Cleared Information System Security Officer L3 Lorton, VA
Lorton, VA - USA
Job Summary
ATTENTION MILITARY AFFILIATED JOB SEEKERS - Our organization works with partner companies to source qualified talent for their open roles. The following position is available to Veterans Transitioning Military National Guard and Reserve Members Military Spouses Wounded Warriors and their Caregivers. If you have the required skill set education requirements and experience please click the submit button and follow the next steps. All positions are onsite unless otherwise stated.
Description:
Are you looking to take the next steps in your career as an Information System Security Officer (ISSO) Level 3 Lets chat and see if we are a good match!
Opportunity:
Virtual Service Operations is searching for an Information System Security Officer (ISSO) to join our dynamic team in Lorton Virginia. The Information System Security Officer (ISSO) is responsible for supporting the cybersecurity compliance and risk management activities of DoD information systems operating within classified and/or controlled environments. The ISSO works closely with the Information System Security Manager (ISSM) system administrators engineers program managers and government stakeholders to ensure systems maintain compliance with applicable cybersecurity policies including the Joint Special Access Program (SAP) Implementation Guide (JSIG) DoD Risk Management Framework (RMF) and applicable Intelligence Community (IC) and DoD directives. The ISSO assists in the implementation assessment monitoring and maintenance of security controls to support Authorization to Operate (ATO) activities and continuous monitoring requirements.
Key Responsibilities:
ISSM Support & Core Security Authorities:
- Assist the ISSM in meeting their duties and responsibilities and assume ISSM responsibilities in the ISSMs absence.
- Ensure systems are operated maintained and disposed of in accordance with security policies and procedures outlined in the security authorization package.
- Verify that all users possess the requisite security clearances authorization and need-to-know and are aware of their security responsibilities prior to being granted access to the system.
- Report all security-related incidents to the ISSM.
- Conduct periodic reviews of information systems to verify continued compliance with the security authorization package.
- Serve as a member of the Configuration Control Board (CCB) when designated by the ISSM.
- Coordinate any changes or modifications to system hardware software or firmware with the ISSM and Authorizing Official/Designated Authorizing Official (AO/DAO) prior to implementation.
- Formally notify the ISSM and AO/DAO when changes occur that might affect the systems security authorization.
- Monitor system recovery processes to confirm security features and procedures are properly restored and functioning correctly.
- Maintain an equivalent IAM Level 2 certification based on the DoD 8140 standard.
- Participate in joint agile backlog planning providing feedback to the software development and infrastructure teams on high- and medium-risk items that require Information System Owner approval.
Cybersecurity Compliance & RMF Support:
- Support the implementation and maintenance of cybersecurity requirements in accordance with JSIG RMF and applicable DoD policies.
- Develop maintain and update RMF documentation including:
- System Security Plans (SSPs)
- Security Control Traceability Matrices (SCTMs)
- Plans of Action and Milestones (POA&Ms)
- Security Assessment Reports (SARs)
- Continuous Monitoring Plans
- Ensure security controls are implemented and maintained in accordance with approved security baselines.
- Support security authorization efforts throughout the RMF lifecycle.
Continuous Monitoring & Vulnerability Management:
- Conduct continuous monitoring activities to maintain system authorization.
- Conduct and analyze vulnerability scan results from security tools such as ACAS and SPLUNK.
- Track remediation efforts and validate closure of identified vulnerabilities.
- Assist with risk assessments and development of mitigation strategies.
- Monitor system changes for security impact and support configuration management activities.
Security Operations:
- Coordinate and support security audits inspections and assessments.
- Maintain security-related records reports and artifacts required for compliance reviews.
- Investigate and document cybersecurity incidents and assist with incident response activities.
- Ensure audit records are collected reviewed retained and documented in accordance with security requirements including any identified anomalies.
- Verify proper implementation of system hardening standards and security configurations.
- Work with information system security engineers to ensure secure system configurations.
- Review proposed system changes and evaluate security implications.
- Validate compliance with approved configuration baselines.
- Support enforcement of least privilege and separation of duties principles.
- Provide security guidance to system users and administrators.
Documentation & Reporting:
- Maintain accurate cybersecurity documentation and records ensuring all IS security-related documentation is current and accessible to properly authorized individuals.
- Prepare reports and briefings for program leadership ISSM and government representatives.
- Support internal and external cybersecurity assessments.
- Develop and maintain the Body of Evidence required for audits and authorization activities.
Required Experience:
Unclear Seniority
About Company
VetJobs & Military Spouse Jobs works with our employer partners to source, screen, and move qualified talent to the desktops of the Hiring Managers. Application is a two-step process, so please be patient with the team. When you submit to a position on our site your information will ... View more