The job duties of the ISSO are as follows: Responsibilities are full time on customers onsite and will cover classified programs and Special Access Programs (SAP). No Telework. Provide subject matter expertise and serve as an advisor on technical matters involving the security of assigned Information Systems. Maintain and develop System Security Plans (SSP) Security Controls Traceability Matrices (SCTM Continuous Monitoring Plans (ConMon) Plan of Actions and Milestones (POA&Ms) and other related Plans Procedures and Guidance. Monitoring and correlating data (e.g. logs events activity etc.) from a variety of sources (e.g. Splunk Trellix STIGs ACAS etc.) to identify and mitigate threats vulnerabilities and non-compliance. Security sustainment activities (Change Management Account Management Media Protection File Transfers etc.) Ensure required cybersecurity controls are implemented and validated to include continuous monitoring actions. Assist in overseeing and managing day-to-day operation of SAP Information Systems. Assist team in Authorization and Accreditation (A&A) process using RMF across the design lifecycle for classified systems obtaining and maintaining Authority to Operate (ATO) and Authority to Connect (ATC). Demonstrate a strong understanding of Networks Cloud and IT system security authorization procedures. |