Information Systems Security Officer ensuring compliance with RMF requirements for Dept. of Commerce systems at CGS. Involving security oversight activities, assessments, and risk management.
Responsibilities
Conduct security assessment, and information system security oversight activities in accordance with NIST 800.53 that support systems from the perspective RMF requirements.
Review systems to identify potential security weaknesses and recommend improvements to amend vulnerabilities, implement changes, and document upgrades.
Maintain responsibility for managing cybersecurity risk from an organizational perspective.
Identify organizational risks, prioritize those risks, and maintain a risk registry for escalating and presenting those risks to senior leadership.
Provide security guidance and IS validation using the National Institute of Standards and Technology (NIST) RMF, DoC, and local security policies.
Provide configuration management (CM) recommendations for information system security software, hardware, and firmware and coordinating changes and modifications with the ISSM, Security Control Assessor (SCA), and Authorizing Official (AO).
Maintain vulnerability scanning tool compliance, such as HBSS or ACAS, and patch management, such as IAVM to ensure IT staff pushes patches to all systems in an effort to maintain compliance with all applicable directives, manage system changes, and assess the security impact of those changes.
Support security authorization activities, including transitioning from the legacy Information Assurance Certification and Accreditation Process (DIACAP) to compliance with the DoC RMF.
Provide subject matter expertise for cyber security and trusted system technology.
Apply advanced technical knowledge and analysis of specialized functional areas in task requirements to develop solutions to complex problems.
Research, write, review, disposition feedback, and finalize recommendations regarding cyber security policy, assessment and authorization assessments (A&As), security test and evaluation reports, and security engineering practices and processes.
Requirements
Bachelor’s Degree.
A minimum of five (5) years experience as an Information Assurance (IA) Analyst, ISSE, ISSO, or similar role in ATO package development, including generating security documentation for requirements, security control assessment, STIG and IAVA compliance, Standard Operating Procedures, test results, etc.
eMASS experience.
Professional security certification such as: CCNA Security, CySA+, GICSP, GSEC, CompTIA Security+ CE, SSCP, or higher.
Strong desktop publishing skills using Microsoft Word and Excel.
Experience with industry writing styles such as grammar, sentence form, and structure.
Ability to multi-task in a deadline-oriented environment.
Benefits
Health, Dental, and Vision
Life Insurance
401k
Flexible Spending Account (Health, Dependent Care, and Commuter)
Paid Time Off and Observance of State/Federal Holidays
Director of Information Security leading LiveEO’s global ISMS for compliance and risk governance. Overseeing critical infrastructure security and ensuring adherence to international standards.
Senior Information Security Specialist securing government IT systems in AWS while implementing security measures and providing guidance. Collaborating with teams to enhance security infrastructure and processes.
Vehicle Cyber Security Engineer responsible for security measures in bus systems at Daimler Buses. Conducting risk analyses, developing security concepts, and collaborating with international partners.
Tech Lead for Product Security Testing driving security verification and validation in embedded industrial products. Leading advanced security testing, including penetration testing and fuzzing compliance with IEC 62443 standards.
Cyber Security Project Manager overseeing IT projects focusing on cybersecurity services and solutions. Ensure the quality of documentation and contract compliance while leading technical personnel in Alexandria, VA.
Microsoft Security Engineer at Iver developing and supporting cybersecurity services with a focus on Microsoft security platforms. Collaborating within a team for continuous improvement.
Information Security GRC Program Senior Manager directing security governance, risk, and compliance functions at Kemper. Leading a team to ensure audits, exams, and control frameworks are maintained effectively.
Associate Director ICT Security overseeing the cybersecurity strategy and team leadership at PFH Technology in Dublin. Ensuring compliance and security in Ireland’s healthcare infrastructure.
Senior Consultant focused on ISMS, BCM, and cybersecurity compliance at VICCON GmbH. Leading projects and collaborating with clients to enhance their information security and resilience.