Search

Information Assurance Security Specialist

PublishedPublished: 6/14/2022
Technology

Job Description


\n

Job Summary:

\n


\n

We are seeking an experienced Information Systems Security Officer (ISSO) / Cybersecurity Engineer to support Department of Defense (DoD) information systems. The ideal candidate will have a strong background in Information Systems Security, Risk Management Framework (RMF), and security compliance, with experience implementing security controls, managing system authorizations, and ensuring compliance with DoD cybersecurity requirements.

\n


\n

Key Responsibilities:

\n


\n

    \n
  • Implement, monitor, and maintain technical, administrative, and operational security controls.
  • \n

  • Support the Risk Management Framework (RMF) lifecycle, including system authorization and continuous monitoring.
  • \n

  • Develop and maintain RMF documentation, including SSPs, POA&Ms, and Security Assessment Reports (SARs).
  • \n

  • Manage and maintain authorization packages using Xacta and/or DCSA eMASS.
  • \n

  • Apply and validate DISA Security Technical Implementation Guides (STIGs) and remediate Information Assurance Vulnerability Alerts (IAVAs).
  • \n

  • Perform vulnerability assessments using SCAP Compliance Checker (SCC) and review vulnerability scan results.
  • \n

  • Review Windows security event logs and investigate security-related incidents.
  • \n

  • Administer and secure Microsoft Windows Server, Active Directory, and Group Policy Objects (GPO).
  • \n

  • Ensure compliance with NIST SP 800 series, CNSSI 1253, NISPOM Chapter 8, and DoD cybersecurity policies.
  • \n

  • Collaborate with system administrators, ISSMs, and security stakeholders to maintain Authority to Operate (ATO).
  • \n

\n


\n

Required Qualifications:

\n


\n

. • 5+ years of experience in Information Systems Security or Cybersecurity.

\n

• Experience implementing and monitoring technical, administrative, and operational security controls.

\n

• Active Secret Clearance is required.

\n

• CISSP or IAM Level III certification (DoD 8570 compliant).

\n

• Strong knowledge of the following publications and frameworks:

\n

    \n
  • RMF (Risk Management Framework)
  • \n

  • NIST SP 800 series
  • \n

  • CNSSI 1253
  • \n

  • NISPOM Chapter 8 and related security publications
  • \n

  • Familiarity with Xacta and/or DCSA eMASS.
  • \n

  • Experience with Security Technical Implementation Guides (STIGs), Information Assurance Vulnerability Alerts (IAVAs), and SCAP Compliance Checker (SCC).
  • \n

  • Strong knowledge of Microsoft Windows Server, Active Directory, Group Policy Objects (GPO), and Windows System Administration.
  • \n

  • Experience reviewing Windows security event logs, vulnerability scanning
  • \n

\n


Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...