Affinity

4423 ISSO

Affinity$100K — $130K *
Information Technology
8 - 10 years of experience
Job Overview by Ladders

Qualifications

  • BS degree with 8-12 years of relevant experience
  • NGA experience preferred
  • Understanding of ICD-503 and NIST frameworks
  • Experience with XACTA; XACTA 360 preferred; and scanning tools
  • Active CISSP or CISM certification desired

Responsibilities

  • Conduct security risk assessments using various accreditation frameworks
  • Develop and maintain system security plans and related documentation
  • Drive security changes and initiatives through governance boards
  • Perform vulnerability management tasks including assessing and reporting
  • Communicate security matters with internal and client leadership
  • Resolve complex security issues with technical expertise
  • Train and manage user access for information systems

Benefits

  • Flexible work hours
  • Professional development opportunities
  • Comprehensive health insurance options
  • Retirement savings plans with company match
  • Support for certifications and continuing education
Full Job Description
4423 ISSO
4423 | TS/SCI

Job Description:

OVERVIEW:

The ISSO conducts security and risk assessments as required using a range of security accreditation frameworks (e.g., NIST, RMF, Common Criteria, DoD, the Intelligence Community Directives (ICDs)), and works to mitigate risks by applying security controls effectively to achieve an acceptable degree of operational risk. As part of this process, the ISSO performs testing and security assessments to sustain required accreditations. The ISSO promotes the use of secure hardware and software within the systems affected by government and corporate approval standards. The ISSO works to ensure all required security policies and practices are effectively applied to systems and ensures security controls implementing these policies are applied and achieve the proper levels of confidentiality, integrity, availability, and privacy protection throughout the system life cycle.

The ISSO also assists with the execution, analysis, and remediation activities for the vulnerability management program (scanning, assessment, reporting, and mitigation verification) that spans different accreditation entities, three distinct classification domain enclaves (U), (S) and (TS), using the Nessus and Tenable-ACAS vulnerability scanning tools.

GENERAL DUTIES:

  • Develops risk mitigation strategies that contribute to the effectiveness, efficiencies, and performance outcomes for strategic projects, program goals, and business processes.
  • Must be able to quickly respond to the needs for updates and maintenance of security documentation, especially System Security Plans, Plans of Actions and Milestones (POA&Ms); Security Impact Assessment for proposed system changes, and Concept of Operations that identify and explain how each system satisfies its assigned security control baselines.
  • Maintains system security plans and related configuration records in customer Service+ (ServiceNow), XACTA-360 platform, and CIO security tools.
  • Drives necessary security changes through steering groups and control (review) boards to meet Risk Management milestones.
  • Can work independently as well as collaboratively to drive security process improvements, especially to address gaps in meeting customer or security requirements and meet due diligence responsibilities.
  • Provides guidance and engages the program lab team to implement secure software and hardware processes, apply government security standards, and commercial best security practices.
  • Resolves highly complex security problems by applying technical knowledge, conceptualizing, reasoning, and interpretation of requirements.
  • Communicating with Leidos and NGA leadership (internally or client) regarding matters of significant importance to the organization/project.
  • Apply in-depth understanding of information security technical principles, theories, concepts, and their application across a range of programs.
  • Develop and maintain security documentation per NGA/IC/DoD-DISA/NIST/Industry standards and policies.
  • Initiate and coordinate all Assessment and Authorization (A&A) and renewal activities working with the Designated Authorization Officials (DAO or DAOR).
  • Address any Information Assurance or Cybersecurity notices, orders, tasking, or directives as required following the agency operations vulnerability and patch management processes.
  • Measure effectiveness of defense-in-depth architecture and Zero Trust policy implementations against known vulnerabilities.
  • Perform security audits and assessments, including creating, tracking, and assisting in remediation of Plan of Action and Milestones (POA&Ms).
  • Coordinate with System Administrators and others to remediate all vulnerabilities and report results. Track open vulnerabilities and obtain and document approvals while managing POA&M status.
  • Update Security CONOPS and Information Technology Disaster Recovery (ITDR) plans for each Security Plan.
  • Manage security profiles and implementation for systems and services scheduled for Assessment and Authorization (A&A).
  • Work with the Systems Engineers and Administrators, Senior ISSO, ISSMs, Lab Team, and Leidos Corporate Security as required to develop and maintain security plans and associated documentation.
  • Maintain records and documentation on program IT systems, upgrades, patches, and connectivity configurations.
  • Evaluate security solutions and implementation strategies for program IT systems and services and maintain operational security posture of development, integration, and deployed capabilities.
  • Provide training and approve user access and IAA (identification, authorization, and authentication) mechanisms for information systems.


REQUIRED QUALIFICATIONS:

  • BS degree and 8 to 12 years of prior relevant experience to operate within the scope of responsibilities.
  • NGA experience desired.
  • Experience that demonstrates an understanding and application of the ICD-503 and NIST risk management framework.
  • Experience desired with the following systems/platforms/tools: XACTA; XACTA 360 (preferred); HBSS; ACAS; Nessus, SPLUNK.


DESIRED QUALIFICATIONS:

  • Has 3+ years of experience operating, analyzing, and resolving vulnerability scan results using tools such as Nessus, Tenable Security Center, or a comparable commercial or GOTs product.
  • Active Certified Information Systems Security Professional (CISSP) certification or ISACA Certified Information Security Manager (CISM) certification.
  • Intelligence Community experience preferred.


CLEARANCE:

  • Active TS/SCI minimum clearance required


Job Details

City : Gaithersburg, Alexandria, Chantilly

State :

About Affinity

Affinity’s patented technology structures and analyzes millions of data points across emails, calendars, and third-party sources to offer users the tools they need to automatically manage their most valuable relationships, prioritize important connections, and discover untapped opportunities. Affinity uses artificial intelligence to analyze relationship strength and illuminate the best paths to warm introductions. The platform also offers a holistic view of users’ networks in a centralized, automatically updated database without any manual upkeep. Founded in 2014, Affinity is headquartered in San Francisco, California. Affinity has raised $120M to date and is backed by leading investors including Menlo Ventures, Advance Venture Partners, 8VC and MassMutual Ventures. It has over 2,700 customers in 70 countries, including venture capital firms such as Bain Capital Ventures and Kleiner Perkins, private equity firms such as SoftBank Group, investment bankers such as Woodside Capital Partners, financial services firms such as Fidelity Investments, real estate companies such as Tishman Speyer, insurers such as American Family Insurance and enterprises such as Nike, Qualcomm and Twilio. Affinity has been named in Fortune Magazine's Best Workplaces, Inc. Magazine's Best Workplaces and editor's number one pick, the Data Breakthrough Award, BIG Innovation Award and others.
Learn more about Affinity
Size
1,000 employees
Industry
Founded
2014

Similar Jobs

More Jobs at Affinity

  • Affinity
    4424 Cybersecurity Engineer
    $90K — $120K *
    Quantico, VA 22134 (Prince William County)
    Aerospace & Defense
    In-Person
  • Affinity
    4422 UI/UX Engineer
    $90K — $120K *
    Alexandria, VA 22304 (Alexandria City County)
    Information Technology
    In-Person
  • Affinity
    4422 UI/UX Engineer
    $90K — $120K *
    Gaithersburg, MD 20878 (Montgomery County)
    Information Technology
    In-Person
  • Affinity
    4422 UI/UX Engineer
    $90K — $120K *
    Chantilly, VA 20152 (Loudoun County)
    Information Technology
    In-Person
  • Affinity
    4425 VoIP Engineer
    $90K — $120K *
    Quantico, VA 22134 (Prince William County)
    Telecommunications & Hardware
    In-Person

More Information Technology Jobs

Find similar 4423 ISSO jobs: