Information Systems Security Officer, Mid
About the Role
Cyber threats are everywhere, and the constantly evolving nature of these threats can make understanding them seem overwhelming to our clients. As an information security risk specialist on our team, you’ll work with clients to discover their cyber risks, understand applicable policies, and develop a mitigation plan. You’ll get technical and personnel details from colleagues to assess the entire threat landscape, then help guide your client through a plan of action with presentations, whitepapers, and milestones. You’ll translate security concepts for your client so they can make the best decisions to secure their mission-critical systems. This is your opportunity to take an active role in information security while growing your skills in cloud technologies.
Responsibilities
- Conduct tools assessments and configuration analysis against best practices, vendor specifications, and government security guidelines and requirements.
- Implement, oversee, and maintain the security configuration, practices, and procedures for systems.
- Implement controls from NIST 800-53, FedRAMP, ICD 503, RMF, and DoD Information Levels, including applying them to the design and implementation of information technology solutions to achieve an authorization to operate (ATO).
- Perform risk analysis.
- Assess configuration changes, such as new COTS tools or web application upgrades, to system security boundary.
- Work within a collaborative team and a fast-paced, dynamic environment.
Requirements
- 2+ years of experience as an ISSO or Information System Security Analyst (ISSA).
- Experience with the implementation, oversight, and maintenance of security configuration, practices, and procedures for systems.
- Ability to perform risk analysis.
- Active TS/SCI clearance; willingness to take a polygraph exam.
- HS diploma or GED.
- DoD 8570 IAM Level II Certification such as CCNA-Security, CySA+, GICSP, GSEC, Security+ CE, CND, or SSCP.
Nice to Have
- Experience with DoD security technical implementation guides (STIGs), checklists, and testing tools, including STIG Viewer, SCAP, and ACAS scanning tool.
- Experience with cyber-related tools, such as Splunk or STIG Viewer.
- Experience with SAP.
- Knowledge of Zero Trust principles and concepts.
- Possession of excellent written, organizational, presentation, and verbal communication skills.
- AWS, Azure, or GCP Certification.
Clearance
Applicants selected will be subject to a security investigation and may need to meet eligibility requirements for access to classified information; TS/SCI clearance is required.
Benefits
Our offerings include health, life, disability, financial, and retirement benefits, as well as paid leave, professional development, tuition assistance, work-life programs, and dependent care. Full-time and part-time employees working at least 20 hours a week on a regular basis are eligible to participate in Booz Allen’s benefit programs. Individuals that do not meet the threshold are only eligible for select offerings, not inclusive of health benefits.
Pay
Salary at Booz Allen is determined by various factors, including but not limited to location, the individual’s particular combination of education, knowledge, skills, competencies, and experience, as well as contract-specific affordability and organizational requirements. The projected compensation range for this position is $61,900.00 to $141,000.00 (annualized USD).
Schedule
This posting will close within 90 days from the posting date.
Work Model
Our people-first culture prioritizes the benefits of collaboration, whether it occurs in person or virtually. To support engagement and effective communication, employees working virtually are generally expected to have their cameras on during meetings.
- Remote: If this position is listed as remote, there may still be occasions when you are required to work in person at a Booz Allen or customer facility.
- Hybrid: If this position is listed as hybrid, you will be expected to work from a Booz Allen facility frequently, in alignment with leadership expectations and the needs of the role. You may also be required to work from or visit a customer facility.
- Onsite: If this position is listed as onsite, work will primarily be performed at a Booz Allen office or customer facility, where employees will collaborate directly with colleagues and customers as required by the role.