ISSO 2
Amentum · Fort Meade, MD · 1 wk ago
On-siteInformation TechnologyFull-time
We are seeking an Information Systems Security Officer (ISSO) 2 for a new prime contract based out of our Maryland office.
Responsibilities
- Provide support for a program, organization, system, or enclave's information assurance program.
- Propose, coordinate, implement, and enforce information systems security policies, standards, and methodologies.
- Maintain operational security posture for an information system or program to ensure information systems security policies, standards, and procedures are established and followed.
- Assist with the management of security aspects of the information system and perform day-to-day security operations of the system.
- Evaluate security solutions to ensure they meet security requirements for processing classified information.
- Perform vulnerability/risk assessment analysis to support security authorization.
- Provide configuration management (CM) for information systems security software, hardware, and firmware; manage changes to the system and assess the security impact of those changes.
- Prepare and review documentation including System Security Plans (SSPs), Risk Assessment Reports, Certification and Accreditation (C&A) packages, and System Requirements Traceability Matrices (SRTMs).
- Support security authorization activities in compliance with National Institute of Standards and Technology Risk Management Framework (NIST RMF).
- Develop and maintain documentation for Security Authorization in accordance with ODNI and DoD policies.
- Ensure compliance with system security policy.
- Provide support to the Information System Security Manager (ISSM) for maintaining the appropriate operational cybersecurity posture for a system, program, or enclave.
- Develop and update the system security plan and other cybersecurity documentation.
- Track and ensure appropriate user identification and authentication mechanisms of the information system (IS).
- Obtain system authorization for ISs under their purview.
- Plan and coordinate implementation of IT security programs and policies.
- Manage and control changes to the system, assessing the security impact of those changes.
- Provide daily oversight and direction to contractor ISSOs.
- Interact with customers, IT staff, and high-level corporate officers to define and achieve required cybersecurity objectives.
- Maintain records on workstations, servers, routers, firewalls, intelligent hubs, and network switches, including system upgrades.
Requirements
- Bachelor's degree in Computer Science, Cyber Security, IT Engineering, or a related field. In lieu of a bachelor's degree, four (4) additional years of work-related experience may be substituted for a total of twelve (12) years.
- Eight (8) years of combined work-related experience in IT, cybersecurity, or security authorization.
- Experience in at least two of the following areas: knowledge of current security tools, hardware/software security implementation, communication protocols, or encryption tools and techniques.
- Familiarity with commercial security products, security authorization techniques, security incident management, and PKI and authorization services.
- Compliance with DoD 8570.01-M with a minimum certification of IAM Level I.
- Active TS/SCI Poly clearance.
Benefits
- Health, dental, and vision insurance
- Paid time off and holidays
- Retirement benefits (including 401(k) matching)
- Educational reimbursement
- Parental leave
- Employee stock purchase plan
- Tax-saving options
- Disability and life insurance
- Pet insurance
Note: Benefits may vary based on employment type, location, and applicable agreements.
Pay
$165,000 - $190,000 per year