Security Support Services Specialist
Role details
Job location
Tech stack
Job description
-
Supports the system assess and authorize (A&A) effort, to include assessing and guiding the quality and completeness of A&A activities, tasks and resulting artifacts mandated by governing DoW and DAF policies.
-
Recommends policies and procedures to ensure information systems reliability and accessibility and to prevent and defend against unauthorized access to systems, networks, and data.
-
Conducts risk and vulnerability assessments of planned and installed information systems to identify vulnerabilities, risks, and protection needs.
-
Promotes awareness of security issues among management and ensuring sound security principles are reflected in organizations' visions and goals.
-
Conducts systems security evaluations, audits, and reviews.
-
Recommends systems security contingency plans, incident response and disaster recovery procedures.
-
Recommends and implements programs to ensure that systems, network, and data users are aware of, understand, and adhere to systems security policies and procedures.
-
Participates in network and systems design to ensure implementation of appropriate systems security policies.
-
Assesses security events to determine impact and implements corrective actions.
-
Ensures the rigorous application of information security/cybersecurity policies, principles, and practices in the delivery of all IT services.
-
Will execute Information System Security Officer (ISSO) duties as outlined in DoWI 8500.01, AFI 17-101, AFI 17-1301, and AF 17-1303 for assigned network enclaves.
Requirements
-
This position requires a minimum of eight years experience, of which at least six years must be specialized experience in defining computer security requirements for high- level applications, evaluation of approved security product capabilities and resolution of computer security problems.
-
Extensive knowledge and proficiency with the Risk Management Framework (RMF) and eMASS or XACTA experience to manage ATO packages including Test Results, Artifacts and POA&Ms.
-
Extensive knowledge and proficiency with SNAP and GIAP.
-
Extensive knowledge and proficiency with the Assured Compliance Assessment Solution (ACAS) Vulnerability Scanner.
-
Expert knowledge of STIG and SCAP tools.
-
Expert knowledge and proficiency with Cybersecurity best practices.
-
Expert knowledge and understanding of Federal and DoW Cybersecurity regulations and policies.
Minimum Education:
-
A Bachelor's degree in computer science/systems, information systems/ technology, engineering/engineering technology, software engineering/programming, management, natural sciences, social sciences, mathematics, or business/finance is required.
-
Education and experience requirements may be substituted with:
-
A Master's Degree (in subjects described above) and seven years general experience of which at least five years must be specialized experience.
-
No degree and twelve years general experience of which at least eleven years is specialized.
Required Certification(s):
-
DoWD 8570.01M Information Assurance Technician (IAT) level III baseline certification required.
-
Must have the ability to obtain this certification withing 6 months of hire: (ISC)2 CGRC - Certified in Governance, Risk, and Compliance, 8 + years of related experience
-
may vary based on technical training, certification(s), or degree Certification
CISSP: Certified Information Systems Security Professional - ISC² - ISC²
CCISO: Certified Chief Information Security Officer - EC-Council - EC-Council
CGRC - Governance, Risk and Compliance Certification - (ISC)2 - (ISC)2
CISM: Certified Information Security Manager - ISACA - ISACA Travel Required
Less than 10% Citizenship
Benefits & conditions
- 401K with company match
- Comprehensive health and wellness packages
- Internal mobility team dedicated to helping you own your career
- Professional growth opportunities including paid education and certifications
- Cutting-edge technology you can learn from
- Rest and recharge with paid vacation and holidays
Work Requirements
Years of Experience, The likely salary range for this position is $107,744 - $126,500. This is not, however, a guarantee of compensation or salary. Rather, salary will be set based on experience, geographic location and possibly contractual requirements and could fall outside of this range. Total compensation for international positions varies by tax, social security, and immigration statuses, as well as location. Generally, an international assignment may include allowances, premium uplifts, and/or relocation or transportation benefits, above base salary range noted.