Serco

Lead Information Systems Security Engineer (ISSE) - Navy Yard - Washington, DC

Serco$108K — $130K *
Aerospace & Defense
8 - 10 years of experience
Job Overview by Ladders

Qualifications

  • Active DoD Secret security clearance required
  • 8570 IAT Level II compliant certification
  • Bachelor's degree in IT, Cybersecurity or related field
  • Minimum 8 years experience in IT or Cybersecurity for DoD
  • Familiarity with EMASS, RMF, ACAS, STIGs
  • Recent RMF and NIST SP 800-53 rev 4 experience
  • Proficiency in at least 2-3 areas like Microsoft SQL, Red Hat Linux, or Cisco

Responsibilities

  • Support CNRNDW ISSM/CIO as lead ISSE for RMF package development
  • Assemble and review documentation for RMF packages
  • Tailor NIST SP 800-53 rev 4 security controls
  • Maintain compliance with NIST SP 800-53 throughout RMF lifecycle
  • Develop Security Assessment Plans according to Navy RMF guidelines
  • Implement and assess security controls and STIGs
  • Coordinate with activities for RMF guidance and status tracking

Benefits

  • Contribute to critical national defense missions
  • Work in a supportive team environment
  • Gain experience with cutting-edge security frameworks
  • Opportunity for career advancement within Serco
  • On-site role provides routine and structure
Full Job Description
Position Description & Qualifications

Are you an ISSE looking for a place where you can make a difference every day? Serco is the place for you! We have an exciting opportunity supporting the United States Navy and our CNIC N6 program at the Navy Yard in Washington, DC - (On-site 5 days a week, Mon-Fri)

CNIC Regional Offices enable improving operational performance and cost reductions through business process definition, analysis, and development of technical capabilities which automate process or improve transparency for analytics and decision making.

This CNIC N6 Lead Information System Security Engineer (ISSE) for the Risk Management Framework (RMF) Assessment and Authorization (A&A) process, is tasked with developing RMF security authorization packages to obtain Authorizations to Operate (ATOs) for various isolated enclaves that support the NDW Region. These enclaves support many different missions, including, but not limited to, Anti-Terrorism/Force-Protection (AT/FP), access control, video monitoring, and mobile radio systems.

This position is contingent upon your ability to transfer & maintain your DoD Secret security clearance.

In this role, you will:
  • Support CNRNDW ISSM / CIO with RMF package development as the lead ISSE.
  • Assemble and review all required documentation as outlined by the ISSM and CNIC for the RMF packages.
  • Tailor security controls out of National Institute of Standards and Technology (NIST) SP 800-53 rev 4 for the systems.
  • Assist with updating policy and documentation along with maintaining compliance with NIST SP 800-53 rev 4 throughout the RMF lifecycle.
  • Develop a Security Assessment Plan (SAP) in accordance with the Navy RMF Process Guide ver. 3.1 and using the templates provided in the RMF Knowledge Service (KS).
  • Assess and implement security controls, Security Technical Implementation Guides (STIGs), and Assured Compliance Assessment Solution (ACAS) scans in accordance with the SAP.
  • Gather ACAS, STIG, Security Content Automation Protocol (SCAP) files, and other related package artifacts and report any discrepancies to the program.
  • Build risk assessment report (RAR) incorporating all findings discovered in testing and documenting an analysis of each finding.
  • Verify traceability between system authorization data flow, boundary diagrams, Hardware, Firmware, Software, Ports, Protocols and Services (PPS) lists, and ACAS scan.
  • Update and help implement the status of all security controls, enhancements, and control correlation identifiers (CCIs) in eMASS.
  • Make data entries into eMASS record for assigned systems and track RMF process timelines.
  • Prepare for and conduct RMF-related briefings at meetings with internal and external representatives.
  • Interact frequently with internal personnel and outside representatives at various levels.
  • Assist in developing schedules and plans of actions and milestones (POA&M) for producing deliverable products and reports within customer-directed timelines.
  • Coordinate with field activities, obtaining statuses and providing RMF guidance for all CNIC CNRNDW packages.


To be successful in this role, you will have:
  • An active DoD Secret security clearance
    • U.S Citizenship required
  • 8570 IAT Level II compliant certification
  • A Bachelor's degree in Information Technology, Cybersecurity, Computer Science, or a related discipline
  • Minimum 8 years of combined experience in the following;
    • Experience in an Information Technology or Cybersecurity environment supporting the Department of Defense
    • Experience with EMASS, RMF, ACAS, STIG's, & VRAM
  • Recent experience with the RMF and NIST SP 800-53 rev 4 as an ISSE
  • Recent experience with developing A&A documentation & obtaining ATO's
  • Knowledge of US naval communication suites in areas such as LAN, WAN, and RF paths
  • Familiarity with the DoD Information Technology Portfolio Repository-Navy (DITPR-DON)/DON Application and Database Management System (DADMS) and the requirements for their use
  • Proficiency in at least 2-3 of the following disciplines
    • Microsoft operating systems
    • Microsoft SQL
    • Red Hat Linux
    • Cisco
    • Aruba Wireless
    • Lenel (preferred)

Additional desired experience and skills:
  • 8570 IAM Level III compliant certification

If you are interested in supporting and working with passionate Serco team- then submit your application now for immediate consideration. It only takes a few minutes and could change your career!

About Serco

Serco Group plc is a British company providing public services. It is listed on the London Stock Exchange and is a constituent of the FTSE 250 Index. The company has four divisions: Health, Justice and Immigration, Transport, and Defence, and operates across the UK and Europe, North America, Asia Pacific and the Middle East. Serco primarily provides public services to governments, including the operation of prisons and hospitals, defence and aerospace services, and transport services. The company also provides IT and consultancy services to the public sector. Serco has been involved in a number of controversies, including allegations of overcharging the UK government and mismanagement of contracts.
Learn more about Serco
Size
50,000 employees
Industry
Founded
1988

Similar Jobs

More Jobs at Serco

More Aerospace & Defense Jobs

Find similar Lead Information Systems Security Engineer (ISSE) - Navy Yard - Washington, DC jobs: