Information Systems Security Officer

ECHELON SERVICES LLC

Hanahan (SC)

Sur place

USD 110 000 - 170 000

Plein temps

14 jours+
Générateur de candidature

Démarquez-vous pour ce poste — générez un CV et une lettre de motivation personnalisés en environ une minute.

Passez les filtres ATS

Résumé du poste

Echelon Services, LLC seeks an Information Systems Security Officer (ISSO) in Charleston, SC to manage system security across networks and standalone systems. The role requires RMF expertise, strong knowledge of security controls, and coordination with DoD policy compliance teams.

Responsibilities include maintaining SSP/ATO, performing risk assessments, and leading incident response. The ideal candidate has a BS in CS/InfoSec, 10+ years in information security, and TS/SCI with CI Polygraph.

Qualifications

  • Education: BS degree in Computer Science, Information Security, or related field.
  • Minimum 10 years of experience in information security with focus on system security administration.
  • Experience with DoD RMF is required.
  • Knowledge of Windows, Linux, Unix OS, networks, and databases.
  • Expertise in SCAP, ACAS, and Splunk; DoD 8140 certification desired.

Responsabilités

  • Develop, implement, and maintain system security documentation (ATO, SSP, POAM).
  • Lead incident response planning and execution; coordinate with CSSP.
  • Perform risk and vulnerability assessments; implement mitigations.
  • Ensure SSP reflects architecture and controls; monitor security baselines.
  • Coordinate with stakeholders in security reviews and design reviews.

Connaissances

RMF Knowledge
System Security Administration
Security Tools (SCAP/ACAS)
Splunk
Network Protocols

Formation

BS in Computer Science or Information Security

Outils

SCAP Compliance Checker
ACAS Scans
Splunk

Description du poste

Position Title: Information Systems Security Officer (ISSO). Clearance Requirements: TS/SCI with CI Polygraph. Investigation or CV date within 5 years.


Location: Charleston, SC


Duties and Responsibilities:


System Security Management


  • Experience with security tools and technologies such as vulnerability scanners, intrusion detection systems, security information and event management (SIEM) systems

  • Participate in the implementation of current and future security domains (i.e. DevSecOps, AI, Cloud Computing, etc.)

  • Develop, implement, and maintain system documentation for information system authorization, security management, and continuous monitoring (CONMON) of both networked and standalone information systems (i.e., Authorization To Operate (ATO), System Security Plan (SSP), Plans of Actions and Milestones (POAM), etc.).

  • Ensures the SSP accurately reflects the system architecture, security controls, and operational procedures

  • Conducts regular reviews and updates to the SSP to address changes in system configuration, threats, vulnerabilities, and regulatory requirements

  • Manages and monitors the implementation of security controls as described in the SSP, including technical, administrative, and physical security measures

  • Conducts risk assessments and vulnerability assessments to identify potential security weaknesses

  • Develops and implements mitigation strategies to address identified risks and vulnerabilities

  • Maintains a thorough understanding of system architecture, operating systems, applications, and network infrastructure

  • Ensures system compliance with applicable IC policies and standards

  • Ensure applicable Security Technical Implementation Guides (STIGs) and Security Requirements Guides (SRGs) are completed

  • Participates in system design reviews to ensure security requirements are integrated from the outset


Incident Response


  • Develops and implements incident response plans (IRPs) for assigned systems

  • Investigates security incidents and breaches, analyzing root causes and implementing corrective actions

  • Coordinates with the Cybersecurity Service Provider (CSSP) and other relevant stakeholders during incident response activities

  • Documents and reports security incidents in accordance with DoD policy

  • Participates in incident response exercises and tabletop scenarios to test the effectiveness of the IRP


Configuration Management


  • Ensures that system configurations are maintained in a secure state

  • Monitors system configurations for unauthorized changes

  • Participates in change management processes to ensure security implications are addressed

  • Ensures accurate documentation of system configurations and security baselines


Audit and Assessment


  • Supports internal and external security audits and assessments

  • Prepares documentation and provides evidence to auditors as required

  • Reviews audit findings and implements corrective actions to address deficiencies

  • Conducts regular self-assessments to ensure compliance with security requirements


Continuous Monitoring


  • Implements and maintains continuous monitoring to track the security posture

  • Analyzes security logs and alerts to identify potential security incidents

  • Reports security status to the relevant stakeholders


Coordination and Communication


  • Collaborate with ISSOs, ISSMs, SCAs, system administrators, and developers

  • Communicates security risks and vulnerabilities to relevant stakeholders

  • Present the system security activities in Scrum meetings and forums

  • Provides technical security advice and guidance to system users and administrators


Qualifications


  • Education: BS degree in Computer Science, Information Security, or a related field

  • Experience/Expertise: Minimum of 10 years of experience in information security, with a focus on system security administration

  • Experience with the DoD Risk Management Framework (RMF) is required

  • Knowledge of operating systems (Windows, Linux, Unix), networking protocols, and database management systems.

  • Expertise in security tools such as SCAP Compliance Checker, ACAS Scans, and SPLUNK

  • Certifications: IAT Level II (CISSP,Security+ CE, CCNA Security, etc.)

  • Possess a DoD 8140 Intermediate or Advanced Certification (i.e. CISSP, Security+, etc.)


Echelon Services, LLC is an equal opportunity employer. All applicants will be considered for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, veteran or disability status.

Obtenez votre examen gratuit et confidentiel de votre CV.

ou faites glisser et déposez votre fichier ici.

Similar jobs

Postes similaires à comparer

Information Systems Security Officer
Information Systems Security Officer

Echelon Services, LLC • Charleston (SC)

Sur place
USD 120 000 - 150 000
Information Systems Security Officer
Information Systems Security Officer

Echelon Services • Hanahan (SC)

Sur place
USD 250 000 - 300 000
Information Systems Security Officer
Information Systems Security Officer

Echelongov • Hanahan (SC)

Sur place
USD 250 000 - 300 000
ME00620-ISSO 1
ME00620-ISSO 1

Momentum Engineering, Inc. • Maryland

Sur place
USD 120 000 - 180 000
11 paid holidays
3 weeks PTO
Group medical plan
+4
ME00620-ISSO 1
ME00620-ISSO 1

Momentum Engineering, Inc • Annapolis (MD)

Hybride
USD 120 000 - 165 000
11 paid holidays
3 weeks PTO
Group medical plan
+2
Senior Information Systems Security Officer (ISSO)
Senior Information Systems Security Officer (ISSO)

Independent Software, Inc. • Maryland

Sur place
USD 100 000 - 130 000
Senior Information System Security Officer (ISSO)
Senior Information System Security Officer (ISSO)

Unity Compass • Alexandria (VA)

Sur place
USD 90 000 - 175 000
Information System Security Officer ISSO SCIF
Information System Security Officer ISSO SCIF

EITACIES Inc. • Reston (VA)

Sur place
USD 120 000 - 180 000
Information Systems Security Officer (ISSO)
Information Systems Security Officer (ISSO)

Synergy ECP • Maryland

Sur place
USD 110 000 - 140 000
Information Systems Security Officer
Information Systems Security Officer

Base-2 Solutions, LLC • Maryland

Sur place
USD 120 000 - 160 000