ISSO/ISSE- Hybrid (Philadelphia)

Ishpi Information Technologies, Inc. (DBA ISHPI)

Philadelphia (Philadelphia County)

On-site

USD 90,000 - 120,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Ishpi Information Technologies, Inc. (DBA ISHPI) is seeking a cybersecurity professional to manage risk management frameworks and perform automated vulnerability assessments. The ideal candidate will have a Bachelor’s degree in a related field, three years of relevant experience, and compliance with NIST guidelines. Responsibilities include maintaining security authorizations, conducting security reviews, and managing cybersecurity patching for various systems. An active government security clearance is required. This role is based in Philadelphia County, PA.

Qualifications

  • Bachelor’s degree in Computer Science, Information Technology or related field.
  • Three years of experience in a relevant cybersecurity role.
  • Active government security clearance required.

Responsibilities

  • Maintain AO Approvals and Authorizations to Operate (ATOs).
  • Perform automated vulnerability assessments using approved tools.
  • Conduct RMF Annual Security Reviews in accordance with guidelines.
  • Document and seek approval for system changes.
  • Manage RMF system packages in eMASS.

Skills

Automated vulnerability assessments
Cybersecurity patching
Risk Management Framework (RMF)
NIST SP 800-53 security controls
Continuous Monitoring (CM)

Education

Bachelor’s degree in Computer Science or related field

Tools

Assured Compliance Assessment Solution (ACAS)
Security Content Automation Protocol (SCAP)
eMASS

Job description

Ishpi Information Technologies, Inc. (DBA ISHPI) is passionate about providing our customers with technical solutions that satisfy their business needs. Through collaborative interactions with customers, team members, subject matter experts (SMEs), technical leaders, and partners we design practical solutions that solve real problems for major government and business organizations. As a member of our group, you will work with a team focused on delivering innovative business solutions using emerging technologies through proven successful methods.

  • Maintain Authorizing Official (AO) Approvals and Authorizations to Operate (ATOs) by performing Continuous Monitoring (CM) activities IAW DoD, Navy, and NAVSEA policy, guidelines, and directives.
  • Assess, document, and review NIST SP 800-53 security controls IAW DoD, Navy, and NAVSEA policy, guidelines, and directives.
  • Perform automated vulnerability assessments utilizing DoD, Navy, and NAVSEA approved tools such as Assured Compliance Assessment Solution (ACAS), Security Content Automation Protocol (SCAP), Evaluate-Stig, and eMASSter.
  • Perform RMF Annual Security Reviews (ASRs) IAW the RMF Process Guide (RPG), NAVSEA Business Rules, and NAVSEA Standard Operating Procedures (SOPs).
  • Document, assess, and seek approval for system/baseline changes IAW Navy Authorizing Official (NAO) and Functional Authorizing Official (FAO) guides as documented in the NAVSEA Business Rules.
  • Manage and maintain RMF system packages and the required A&A artifacts in Enterprise Mission Assurance Support Service (eMASS) IAW DoD, Navy, and NAVSEA policy, guidelines, and directives.
  • Perform System Level Continuous Monitor (SLCM) IAW approved System Security Plans (SSPs) in eMASS.
  • Develop and maintain Plans of Action and Milestones (POA&Ms) for systems in eMASS.
  • Develop and maintain project integrated master schedules for RMF projects.
  • Evaluate, remediate, and mitigate technical and non-technical vulnerabilities.
  • Provide cybersecurity patching of assets as required by DoD and DoN TASKORDs, FRAGORDs, or as designated by Command ISSM, ACIO, and/or Code 418 management.
  • Ensure correct application and implementation of DoD Security Technical Implementation Guides (STIGs) and Security Requirements Guide (SRGs).
  • Lead or assist with developing, maintaining, and tracking Risk Management Framework (RMF) system security plans to include System Categorization, Security Control Set, Platform Information Technology (PIT) Determination Checklists, Assess Only (AO) Determination Checklists, Implementation Plans, System Level Continuous Monitoring (SLCM) Strategies, System Level Policies, Hardware Lists, Software List, System Diagrams, Privacy Impact Assessments (PIA), and other package evidence or implementation guidance as required.
Education

Bachelor’s degree in Computer Science, Information Technology, Information Assurance, CyberSecurity, or an equivalent technical degree from an accredited college or university.

Experience

Three (3) years or more of direct experience performing the above duties as an ISSO, ISSE, or Navy Qualified Validator (NQV) within a DoD component.

Minimum Certification Requirement includes one of the following

CGRC, SecurityX, CISM, CISSP, GSLC, CCISO, CCNA/CCNP Security, CySA+, GICSP, CND, GSEC, Security+ CE, SSCP, CISA, GCED, GCIH

Security Clearance

Requires U.S. Citizenship and an active government security clearance.

Equal Opportunity Employer

All qualified candidates will be considered without regard to legally protected characteristics.

Expression of Interest

By applying to this job, you are expressing interest in this position and could be considered for other career opportunities where similar skills and requirements have been identified as a match. Should this match be identified, you may be contacted for this and future openings.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

ISSO/ISSE- Hybrid (Philadelphia) with Security Clearance
ISSO/ISSE- Hybrid (Philadelphia) with Security Clearance

Ishpi Information Technologies, Inc. (ISHPI) • Philadelphia

On-site
USD 95,000 - 140,000
Information Systems Security Engineer
Information Systems Security Engineer

Data Intelligence LLC • Philadelphia

On-site
USD 100,000 - 130,000
Medical, dental and vision insurance
401k
PTO
+1
Information Systems Security Officer
Information Systems Security Officer

Future Technologies Inc. • King George (VA)

On-site
USD 105,000 - 140,000
Information System Security Engineer (ISSE) II - Hybrid
Information System Security Engineer (ISSE) II - Hybrid

Ishpi Information Technologies, Inc. (ISHPI) • Philadelphia

On-site
USD 70,000 - 100,000
Senior Information Systems Security Officer (ISSO)
Senior Information Systems Security Officer (ISSO)

Independent Software, Inc. • Maryland

On-site
USD 100,000 - 130,000
Information System Security Officer (ISSO)
Information System Security Officer (ISSO)

Ara • Albuquerque (NM), Northern (KY)

Hybrid
USD 95,000 - 130,000
Information System Security Engineer (ISSE) II (on-site)
Information System Security Engineer (ISSE) II (on-site)

Ishpi Information Technologies, Inc. (ISHPI) • Philadelphia

On-site
USD 90,000 - 120,000
Information Systems Security Officer (Technical ISSO / RMF Assessor)
Information Systems Security Officer (Technical ISSO / RMF Assessor)

Peraton • Riverdale Park (MD)

On-site
USD 112,000 - 179,000
Heavily subsidized employee benefits
25 days of PTO annually
Eligibility for bonus plan
Information Systems Security Engineer ISSE
Information Systems Security Engineer ISSE

Precise Systems • Town of Texas (WI)

On-site
USD 80,000 - 100,000
Comprehensive employee benefits
Equal Opportunity Employer
Information System Security Officer (ISSO)
Information System Security Officer (ISSO)

Astrion • United States

On-site
USD 90,000 - 120,000