The Charles Stark Draper Laboratory

IS Security Officer 2

Aerospace & Defense
Less than 5 years of experience
Job Overview by Ladders

Qualifications

  • Bachelor's degree in Information Technology or related field.
  • 3-5 years relevant industry experience in Cyber Security.
  • IAM I/IAT II Certification, or greater.
  • Fundamental understanding of common auditing techniques.
  • Experience with auditing systems using native language (PS/BASH) and relevant tools.

Responsibilities

  • Assist the ISSM in their duties and take over in their absence.
  • Ensure system operations, maintenance, and disposal comply with security policies.
  • Conduct periodic system reviews for compliance with security guidelines.
  • Coordinate system changes with the ISSM and corresponding authorities.
  • Monitor system recovery processes to validate proper functioning of security features.
  • Manage configuration baselines for systems and their software.
  • Mentor and coach junior ISSO 1 personnel.

Benefits

  • Programs to improve work-life balance including workplace flexibility.
  • Employee clubs and workshops for personal development.
  • Access to off-site social events to foster team engagement.
  • Discounts to local cultural activities and museums.
  • Opportunities to work at a nationally renowned R&D innovation company.
Full Job Description

Job Description Summary:

The Information System Security Officer 2 (ISSO) supports the continuous monitoring and authorization efforts of multiple classified information systems under the direction of the Information System Security Manager (ISSM). Performing a variety of technical, and non-technical Cyber Security functions. Responsibilities also include physical and environmental protection, personnel security, incident handling, and security training and awareness. In close coordination with the ISSM and ISO, the ISSO plays an active role in monitoring a system and its environment of operation to include developing and updating the SSP, managing and controlling changes to the system, and assessing the security impact of those changes.

Job Description:

Duties/Responsibilities
• Assist the ISSM in meeting their duties and responsibilities. The ISSO shall assume ISSM responsibilities in the absence of the ISSM.
• Ensure systems are operated, maintained, and disposed of in accordance with security policies and procedures as outlined in the security authorization package.
• Attend required technical and security training (e.g., operating system, networking, security management) relative to assigned duties.
• Ensure all users have the requisite security clearances, authorization, need-to-know, and are aware of their security responsibilities before granting access to the IS.
• Conduct periodic reviews of information systems to ensure compliance with the security authorization package.
• Coordinate any changes or modifications to hardware, software, or firmware of a system with the ISSM and AO/DAO prior to the change.
• Formally notify the ISSM and AO/DAO when changes occur that might affect system authorization.
• Monitor system recovery processes to ensure security features and procedures are properly restored and functioning correctly.
• Ensure all IS security-related documentation is current and accessible to properly authorized individuals.
• Conduct Audits and Continuous Monitoring (ConMon) activities using available technical and non-technical processes, reports Audit and ConMon findings, Execute incident response and attends and contributes to status meetings.
• Manage configuration baselines of both hardware and software
• Identify system architecture flaws using industry standard tools (e.g. STIG, SCAP, Nessus) that will be flowed to the ISSM for review.
• Mentors and coaches ISSO 1.
• Performs other duties as assigned.

Skills/Abilities
• Fundamental understanding of common auditing techniques
• Understanding of RMF (NIST SP 800-53, JSIG, DAAG, ICD 503), IR, Vulnerability Management, SCAP, STIG, and Security-Relevant Tools.
• Understands Information Technology basics.
• Awareness of network type designations (e.g. WAN, LAN) and associated infrastructure (e.g. Servers, switches, firewalls).

Education
• Requires a bachelor's degree in Information Technology or a related field.
• Equivalent industry experience may be substituted.
• Possesses an IAM I/IAT II Certification, or greater.

Experience: 
• 3-5 years year relevant industry experience is required,
• Preferred experience with auditing systems using native language (PS/BASH), with tools and basic scripts / queries, and experience working with ISSMs to create and manage POA&am;Ms.

Additional Job Description:

Applicants selected for this position will be required to obtain and maintain a government security clearance.

Current in scope Top Secret security clearance required.

Job Location - City:

Cambridge

Job Location - State:

Massachusetts

Job Location - Postal Code:

The US base salary range for this full-time position is

$82,300.00 - $220,000.00

Our salary ranges are determined by role, level, and location. The range displayed on each job posting reflects the minimum and maximum target salaries for the position across all US locations. Within the range, individual pay is determined by work location and additional factors, including job-related skills, experience, and relevant education or training. Union ranges will be in compliance with the collective bargaining agreement's approved rates by location and role. Your recruiter can share more about the specific salary range for your preferred location during the hiring process.  Please note that the compensation details listed in US role postings reflect the base salary only, and does not include bonuses or benefits.

Our work is very important to us, but so is our life outside of work. Draper supports many programs to improve work-life balance including workplace flexibility, employee clubs ranging from photography to yoga, health and finance workshops, off site social events and discounts to local museums and cultural activities. If this specific job opportunity and the chance to work at a nationally renowned R&am;D innovation company appeals to you, apply now www.draper.com/careers.

About The Charles Stark Draper Laboratory

Draper Laboratory is an American non-profit research and development organization, headquartered in Cambridge, Massachusetts; its official name is The Charles Stark Draper Laboratory, Inc. The laboratory specializes in the design, development, and deployment of advanced technology solutions to problems in national security, space exploration, health care and energy. The laboratory was founded in 1932 by Charles Stark Draper at the Massachusetts Institute of Technology to develop aeronautical instrumentation, and came to be called the MIT Instrumentation Laboratory. During this period the laboratory is best known for developing the Apollo Guidance Computer, the first silicon integrated circuit based computer. It was renamed for its founder in 1970, and separated from MIT in 1973 to become an independent, non-profit organization. The expertise of the laboratory staff includes the areas of guidance, navigation, and control technologies and systems; fault-tolerant computing; advanced algorithms and software systems; modeling and simulation; and microelectromechanical systems and multichip module technology.
Learn more about The Charles Stark Draper Laboratory

Similar Jobs

More Jobs at The Charles Stark Draper Laboratory

More Aerospace & Defense Jobs

Find similar IS Security Officer 2 jobs: