Information Systems Security Officer (TS/SCI with Poly Required)
GCI Incorporated · Tysons Corner, VA · 1 mo ago
On-siteInformation TechnologyFull-time
About the role
Members of the ISSO team support the assessment and authorization (A&A) process for information systems. The successful candidate will have requisite cyber security experience with methods and tools used to improve the security posture of critical systems such as identifying risks, vulnerabilities, anomalies, patching, auditing, automation, security hardening, best practices, and evaluating system changes. The candidate will collaborate with developers and engineers on projects to create a secure hybrid-cloud environment.
Responsibilities
- Support the assessment and authorization (A&A) process for information systems
- Identify risks, vulnerabilities, anomalies, and evaluate system changes
- Implement security hardening and best practices for operating systems (e.g., CentOS, RedHat, Windows)
- Collaborate with developers and engineers to secure hybrid-cloud environments
- Assess and report on control implementation using cyber security and assessment management systems
- Monitor and manage perimeter controls (firewalls), access control mechanisms, and network architectures
- Use vulnerability and risk assessment tools such as Elasticsearch, Splunk SIEMs, Rapid7 Nexpose, and IDS/IPS monitoring
- Research and document software and hardware vulnerabilities
- Work closely with stakeholders, developers, external teams, and customer security managers (ISSMs)
- Assist with the customer’s assessment and authorization tracking tools
- Apply knowledge of Common Control Provider (CCP) requirements and methodology
- Design and implement defense-in-depth security solutions
- Document processes and procedures in CONOPS, system security, contingency, and configuration management plans
- Facilitate customer concurrences for risk-based decisions, including waivers
- Assist with decisions impacting security posture and compliance with NIST 800-53
- Monitor and audit cloud-based technologies, products, and services (e.g., AWS, Microsoft Azure)
- Work within fast-paced customer environments using their network systems, infrastructure, and tools
Requirements
- Bachelor’s degree in Cybersecurity, IT, or other related technical discipline; or equivalent combination of education, technical training, or work/military experience
- Minimum eight (8) years of applied experience or relevant degree plus five (5) years of Cybersecurity expertise
- Demonstrated ability to successfully shepherd IT projects through the authorization lifecycle
- Active/current TS/SCI with Polygraph clearance (US Citizenship required)
Skills
- Strong verbal and written communication within a team context
- Understanding of networking topologies, hardware, and commonly used network devices (e.g., IDS/IPS)
- Experience with vulnerability and risk assessment tools (e.g., Elasticsearch, Splunk, Rapid7 Nexpose)
- Familiarity with communications protocols (e.g., TCP/IP, UDP, HTTP/S, SSH, LDAP)
- Experience with open-source and commercial tools (e.g., nmap, Nessus, Rapid7, Jira, Confluence, Cisco, VMware, Citrix, Trellix)
- Experience with scripting/programming languages (e.g., Bash, PowerShell, Python) — desired
- Knowledge of the customer’s organization, processes, and request/approval tools