Senior Information System Security Officer
About the role
CACI is searching for a Senior Information System Security Officer (Senior ISSO) to support the DHS Headquarters. As a Senior Information System Security Officer, you will play a crucial role in ensuring the security and compliance of DHS HQ's information systems. You will work in a dynamic environment, collaborating with IT system owners, stakeholders, and cybersecurity professionals to implement and maintain robust security controls. Your efforts will directly contribute to safeguarding DHS's mission-critical systems and data.
Responsibilities
- Execute complete Risk Management Framework (RMF) activities for Authority to Operate (ATO) decisions including system categorization, security control selection and implementation, self-assessments, POA&M development, and continuous monitoring.
- Develop and maintain System Security Plans (SSPs) including control baselines, inheritance, Business Impact Analyses, implementation statements, technical and system descriptions, and hardware and software inventories.
- Create and maintain Configuration Management Plans, conduct Security Impact Analyses, approve Change Requests, and document the security impact of configuration changes.
- Develop and test Contingency Plans and Incident Response Plans to ensure business continuity, as well as conduct annual risk assessments, supporting security assessments, and vulnerability assessments across assigned systems.
- Advise system owners and senior executives on all cybersecurity matters and develop remediation work plans for assessment and/or audit findings.
- Maintain Hardware and Software Inventory Lists and conduct FISMA Scorecard Analysis.
- Ensure proper access controls are implemented for system access, track and suggest technologies, processes, and practices designed to protect networks, devices, programs, and data from malicious attack, damage, or unauthorized access.
- Research and maintain proficiency in tools, techniques, countermeasures, and trends in computer and network vulnerabilities, data hiding, and network and device security and encryption.
Qualifications
- U.S. Citizenship required
- Active Top Secret Clearance
- BS/BA + 15 years of applicable experience in information security
- 10+ years of experience in information security
- Experience working with classified information systems and SCIFs
- Demonstrated expertise in RMF, FISMA, NIST, DHS 4300 Series, and classified system security requirements
- Complete Standard Form 4414 Non-Disclosure Agreement prior to accessing TS/SCI information
- One of the following Information Assurance Technician (IAT) Level III qualifications: Certified Information System Security Professional (CISSP), Certified Information Security Manager (CISM), CompTIA Advanced Security Practitioner (CASP+)
Desired qualifications include previous DHS or DoD experience with classified systems, experience with Supply Chain Risk Management for classified networks, experience with CSAM, RegScale, eMASS, or similar GRC tools in classified environments, knowledge of Intelligence Community Directive (ICD) 503 and related requirements, experience supporting emergency operations or disaster response missions, and strong communication skills.
Benefits
CACI offers a broad and competitive mix of benefits options designed to support and protect employees and their families, including healthcare, wellness, financial, retirement, family support, continuing education, and time off benefits.
Pay
The proposed salary range for this position is $120,800 - $265,800.