Job Type
Full-time
Description
Location: NAS Patuxent River, MDSecurity Clearance Requirement: Active Top SecretTelework Eligible? No, position will be 100% on-siteThe
Junior Information Systems Security Officer (ISSO) will provide critical cybersecurity auditing support to the OASIS team in PMA-205 by reviewing system audit records, identifying and documenting security concerns, and reporting findings to the Information System Security Manager (ISSM) or cybersecurity lead.
Key Responsibilities:- Assisting with reviewing information system audit logs in accordance with established daily, weekly, and monthly schedules.
- Monitoring security logs for unauthorized access attempts, unusual account activity, privilege changes, policy violations, and other suspicious events.
- Documenting audit reviews using approved checklists, tracking systems, and reporting templates.
- Identifying and report audit discrepancies, anomalies, and potential security concerns to the ISSM or senior cybersecurity personnel.
- Escalating suspicious or significant events in accordance with established incident reporting procedures.
- Assisting with tracking audit findings and maintaining supporting documentation through resolution.
- Supporting periodic reviews of user accounts, privileged accounts, and access permissions.
- Verifying that user access aligns with approved roles and authorization records.
- Assisting with reviewing records related to account creation, modification, disabling, and removal.
- Aiding in maintaining audit records to demonstrate compliance with organizational security requirements.
- Supporting internal and external assessments by collecting and organizing requested audit evidence.
- Assisting with preparing recurring audit reports, metrics, and compliance documentation.
- Following established procedures for handling classified, controlled, or sensitive information.
- Safeguarding audit information from unauthorized access, alteration, or disclosure.
- Learning and applying applicable cybersecurity policies, procedures, and regulatory requirements.
- Performing other audit and compliance-related duties as assigned within the scope of the position.
- This position may require up to 5% annual travel.
The job description is not intended to be an all-inclusive list of duties and responsibilities. It is intended to describe the general nature of the position.
Requirements
Education and Experience:- Bachelor's degree in Cybersecurity, Information Systems, Computer Science, Information Technology, Engineering, or a related technical field highly desired. In lieu of degree, 5 years' experience as an IT technician on DoD classified networks is acceptable.
- Minimum 3 years of ISSO or cybersecurity experience, with a strong desire to increase experience that is focused on system/network security auditing.
- Experience with SolarWinds Security Event Manager (SEM), ARM, and related monitoring/auditing tools is preferred.
- Hands-on experience with ACAS, DISA STIGs, SCAP Compliance Checker, and DoD information security standards.
- Familiarity with NIAP/Common Criteria, DoD APL, and DoD/IC cybersecurity directives.
Equally Important:- Ability to build positive, collaborative relationships across teams and with external partners.
- Effective communicator with strong verbal and written skills.
- Proactive, self-directed work style with the ability to operate independently.
- Analytical thinker with proven problem-solving capabilities.
- Highly organized, with the ability to balance competing priorities in a fast-paced environment.
Security Clearance Requirement:- This position requires U.S. citizenship and an active DoD Top Secret clearance. Selected candidate will be subject to a government security investigation and must meet eligibility requirements for access to classified information.
Salary Range:- The estimated salary range for this position will be $120,000 - $135,000 annually, based on an individual's level of experience and skill set. It is our goal at ASEC to provide equitable compensation to all employees.