Protocol (SCAP) tools to analyze system configurations and check compliance with DoD Security Technical Implementation Guides (STIGs).
- Foster and promote a proactive cybersecurity culture within the organization through awareness and adherence to security principles.
- Collaborate effectively with cross-functional teams, customers, and third-party vendors.
- Present complex cybersecurity concepts and issues in a clear, concise manner to both technical and non-technical audiences.
Requirements
- 5 or more years of general work experience.
- 5 or more years of directly related experience in cybersecurity or information assurance.
- Experience applying RMF processes and principles in compliance with NIST SP 800 series.
- Must meet the requirements outlined in DoDM 8140 in the Information System Security Manager role (722).
- Must be a U.S. Citizen.
- Must have and be capable of maintaining a U.S. Department of Defense (DoD) security clearance at the TS/SCI level.
- Up to 10% travel may be required.
Preferred Qualifications
- In-depth experience with the implementation of RMF processes in compliance with applicable DoD and industry cybersecurity policies and standards.
- Practical experience using SCAP tools to analyze system configurations and check compliance with DoD STIGs.
- Familiarity with best practices for secure system architectures, vulnerability management, and incident response.
- Strong interpersonal and communication skills.
Benefits
- Medical, dental, and vision insurance.
- Life insurance, short-term disability, and long-term disability.
- 401(k) match.
- Flexible spending accounts.
- Flexible work schedules.
- Parental leave.
- Paid time off and holidays.
Specific benefits are dependent upon the specific business unit as well as whether or not the position is covered by a collective-bargaining agreement.