Information Systems Security Officer
Mechanicsburg, PA, United States
Full Time Senior-level / Expert Clearance required USD 63K - 147K * est.
Sev1Tech
WE ARE SEV1TECH Serving critical missions for the United States at home and abroad Sev1Tech is a leading provider of IT modernization, cloud, cybersecurity, engineering, fielding, training, and program support services for U.S. government...Overview/ Job Responsibilities
Sev1Tech is looking for an experienced Information Systems Security Officer (ISSO) who can prepare, submit, and monitor accreditation packages through the Risk Management Framework (RMF) process ensuring receipt of Interim Authority to Test (IATT) or Authority to Operate (ATO) in support of the Naval Supply Systems Command (NAVSUP) Ordnance Information System (OIS) program. The ISSO will maintain current operating cybersecurity environment within AWS GovCloud operating environment.
The ISSO will apply their knowledge of DOD Cybersecurity processes and best practices used to secure technical solutions, including applications, systems, architectures, and infrastructures on-site in either Mechanicsburg, PA, or Yorktown, VA.
If position filled in Yorktown, VA, travel to Mechanicsburg, PA, will be required for Program Increment planning sessions, 2 times per year. Additional travel may be required for other meetings.
This critical role will also be responsible for:
- Meeting and maintaining DOD RMF CYBER certification and accreditation requirements, including researching, testing and providing technical information for obtaining required system accreditation.
- Developing Security Requirements Traceability Matrix (STRM), aligning security requirements with the individual components of a system.
- Performing checks of systems and applications for Information Assurance vulnerabilities using approved automated IA tools (ACAS, SCAP-compliant scanners, DISA STIG Viewer, etc.), custom scripts and manual processes (i.e., Security Technical Implementation Guides [STIGS]).
- Monitoring OIS security posture, documenting raw findings in a quick look report, for customer notification. Create and maintain system Plan of Action and Milestones (POA&Ms) of open vulnerabilities and applied mitigations utilizing Department of Defense Enterprise Mission Assurance Support Service (eMASS) tool.
- Supporting the development and documentation of risk assessment results and recommendations using identified threats, applicable vulnerabilities, and likelihood of occurrence within context of risk tolerances
- Monitor all database and application software used in OIS for version change control and nearing/exceeding last date allowed in the Department of Navy Application Database Management System (DADMS).
- Coordinating/interfacing with OIS Technical Team, Defense Information Systems Agency (DISA), IA Staff, and Fleet Cyber Command to document, review, revise, and submit changes related to Ports, Protocols, and Services Management (PPSM), Access Control Lists (ACLs), and Whitelists. This support includes preparing and submitting the registration forms for new requirements.
- Supporting DOD IT Portfolio Repository–DON (DITPR-DON) to support the annual review.
- Providing recommendations for corrective actions and mitigation strategies.
- Producing security risk assessment briefs and reports for delivery to stakeholders and senior management.
- Support the DevSecOps team in implementing Cyber Security requirements to achieve and maintain accreditation and authority to operate within specified timelines.
- Interpret OS, web server, and database scans to facilitate resolving security findings with the DevSecOps team and external teams
- Ensure systems are scanned, patched, and compliant with DoD policy
- Troubleshoot Windows and RHEL security policies
- Support with configurations including CloudWatch logs, registering systems, reporting and manage findings
- Assess systems to determine applicable IA controls based on design, architecture, and data
- Attend risk management and system meetings to provide status updates and take action items
Minimum Qualifications
- Must have DOD Secret level clearance to start
- Certification Requirement: Directive 8570.1/8140 – IAM-1: Security+
- Bachelor’s degree with a minimum of 6 years of relevant experience.
- Experience performing risk assessments and audits.
- Experience using DoD approved tools (ACAS, SCAP-compliant scanners, eMASS, etc.).
- Knowledge of the overall Risk Management Framework and NIST compliance as a security professional.
- Experience presenting to clients or management to present technical and non-technical information to allow key personnel to make informed decisions.
- Experience successfully advising stakeholders through the ATO process.
- Familiarity with information security documents, government orders, notices, and guidelines.
- Experience documenting and maintaining systems running in AWS GovCloud (DoD preferred)
- Ability to work independently to create and update Security Plans, Contingency Plans, and other security documents
- Solid understanding in DoD Cyber Security policies and requirements
Desired Qualifications
- Bachelor’s degree in Engineering, IT, Computer Science, or related field or equivalent
- 10 years’ experience in ISSO capacity
- Experience supporting DoD (Navy preferred) enterprise application transition to the AWS GovCloud (up to IL 6) in a security capacity
- CISSP or equivalent certification
- AWS Certified Security certification
About Sev1Tech LLC
Welcome to Sev1Tech! Founded in 2010, we are proud to be a leading provider of IT modernization, engineering, and program management solutions. Our commitment is to deliver exceptional program and IT support services that empower critical missions for both Federal and Commercial clients.
At Sev1Tech, our mission is clear: Build better companies. Enable better government. Protect our nation. Build better humans across the country. We believe that through innovation and dedication, we can make a significant impact on the communities we serve.
Join the Sev1Tech family, where your potential for greatness is limitless! Here, you will not only achieve remarkable accomplishments but also enjoy a fulfilling and rewarding career progression. We invite you to explore opportunities with us and become part of a team that values your contributions and growth.
Ready to take the next step? Apply directly through our website: Sev1Tech Careers and use the hashtag #joinSev1Tech to connect with us on social media!
For any additional questions or to submit referrals, feel free to reach out to recruiting@sev1tech.com.
* Salary range is an estimate based on our InfoSec / Cybersecurity Salary Index 💰
Tags: ACAS Audits AWS CISSP Clearance Compliance Computer Science DevSecOps DISA DoD DoDD 8140 DoDD 8570 DoD RMF eMASS IAM Monitoring NIST POA&M Risk assessment Risk management RMF SCAP STIGs Vulnerabilities Windows
Perks/benefits: Career development Startup environment
More jobs like this
Explore more career opportunities
Find even more open roles below ordered by popularity of job title or skills/products/technologies used.