Bachelor's degree with 14+ years of related experience; 4 years can substitute for degree.
Experience with ATO packages in on-premises and Cloud environments.
Proficient in Government Risk Compliance (GRC) tools like CSAM, eMASS, and XACTA.
Skilled in developing SOPs, After-Action Reports, and policy documents.
Experience documenting security controls in a System Security Plan (SSP).
Familiar with RMF, Cloud Security Requirements Guide, NIST guidelines, and STIG.
Understanding of DOD requirements for Network Topology and Data Flow Diagrams.
Responsibilities
Document security controls in SSP according to NIST SP 800-53A rev4.
Create Authority to Operate (ATO) packages.
Validate vulnerability and risk assessments for accreditation support.
Utilize inspection tools to audit systems and identify vulnerabilities.
Conduct technical evaluations of information system designs focusing on security.
Review system additions and enhancements, providing recommendations to management.
Determine specifications and compatibility for hardware and software.
Benefits
Opportunity to work with cutting-edge security technologies.
Engagement in high-impact projects supporting national security.
Collaborative work environment with experienced professionals.
Access to ongoing training and professional development opportunities.
Full Job Description
Job Description
SAIC is seeking an ATO ISSO to support USPACOM documenting security controls and creating Authority to Operate (ATO) packages.
JOB DESCRIPTION:
Documenting security controls in SSP per NIST SP 800-53A rev4.
Create Authority to Operate (ATO) packages.
Validate vulnerability/risk assessment analysis to support accreditation.
Utilize various information system inspection tools to audit systems, analyze potential vulnerabilities and identify mitigation approaches.
Conduct technical evaluation of information system designs, focusing on information security aspects and accreditation.
Review completion and implementation of system additions and enhancements and make recommendations to management.
Determine system specifications, input/output processes, and working parameters for hardware and software compatibility.
Assist and review program documentation to include RMF reports, accreditation packages, and security policy guides using NIST 800-53A guidance.
Qualifications
REQUIRED EDUCATION AND EXPERIENCE:
Bachelors and fourteen (14)+ years of related experience; additional four (4) years of experience considered in lieu of degree.
Experience working with Authority to Operate (ATO) packages for both on-premises, and Cloud environments.
Experience using Government, Risk Compliance (GRC) tools (i.e. Cyber Security Assessment and Management (CSAM), eMASS, XACTA, etc.)
Experience developing Standard Operating Procedures (SOP), After-Action Reports, and Policy and Procedure documents.
Experience documenting security controls in a System Security Plan (SSP) and how the controls are being implemented.
Familiar with Risk Management Framework (RMF), Cloud Security Requirements Guide (SRG), National Institute of Standards and Technology (NIST) guides, and Security Technical Implementation Guide (STIG).
Understanding of the DOD requirements for Network Topology, System Security Boundary, and Data Flow Diagrams.
REQUIRED CERTIFICATION:
Must have a current DoD IAM Level I or higher certification (i.e. Security+ CE, Cloud+, CASP+, OR CISSP etc.)
REQUIRED CLEARANCE:
Must have a current Active Secret Clearance with the ability to obtain a TS/SCI Clearance.
Must be a current US Citizen.
About SAIC
Science Applications International Corporation (SAIC) is a technology integrator in the technical, engineering, intelligence, and enterprise information technology markets. SAIC has approximately 26,000 employees and operates in more than 70 countries. The company was founded in 1969 and is headquartered in Reston, Virginia. SAIC provides services to the U.S. government, including the Department of Defense, the intelligence community, and civilian agencies. The company also serves commercial customers in the healthcare, energy, and financial services sectors.