Location: JBAB, National Capital Region
Clearance: TS/SCI (SCI Eligibility required)
Education: BA/BS (or an AA/AS plus anadditional4 years of work experience)
Salary Range: $84 - 94k
Outcomes:
The successful candidate is expected to accomplish the following outcomes during the first year in the position:
- Formally track all tasks, to include assigned by, suspense, status, and comments on all assigned tasks through completion and be prepared to brief upon request.
- Develop digital continuity folders and files that include standard operating procedures, workflows and POC lists to accomplish all tasks.
- Create 2-3 products beyond the client’s requirements that positively impact the client to either increase efficiency, effectiveness, or innovation.
- Establish foundation in AI/ML skills and contribute to AI/ML operationalization and modernization goals and objectives.
- Master position tasks within 60 days and exceed requirements within 90 days.
- Use government provided Generative AI tools on a day-to-day basis to accelerate tasks, research, documentation, analysis, planning, reporting, and problem solving.
- Make recommendations on process improvements and practices that improve quality, speed and/or efficiency.
Responsibilities:
The Information Systems Security Officer (ISSO) SME supports Secretary of the Air Force, Office of Competition (SAF/OCX) providing onsite ISSO process support in support of SAF/OCB Information Systems Security Managers (ISSMs) where Information Systems are located, which may include:the Pentagon, Joint Base Anacostia-Bolling, Fort Washington MD, and San Antonio TX.Primarily, the ISSO SME provides cybersecurity assessment support, STIG and ACAS vulnerability scan coordination, and Enterprise system security documentation development. Per PWS section 1.3.9.1 Information System Security Officer(ISSO),responsibilities include but are not limited to:
- Provide onsite ISSO support to SAF/OCX Information System Security Managers (ISSMs) where Information Systems are located, which may include: the Pentagon, Joint Base Anacostia-Bolling, and Fort Washington MD.
- Coordinate cybersecurity-related processes and activities for SAF/OCX Information Systems and related interfaces. The processes include, but are not limited to, Risk Management Framework (RMF) and system authorization, Cyber Incident Handling, System Life Cycle Management Processes (e.g., Engineering Change and Configuration Management), Vulnerability Management, Malware Protection, Security Assessments/Evaluations/Reviews, Continuous Monitoring, Department of Defense Information Network (DODIN) Connection Approval Process, and Cyber Security Service Provider (CSSP).
- WorkwiththeCyberspaceCapabilitiesBranchandother SAF/OCB Divisionsto provide iterative innovation proposals to be implemented quarterly, by proposing best practices,innovative technology, and/or process improvements that would support the overarchingobjective of managing the Branch’s daily operations more efficiently and effectively across theEnterprise. Proposals may include methods for increasing mission capability, enhancingcustomer experience and improving coordination across the geographically-dispersed enterprise.The Contractor shall provide cost/benefit analysis proposals for Government review for anyrecommendedeffortsthatrequireresources externaltotheirorganization.
- Support, document and advise on cybersecurity assessments, security impact analysis and system authorization of SAF/OCX Information Systems. The format of the documentation will be determined based on the applicable DoW, Air Force and Multi-National directives and guidance. The documentation shall be submitted electronically to the appropriate repository per the DAF ISSM guidance.
Qualifications:
The candidate must have the following qualifications:
- Minimum of five (5)years of related work experience.
- Minimum of three (3) years specificwork-relatedexperience in support of a DoWcomponent.
- Minimum of three (3) years as a staff action officer (e.g. DoW Staff. Service Staff, CCMD staff, Joint Staff, or equivalent) and may be included in years of technical experience above.
- Experience supporting technical security of military systems with at least two of which include experience in coalition operations and at least multi-level security solutions supporting coalition environments or bilateral military information sharing efforts.
- Experience with the following processes:Risk Management Framework (RMF) and system authorization, Cyber Incident Handling, System Life Cycle Management Processes (e.g. Engineering Change and Configuration Management), Vulnerability Management, Malware Protection, and Security Assessments/Evaluations/Reviews, Continuous Monitoring, DODIN Connection Approval Process, and Cybersecurity Service Provider (CSSP).
- Good verbal and written communication.
Certifications required:
- IAM Level II certification (i.e. CAP, CASP+CE. CISM, CISSP, GSLC, or CCISO) (mandatory), CEH desirable.Shall comply with DoW established Directive 8140.
The following qualifications are desired:
- Knowledgeable and skilled in applying Generative AI.
- CompTIA Network+ (desired).
- CompTIA Security+ (desired).
Travel:
Local travel within the NCR and occasional long-distance travel outside the NCR