OverviewInformation System Security Officer (ISSO) -Ft. Irwin, California Job Summary:Information System Security Officer (ISSO) with extensive experience supporting classified and unclassified enterprise networks within the U.S. Department of War (DoW)/federal defense environment. Skilled in implementing and maintaining information assurance and cybersecurity controls in accordance with NIST RMF, CNSSI, and DoD/IC directives. Demonstrated expertise in vulnerability management, system hardening, security assessment and authorization (A&A), continuous monitoring, and incident response. Proven ability to collaborate with system owners, engineers, and mission stakeholders to develop secure architectures, author and maintain security documentation (SSP, POA&M, SCTM, etc.), and ensure continuous compliance with government and contractual requirements. Strong communicator with a track record of supporting complex, mission-critical systems and enabling warfighter and national security objectives while managing cyber risk.
ResponsibilitiesResponsibilities:- Conducts regular security assessments and audits on I.T. devices and information system assigned to identify vulnerabilities, security gaps, and non-compliance with security policies and standards in support of U.S. Army's Warfighter Training& Readiness Solutions ( W-TRS) program
- Performs risk analysis to evaluate the potential impact of identified vulnerabilities on the security and operations of training Devices
- Determines the likelihood of a security breach and the potential consequences
- Ensures that all DoD and U.S. Army security policies, procedures, and standards are properly implemented in all training devices
- Prepares for and respond to security incidents involving training devices
- Creates and maintains detailed RMF body of evidence, documentation of all security assessments, audits, incidents, and remediation efforts
QualificationsRequired Qualifications:- Conduct regular security assessments and audits on IT devices / Information Systems to identify vulnerabilities, security gaps, and non-compliance with security policies and standards, using both manual inspections and automated tools to scan for vulnerabilities
- Participate in the Risk Governance process to provide security risks, mitigations, and input on other technical risk. Prepares and presents reports on the security posture to senior management and other stakeholders
- Create and maintain detailed RMF Assess and Authorization (A&A) documentation, incident reports, findings from device / information system examinations, summaries, and other situational awareness information
- Support necessary compliance activities (e.g., ensure that system security configuration guidelines are followed, compliance monitoring occurs)
- Experience with creating / managing plans of actions and milestones (POA&Ms) or remediation plans are in place for vulnerabilities identified during risk assessments, audits, inspections, etc
- ACAS/Nessus vulnerability scans, review audit logs in Splunk to detect suspicious or unauthorized activity, and that all modules are functioning / detecting for HBSS/ TRELLIX
- Stay abreast of the latest security threats, trends, and technologies
- Ability to provide continuous evaluations and improve the security measures in place to address evolving security challenges
- Familiar with all DoD Cybersecurity guidance, NIST Special Publications, and U.S. Army Information Technology / Cybersecurity Regulations
- Overseeing an information security training and awareness program
Preferred Qualifications:- Experience working with DoD / U.S. Army / Federal Government
- Experience with software/tools: ACAS / Nessus, Splunk, ePolicy Orchestrator - HBSS/TRELLIX, SCAP Compliance Checker (SCC), STIG Viewer, eMASS
- Experience as an ISSO
Education/Experience:- High School Diploma or Equivalent with 6+ years of experience or
- A.A. in Engineering, Computer Science, Computer Engineering, Electrical Engineering, Mathematics, or related field with 4+ years of experience or
- B.S. in Engineering, Computer Science, Computer Engineering, Electrical Engineering, Mathematics, or related field with 2+ years of experience or
- Masters in Engineering, Computer Science, Computer Engineering, Electrical Engineering, Mathematics, or related field with 1+ years of experience
Certification(s):- 8140/8570 DoD Certification; Foundation-Intermediate / Information Assurance Manager I (IAM I)
Clearance Required:- Active Secret Clearance of the ability to obatin a Secret clearance within 6 months of hire.