Information System Security Officer (ISSO)
Public Trust: None
Requisition Type: Regular
Your Impact
Own your opportunity to serve as a critical component of our nation’s safety and security. Make an impact by using your expertise to protect our country from threats.
Job Description
GDIT is your place. You make it your own by embracing autonomy, seizing opportunity, and being trusted to deliver your best every day. We think. We act. We deliver. There is no challenge we can’t turn into opportunity. And our work depends on TS/SCI level cleared Information System Security Officer (ISSO) in MacDill AFB Tampa, FL.
Job Duties:
- Develop and coordinate all authorization documentation associated including the Systems Categorization, Systems Security Plan, and Systems risk assessment
- Support the control assessment, reporting and monitoring processes using the Cyber Security and Assessment Management (CSAM) system
- Assist the component with staying on track with Core Controls and A-123 control assessment schedules
- Work with components to ensure each Risk Based Decisions (RBD’s) has a current Waivers.
- Coordinate with CSS Customer Liaison support, including status of the process and POA&Ms.
- Support and document security controls tests, assist in remediation and ensure that POA&Ms are being appropriately managed.
- Develop or update the Business Continuity and Contingency Plan for the component.
- Assist the components with decisions that affect security of their systems and networks.
- Facilitate preparations for the tri-annual Security Assessment and Authorization (SA&A) component’s Information System.
- Conduct assessments of information systems security requirements, evaluate current security posture and recommend priorities for remediation.
- Review information system infrastructure and application architecture to assess security requirements
- Review existing SA&A documentation, Security Assessment Report and security infrastructure (i.e. IDS, firewalls, vulnerability scan tools, etc.)
- Assess NIST 800-53, Rev 4. Control and document results
- Evaluate and strengthen standard SA&A Documentation
- Perform and document risk assessments, analyzing security vulnerabilities, and the metrics to measure the risks associated with those vulnerabilities;
- Based on the risk profile of the analyzed systems, development and documentation of a Plan of Action and Milestones (POA&M) for mitigating those risks;
- Design and development of comprehensive Systems Security Plan, covering at a high level the infrastructure, policies and procedures which define the systems security profile for the analyzed systems;
- Development of Systems Security Users Guides specific to selected networks, desktop computers, servers and data base systems; Design, development, and validation of System Test and Evaluation (ST&E) reviews for new and/or legacy systems.
- Review and conduct NIST-based Self Assessments, identifying any weaknesses which need to be addressed, and developing a POA&M for each of those weaknesses based on industry best practices.
- Design and development of Initial Privacy Assessment (IPA) and Privacy Impact Assessments (PIAs) for each major Federal Government IT Systems Developing and conducting System Test and Evaluations (ST&Es) and Independent Verification and Validation (IV&Vs) of the security profiles of Federal Government IT Systems
- Conduct OMB A-123 security assessments of Federal Government IT Systems.
Required Skills
- Bachelor’s Degree in Computer Science or related technical discipline, or the equivalent combination of education, technical certifications or training, and work experience
- 8+ years’ experience performing systems security assessments, preparing system security documentation, and/or performing security upgrades for live networks, desktop systems, servers, and enterprise data bases leading to successful certification and accreditation or security authorization of such systems.
- 8+ years’ experience assessing and enhancing IT systems security policies and procedures in response to the regulatory requirements associated with Federal and International standards.
- 8+ years IT Security experience with extensive knowledge in security regulations and security assessments having developed numerous security C&A (or SA&A) and ATO on a range of systems including classified systems
- Strong working knowledge with NIST Special Publications and the NIST SP 800-37 SA using CSAM system
- TS/SCI clearance required and eligibility to obtain/maintain a CI Poly
- Current certification in one or more of the following IT Security disciplines:
- ISACA - Certified Information Systems Auditor (CISA)
- ISACA - Certified in Risk and Information Systems Control (CRISC)
- ISACA - Certified Information Security Manager (CISM)
- ISACA - Certified in Governance of Enterprise IT(CGEIT)
- (ISC)2 - Certified Information Systems Security Professional (CISSP)
- (ISC)2 - Certified Authorization Professional (CAP)
Work Requirements
Years of Experience
8 + years of related experience
* may vary based on technical training, certification(s), or degree
Certification
Certified Information Systems Auditor (CISA) | Information Systems Audit and Control Association (ISACA) - Information Systems Audit and Control Association (ISACA)
Travel Required
None
Citizenship
U.S. Citizenship Required
Recommended Jobs
INTERNET SALES MANAGER
Due to continued growth, Coast Mazda is seeking an Internet Manager to lead our internet sales operations and expand our team of sales associates. We are looking for a motivated, goal-oriented individ…
DIETITIAN
Position Title: DIETITIAN Morrison Healthcare is a leading national food and nutrition services company exclusively dedicated to serving more than 600 hospitals and healthcare systems. Mo…
Receiving Chemist/Sampling Technician (2nd shift)
Our Warehouse Chemical Technician / Receiving Chemist I for our Bartow, FL facility is responsible for working in the facility warehouse to complete tasks associated with receiving and sampling w…
Accounts Payable Specialist -Hybrid Sarasota, FL
Accounts Payable Specialist About Sangoma: At Sangoma, we pride ourselves on delivering audaciously simple value propositions. Our solutions are not just scalable; they’re tailored to meet the di…
Kitchen Supervisor
The Kitchen Supervisor at Liberty Correctional Institution supervises inmates to ensure that meal and food items are prepared in accordance with production plans. In this role, you will train worke…
Staff Software Engineer - Systems Security
About Fortanix: In today's world, where data spreads across various clouds and devices, traditional security measures aren't enough. Businesses need a dynamic approach to defend against constant c…
Beauty Advisor
Sephora is seeking a Beauty Advisor in Orlando, FL, to deliver exceptional client experiences through personalized beauty consultations and expert product recommendations. This part-time position requ…
Critical Care Veterinary Technician, PERC
Are you looking for an opportunity to utilize your full skill set while simultaneously learning new & advanced techniques? If so, Pet Emergency & Referral Center is looking to add YOU to thei…
Client Service Representative
Christian Dior Couture seeks a Client Service Representative for its Miami location. This full-time position involves managing client service functions, including POS systems, inventory control, and c…
Crew Member - 13715 SW 152nd St
Job Description Crew Member perform customer service duties and pizza maker duties. They are responsible for providing quality customer service as well as making our delicious food with pride.…