Senior ISSO
Sterling, VA
Applications have closed
In a world of technology, people make the difference. We believe if we invest in great people, then great things will happen. At AnaVation, we provide unmatched value to our customers and employees through innovative solutions and an engaging culture.
As an Information Systems Security Officer (ISSO), your responsibilities will include:
•Managing all aspects of an organization's information security system, for classified and unclassified systems, including researching, testing, training and implementing programs designed to safeguard sensitive information from any possible breaches.•Understanding the Risk Management Framework (RMF), and how risk management is executed, what risk means, and how to analyze it.•Spearheading Authority to Operate (ATO) and/or Authority to Proceed (ATP) efforts while making independent recommendations to Government Leads during these processes.•Conducting risk analysis from vulnerability and compliance scans, pen testing results, or other audit activity.•Creating written works to include but not limited to Plan of Action and Milestones, System Security Plans, System Specific Policies and Procedures, Configuration Management Plans, Contingency Plans and Test Results, Business Impact Analyses, and Security Impact Analyses.•Participating in Agile Planning Events to provide technical input.
Work location is Sterling, VA or Rockville, MD, candidate must reside in the commutable area to these locations.
Required Qualifications:
- Active Secret Security Clearance
- Bachelor’s degree and 7+ years work experience or equivalent experience or 10 years related work experience, to include:
- Being a self-starter who’s able to work in both independent and team environments while building work relationships with SMEs across divisions. Additionally, must be comfortable with cyber security and able to brief issues to the customer.
- The ability to articulate and provide a true and accurate status update on government IT systems security posture as well as overall system health to the customer in a clear and concise manner.
- Experience executing the NIST Risk Management Framework (RMF) and applying security practices found in NIST publications. (i.e. SP 800-53, SP 800-30, SP 800-60, FIPS 199, FIPS 140-2, etc.)
- Experience documenting System Security Plans to include security control implementation statements.
- Experience conducting periodic reviews of implementation statements to ensure persistent compliance with applicable government and agency level policies in addition to ISO and NIST standards.
- Experience validating the implementation of security controls within a cloud environment (AWS or Azure).
- Supporting the security assessment and authorization (or ATO) process.
- Analyzing testing results from scans, audits, penetration tests, or other test efforts to determine risk levels.
- Hands-on experience with vulnerability management tools such as Tenable Nessus and Security Center.
- Conducting Continuous Monitoring and maintaining the security posture of IT systems within on-prem, cloud, and hybrid environments.
- Knowledgeable on one or more cloud computing services and technologies including but not limited to: AWS, Microsoft Azure, VMware, etc.
- Familiarization with the Microsoft Office 365 Suite. (i.e. Word, PowerPoint, SharePoint, Excel, etc.)
Desired Qualifications:
- Active Top Secret Clearance
- Cyber program experience within federal customer space a plus!
- Familiarization with Scaled Agile Frameworks (SAFe), agile development principles, and DevSecOps methodologies are a plus!
- Experience with managing vulnerabilities on virtualized IT systems and assets or virtual machines (i.e. VDI and VMware.) is a plus!
- Experience with SAFe Agile tools like Jira, Jira Align, or ServiceNow.
- Certifications such as CISSP, CCSP, AWS, Microsoft Azure, CISA, CAP, and SAFe 6 are highly desired.
About AnaVation AnaVation is the leader in solving the most complex technical challenges for collection and processing in the U.S. Federal Intelligence Community. We are a US owned company headquartered in Chantilly, Virginia. We deliver groundbreaking research with advanced software and systems engineering that provides an information advantage to contribute to the mission and operational success of our customers. We offer complex challenges, a top-notch work environment, and a world-class, collaborative team.
If you want to grow your career and make a difference while doing it, AnaVation is the perfect fit for you!
* Salary range is an estimate based on our InfoSec / Cybersecurity Salary Index 💰
Tags: Agile Audits AWS Azure CCSP CISA CISSP Clearance Cloud Compliance DevSecOps FIPS 140-2 Jira Monitoring Nessus NIST NIST 800-53 Pentesting POA&M Risk analysis Risk management RMF Security assessment Security Clearance Security Impact Analysis SharePoint System Security Plan Top Secret Top Secret Clearance VMware Vulnerabilities Vulnerability management
Perks/benefits: 401(k) matching Career development Competitive pay Health care Insurance Medical leave Team events
More jobs like this
Explore more career opportunities
Find even more open roles below ordered by popularity of job title or skills/products/technologies used.