Location: Reston, VA
Security Clearance: Active TS/SCI [Required]
Job Type: Full-Time
Target Salary Range*:$170,000 - $201,000
*This represents the potential salary range for this position depending on education level, years of experience and/or certifications in addition to other position specific requirements which may impact salary
Position Overview
The Amatriot Group is looking to hire an Information Systems Security Officer (ISSO) responsible for researching, generating, and validating security controls that support the customer’s Risk Management Framework.
The Senior ISSO will define, create, and maintain System Security Plans to support Accreditation and Authorization reviews and coordinate with customer security organizations, application development teams, and sustainment teams to maintain and/or obtain an Authority to Operate.
This role will review systems to identify potential security weaknesses, recommend improvements to address vulnerabilities, assist with implementing changes, and document upgrades. Knowledge of complex environments involving shared IC networks and multiple security enclaves is a sought-after skill.
Key Responsibilities:
Information System Security Oversight
- Serve as the principal advisor to the information system owner and the ISSM on all matters, technical and otherwise, involving the security of information systems.
- Ensure the day-to-day implementation, oversight, continuous monitoring, and maintenance of the security configuration, practices, and procedures for each assigned system.
- Provide liaison support between the system owner and customer security teams.
- Participate in the change management process.
RMF, A&A, and ATO Support
- Research, generate, and validate security controls that support the customer’s Risk Management Framework.
- Define, create, and maintain System Security Plans to support Accreditation and Authorization reviews.
- Coordinate with customer security organizations, application development teams, and sustainment teams to maintain and/or obtain an Authority to Operate.
- Prepare and maintain documentation from information obtained from the customer using accepted guidelines such as DITSCAP.
- Develop Plan of Action and Milestones in response to reported security vulnerabilities.
Security Requirements and Compliance
- Design, develop, and implement security requirements within an organization’s business processes.
- Develop strategies to comply with privacy, risk management, and e-authentication requirements.
- Analyze policies and procedures against federal laws and regulations and provide recommendations for closing gaps.
- Conduct security program audits and develop solutions to lessen identified risks.
Vulnerability Management and Continuous Monitoring
- Review systems to identify potential security weaknesses.
- Recommend improvements to address vulnerabilities.
- Assist with implementing changes and documenting upgrades.
- Perform vulnerability assessments, including development of risk mitigation strategies.
- Assist ISSEs and/or Security Engineers with implementation of the Continuous Monitoring program.
Technical Coordination
- Coordinate with the team’s ISSEs and/or Technical Leads to implement technical solutions during development.
- Coordinate with Information System Security Managers in testing, documenting, and achieving accreditation of systems throughout the development process and achieving operational acceptance.
Qualifications:
Education
- BS in Computer Science, Engineering, Information Technology, System Administration, Cyber Security, with 8 or more years of prior relevant experience.
- Will consider 6 years of prior relevant experience with an MS or 4 years of prior relevant experience with a PhD.
Experience
- Five or more years of information assurance and cyber security engineering experience.
- Experience with the Risk Management Framework and ICD 503 Security Accreditation processes.
- Experience working in Xacta, including updating and maintaining ATO records within Xacta.
- Experience coordinating with Information System Security Managers in testing, documenting, and achieving accreditation of systems throughout the development process and achieving operational acceptance.
- Experience with STIG compliance, creating POA&Ms, and vulnerability management.
Certifications
- CompTIA Security+ and/or CISSP certification.
Clearance
- Active Top Secret/SCI clearance with CI polygraph.
Preferred Qualifications:
- Experience with security tools and processes such as Nessus Security Center, WebInspect, AppDetective, ACAS, and similar tools.
- Experience with cloud computing technologies/Amazon Web Services, specifically C2S.
- Knowledge of complex environments involving shared IC networks and multiple security enclaves.