Full-Time

Junior Information Systems Security Officer

RedTrace Technologies Inc

RedTrace Technologies Inc

No salary listed

No H1B Sponsorship

Washington, DC, USA

In Person

Onsite work required; temporary remote rotation available due to COVID-19.

US Citizenship, US Top Secret Clearance Required

Category
IT & Security (1)
Required Skills
Vulnerability Analysis
Requirements
  • Current U.S. Government Top Secret Clearance with SCI and a CI-Polygraph eligibility
  • Must be a U.S Citizen
  • 5+ years serving as an Information Systems Security Officer (ISSO) at a cleared facility
  • Minimum of 5 years of work experience in a computer science or Cybersecurity related field
  • Familiarity with the use and operation of security tools including Tenable Nessus and/or Security Center, IBM Guardium, HP WebInspect, Network Mapper (NMAP), and/or similar applications
  • Hold at least one of the following certifications: Certified Information Systems Security Professional (CISSP) or Global Information Security Professional (GISP), or the CompTIA Advanced Security Practitioner (CASP) or other certifications exemplifying skill sets such as those described in DoD Instruction 8570.1 Information Assurance Management (IAM) Level I proficiency
Responsibilities
  • Ensure the day-to-day implementation, oversight, continuous monitoring, and maintenance of the security configuration, practices, and procedures for each Information System
  • Provide liaison support between the system owner and other IS security personnel
  • Ensure that selected security controls are implemented and operating as intended during all phases of the Information System lifecycle
  • Ensure that system security documentation is developed, maintained, reviewed, and updated on a continuous basis
  • Conduct required IS vulnerability scans according to risk assessment parameters
  • Develop Plan of Action and Milestones (POAMs) in response to reported security vulnerabilities
  • Manage the risks to Information Systems and other agency assets by coordinating appropriate correction or mitigation actions, and oversee and track the timely completion of POAMs
  • Coordinate system owner concurrence for correction or mitigation actions
  • Monitor security controls for agency Information Systems to maintain Security Authorized To Operate (ATO)
  • Upload all security control evidence to the Governance, Risk, and Compliance (GRC) application to support security control implementation during the monitoring phase
  • Ensure that changes to an agency Information System, its environment, and/or operational needs that may affect the authorization status are reported to the system owner and Information System Security Manager (ISSM)
  • Ensure the removal and retirement of Information Systems being decommissioned in coordination with the system owner, ISSM, and ISSR
  • Provide baseline security controls to the system owner, contingent upon the IS’s security categorization, type of information processed and entity type
  • Provide a recommendation to the Authorizing Official, in consultation with the system owner, regarding systems’ impact levels and Information Systems’ authorization boundary
  • Ensure that new entities are created in the GRC application with the security categorization of agency Information Systems
  • Initiate, coordinate, and recommend to the agency Authorizing Official all Interconnection Security Agreements (ISAs), Memoranda of Understanding (MOUs), and Memoranda of Agreement (MOAs) that permit the interconnection of an agency Information System with any non-agency or joint-use Information System
  • Perform an independent review of the System Security Plan (SSP) and make approval decisions
  • Request and negotiate the level of testing required for an Information System with the Enterprise Information Security Section and the agency Authorizing Official
  • Schedule security control assessments in coordination with the system owner
  • Coordinate Information System security inspections, tests, and reviews with the Security and system owner. Submit the final Security Assessment and Authorization (SAA) package to the agency Authorizing Official for a security ATO decision
  • Ensure that the Security ATO Electronic Communication (EC) is serialized into Sentinel under the applicable case file number
  • Advise the agency Authorizing Official of Information System vulnerabilities and residual risks
  • Ensure that all POA&M actions are completed and tested
  • Coordinate initiation of an event-driven reauthorization with the agency Authorizing Official
  • Ensure the removal and retirement of agency Information Systems being decommissioned, in coordination with the System Owner, IS Security Manager and Information System Security Representative
Desired Qualifications
  • A bachelor’s and/or advanced degree in computer science, business management, or IT-related discipline
RedTrace Technologies Inc

RedTrace Technologies Inc

View

Company Size

N/A

Company Stage

N/A

Total Funding

N/A

Headquarters

N/A

Founded

N/A