ISSO/Information System Security Officer

UIC Government Services and the Bowhead Family of Companies

Dahlgren (VA)

On-site

USD 130,000 - 150,000

Full time

14 days+
Application generator

Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Job summary

Bowhead is seeking a full-time ISSO in Dahlgren, VA to identify, mitigate, and report on vulnerabilities across DoD networks. You will perform vulnerability scans, analyze findings, and apply host, network, and OS hardening techniques to improve security.

Responsibilities include using DoD analysis tools (ACAS, HBSS), conducting risk assessments, and translating technical findings into actionable risk-reduction steps. A Bachelor’s degree, IAM II, and TS clearance eligibility are required.

Qualifications

  • Bachelor's degree required and 5+ years of relevant experience.
  • IAM Level II certification required.
  • Knowledge of computer networking concepts, protocols, and network security methodologies.
  • Knowledge of network security architecture concepts including topology, protocols, components, and principles (defense-in-depth & zero trust).
  • Knowledge of system, network, and OS hardening techniques.
  • Knowledge of IDS/IPS tools and applications.
  • Knowledge of TCP/IP, DHCP, DNS, and directory services.
  • Knowledge of application vulnerabilities.
  • Knowledge of system administration for Unix/Linux, IOS, Android, Windows.
  • Travel may occasionally be required, but rare.

Responsibilities

  • Conduct vulnerability scans and recognize vulnerabilities in security systems.
  • Use DoD network analysis tools to identify vulnerabilities (ACAS, HBSS).
  • Perform application vulnerability assessments.
  • Identify systemic security issues from vulnerability/configuration data.
  • Share insights about threat environment to improve risk posture.
  • Apply cybersecurity and privacy principles to organizational requirements.
  • Troubleshoot cyber defense infrastructure anomalies and resolve issues.
  • Perform impact/risk assessments.

Skills

Vulnerability scans
ACAS/HBSS
System/Network hardening
Application vulnerability
Threat analysis
Cybersecurity principles
VPN security
Network security
Malware protection
Troubleshooting
Risk assessments

Education

Bachelor's degree
5+ years experience
IAM Level II

Tools

HBSS
ACAS
VPN

Job description

Overview

Bowhead is seeking a skilled full-time ISSO/Information System Security Officer to join our team in Dahlgren, VA. The ideal candidate will have a strong background in computer networking concepts and protocols, as well as network security methodologies. The ISSO will be responsible for identifying and mitigating vulnerabilities in security systems, conducting vulnerability scans, and applying system, network, and operating system hardening techniques.

Responsibilities
  • Conducting vulnerability scans and recognizing vulnerabilities in security systems.

  • Using DoD network analysis tools to identify vulnerabilities (e.g., ACAS, HBSS, etc.).

  • Conducting application vulnerability assessments.

  • Identifying systemic security issues based on the analysis of vulnerability and configuration data.

  • Sharing meaningful insights about the context of an organization’s threat environment that improve its risk management posture.

  • Applying cybersecurity and privacy principles to organizational requirements (relevant to confidentiality, integrity, availability, authentication, non-repudiation).

  • Troubleshooting and diagnosing cyber defense infrastructure anomalies and working through resolution.

  • Performing impact/risk assessments.

Required Skills
  • Skill in conducting vulnerability scans and recognizing vulnerabilities in security systems.

  • Skill in using DoD network analysis tools to identify vulnerabilities (e.g., ACAS, HBSS, etc.).

  • Skill in system, network, and OS hardening techniques (e.g., remove unnecessary services, password policies, network segmentation, enable logging, least privilege, etc.).

  • Skill in conducting application vulnerability assessments.

  • Ability to identify systemic security issues based on the analysis of vulnerability and configuration data.

  • Ability to share meaningful insights about the context of an organization’s threat environment that improve its risk management posture.

  • Ability to cybersecurity and privacy principles to organizational requirements (relevant to confidentiality, integrity, availability, authentication, non-repudiation).Tenable Assured Compliance Assessment Solution (ACAS)

  • Trellix Endpoint Security System (ESS), previously known as McAfee Host Based Security System (HBSS)

  • Skill in applying host/network access controls (e.g., access control list).

  • Skill in using Virtual Private Network (VPN) devices and encryption.

  • Skill in securing network communications.

  • Skill in protecting a network against malware. (e.g., NIPS, anti-malware, restrict/prevent external devices, spam filters).

  • Skill in troubleshooting and diagnosing cyber defense infrastructure anomalies and work through resolution.

  • Skill in performing impact/risk assessments.

  • Skill to develop insights about the context of an organization’s threat environment

  • Skill to apply cybersecurity and privacy principles to organizational requirements (relevant to confidentiality, integrity, availability, authentication, non-repudiation).

  • Other duties as assigned

Qualifications
Required
  • Bachelor's degree required and five (5+) or more years of relevant experience.

  • IAM Level II certification required

  • Knowledge of computer networking concepts and protocols, and network security methodologies.

  • Knowledge of network security architecture concepts including topology, protocols, components, and principles (e.g., application of defense-in-depth & concept of zero trust).

  • Knowledge of basic system, network, and OS hardening techniques.

  • Knowledge of Intrusion Detection System (IDS)/Intrusion Prevention System (IPS) tools and applications.

  • Knowledge of network protocols such as TCP/IP, Dynamic Host Configuration, Domain Name System (DNS), and directory services.

  • Knowledge of application vulnerabilities.

  • Knowledge of system administration, network, and operating system hardening techniques.

  • Knowledge of system administration concepts for operating systems such as but not limited to Unix/Linux, IOS, Android, and Windows operating systems.

  • Travel may occasionally be required, but rare

Preferred
  • Knowledge of cyber threats and vulnerabilities.

  • Knowledge of specific operational impacts of cybersecurity lapses.

  • Knowledge of host/network access control mechanisms (e.g., access control list, capabilities list).

  • Knowledge of cybersecurity and privacy principles and organizational requirements (relevant to confidentiality, integrity, availability, authentication, non-repudiation).

  • Knowledge of network traffic analysis methods.

  • Knowledge of Virtual Private Network (VPN) security.

  • Knowledge of transmission records (e.g., Bluetooth, Radio Frequency Identification (RFID), Infrared Networking (IR), Wireless Fidelity (Wi-Fi). paging, cellular, satellite dishes, Voice over Internet Protocol (VoIP)), and jamming techniques that enable transmission of undesirable information, or prevent installed systems from operating correctly.

  • Knowledge of network access, identity, and access management (e.g., public key infrastructure, Oauth, OpenID, SAML, SPML).

  • Knowledge of system and application security threats and vulnerabilities (e.g., buffer overflow, mobile code, cross-site scripting, Procedural Language/Structured Query Language [PL/SQL] and injections, race conditions, covert channel, replay, return-oriented attacks, malicious code).

  • Knowledge of different classes of attacks (e.g., passive, active, insider, close-in, distribution attacks).

  • Knowledge of application security risks.

Targeted salary range is $130,000 to $150,000 annually based on qualifications and experience.

Physical Demands:

  • Must be able to lift up to 10 pounds

  • Must be able to stand and walk for prolonged amounts of time

  • Must be able to twist, bend and squat periodically

SECURITY CLEARANCE REQUIREMENTS: Must be able to maintain a Top Secret clearance. US Citizenship is a requirement for Top Secret clearance at this location.

Please note that the salary information is a general guideline only. Bowhead considers factors such as (but not limited to) scope and responsibilities of the position, candidate’s work experience, education/training, key skills, internal peer equity, as well as, market and business considerations when extending an offer.

Applicants may be subject to a pre-employment drug & alcohol screening and/or random drug screen, and must follow UIC’s Non-DOT Drug & Alcohol Testing Program requirements. If the position requires, an applicant must pass a pre-employment criminal background history check. All post-secondary education listed on the applicant’s resume/application may be subject to verification.

Where driving may be required or where a rental car must be obtained for business travel purposes, applicants must have a valid driver license for this position and will be subject to verification. In addition, the applicant must pass an In-house, online, driving course to be authorized to drive for company purposes.

UIC is an equal opportunity employer. Ukpeaġvik Iñupiat Corporation (UIC) considers all applicants for employment without regard to race, color, religion, creed, sex, sexual orientation, gender or gender identity, pregnancy, national origin, age, disability, military/veteran status, marital status, genetic information, or any other legally protected status EOE/D/V. Pursuant to The Alaska Native Claims Settlement Act 43 U.S.C. Sec. 1601 et seq., and subject to other state and federal requirements, UIC and its subsidiaries may legally grant certain preference in employment opportunities to UIC Shareholders and their Descendants. Please view Equal Employment Opportunity posters here .

The contractor will not discharge or in any other manner discriminate against employees or applicants because they have inquired about, discussed, or disclosed their own pay or the pay of another employee or applicant. However, employees who have access to the compensation information of other employees or applicants as a part of their essential job functions cannot disclose the pay of other employees or applicants to individuals who do not otherwise have access to compensation information, unless the disclosure is (a) in response to a formal complaint or charge, (b) in furtherance of an investigation, proceeding, hearing, or action, including an investigation conducted by the employer, or (c) consistent with the contractor's legal duty to furnish information. 41 CFR 60-1.35(c)

UIC Government Services (UICGS / Bowhead) provides innovative business solutions to federal and commercial customers in the areas of engineering, maintenance services, information technology, program support, logistics/base support, and procurement. Collectively, the fast-growing Bowhead Family of Companies offers a breadth of services which are performed with a focus on quality results. Headquartered in Springfield, VA, we are a fast-growing, multi-million-dollar company recognized as a top Alaska Native Corporation providing services across the Department of Defense and many federal agencies. Bowhead offers competitive benefits including medical, dental, vision, life insurance, accidental death and dismemberment, short/long-term disability, and 401(k) retirement plans as well as a paid time off programs for eligible full-time employees. Eligible part-time employees are able to participate in the 401(k) retirement plans and state or contract required paid time off programs.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Senior Data Scientist
Senior Data Scientist

UIC Government Services and the Bowhead Family of Companies • Saint Inigoes Shores (MD)

On-site
USD 90,000 - 150,000
Medical benefits
401(k) retirement plans
Paid time off
Journeyman Security Specialist (SAP) (STO)
Journeyman Security Specialist (SAP) (STO)

UIC Government Services and the Bowhead Family of Companies • Dahlgren (VA)

On-site
USD 100,000 - 110,000
Mechanical Engineer - Test and Evaluation
Mechanical Engineer - Test and Evaluation

UIC Government Services and the Bowhead Family of Companies • King George (VA)

On-site
USD 75,000 - 110,000
Field Programmable Gate Array (FPGA) Engineer
Field Programmable Gate Array (FPGA) Engineer

UIC Government Services and the Bowhead Family of Companies • Dahlgren (VA)

On-site
USD 110,000 - 130,000
Medical, dental, vision
401(k) retirement plans
Paid time off
Maintenance & Repair Worker I
Maintenance & Repair Worker I

UIC Government Services and the Bowhead Family of Companies • Dahlgren (VA)

On-site
USD 29,000 - 39,000
Program Management Specialist, Program Manager, Senior
Program Management Specialist, Program Manager, Senior

UIC Government Services and the Bowhead Family of Companies • Patuxent Highland (MD)

On-site
USD 110,000 - 160,000
Interdisciplinary Engineer ($5,000 Sign-On)
Interdisciplinary Engineer ($5,000 Sign-On)

UIC Government Services and the Bowhead Family of Companies • Juneau (AK)

On-site
USD 90,000 - 135,000
Program Operations Manager
Program Operations Manager

UIC Government Services and the Bowhead Family of Companies • White Plains (MD)

Hybrid
USD 120,000 - 145,000
Administrative Assistant Junior
Administrative Assistant Junior

UIC Government Services and the Bowhead Family of Companies • Patuxent Highland (MD)

On-site
USD 38,000 - 52,000
Medical Insurance
Dental Insurance
Vision Insurance
+4
Program Manager
Program Manager

UIC Government Services and the Bowhead Family of Companies • Saint Inigoes Shores (MD)

On-site
USD 100,000 - 175,000