Job Title: Specialist, Cyber Intelligence (ISSO), L3Job Code: 41273Job Location: Tulsa, OKSchedule: 9/80 (employee's work 9 out of every 14 days - totaling 80 hours worked - and have every other Friday off)
Job Summary: Performs ISSO duties under the guidance of the Information System Security Manager (ISSM) on assigned government-authorized systems. Knowledgeable in information technology and security. Responsibilities include: authoring and maintaining documentation supporting the Assessment & Authorization (A&A) of assigned systems in accordance with the Risk Management Framework (RMF) under the DAAG (Formerly DAAPM) and NISPOM; performing security control assessments as part of the systems' Continuous Monitoring Plan; overseeing configuration management of assigned systems; works with IT organization to develop device and system hardening guides following DISA and NIST guidelines; auditing systems to ensure security posture integrity; conducting periodic hardware/software inventory assessments; identifying system security controls shortcomings and developing POA&Ms; remediate control deficiencies; conducts, documents and reports annual self-assessments; maintaining operational information security posture for a system, program, or enclave; investigating security incidents such as data spills, data integrity, and malicious events; authoring and delivering security education training to range of audience levels.
Essential Functions: • Coordinate with the Information System Security Manager (ISSM) and Facility Security Officer (FSO) on system security compliance.
• Experience completing DISA Security Technical Implementation Guidelines (STIG) checklists and DISA Security Content Automation Protocol (SCAP).
• Experience with Windows Information System Security requirements to include reviewing audit log data utilizing security tools (Log360, Splunk, VSFramework).
- Conducts and manages risk assessments in compliance with NISPOM/DAAPM/DAAG, RMF, JSIG, and NIST 800-series (e.g., 800-53, 800-171) standards.
- Assist FSO and Security Associates to help protect the integrity of legacy closed room and open storage secured areas.
- Contributes to Risk Management Framework (RMF) activities and related system lifecycle documentation (e.g., CONOPS, SOPs, training materials).
- Performs ISSO responsibilities as needed.
- Oversees cyber compliance efforts through self-inspections, customer audits, and system tests to ensure authorized operation.
- Ensures security requirements are addressed in acquisitions, procurements, and outsourcing efforts.
• Perform vulnerability, compliance, and network mapping scans on information systems and work with system administrators to address vulnerabilities (ACAS, Nessus).
• Assist COMSEC Managers with the incorporation of NSA Type 1 devices.
- Understanding of Windows Server infrastructure, ensuring seamless integration and operation with Linux systems.
- Ensure compliance with internal policies and regulatory standards.
Required Qualification (One of the Following with an Active Secret Clearance): - Bachelor's Degree and minimum 4 years of prior relevant experience.
- Graduate Degree and a minimum of 2 years of prior related experience.
- In lieu of a degree, minimum of 8 years of prior related experience.
- Must have active Secret Clearance.
Preferred Additional Skills:- Active CompTIA Security + or obtain 8410 Intermediate (formerly IAT Level II 8570) equivalent within 6 months of hire.
- Previous experience as an ISSO (or equivalent position) overseeing cybersecurity on classified and/or unclassified systems under NISPOM, NIST 800-53 and/or NIST 800-171.
- Experience in creating, conducting, or overseeing internal security assessments.
- Understanding of DAAG (Formerly DAAPM) and various NIST/DoD policies and procedures.
- Experience with Linux based operating systems.
- Experience in Security databases and sites including SIMS and eMASS.
#LI-CD1