Senior Information System Security Officer

B CORE LLC
McLean, United States of America
2 days ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Working hours
Regular working hours
Languages
English
Experience level
Senior
Compensation
$ 235K

Job location

McLean, United States of America

Tech stack

Microsoft Windows
Amazon Web Services (AWS)
Confluence
JIRA
Azure
Bash
CentOS
Cloud Computing
Configuration Management
Communications Protocols
Computer Security
Information Systems
Elasticsearch
Information Security Management
Networking Hardware
Intrusion Detection Systems
Python
Lightweight Directory Access Protocols (LDAP)
Network Architecture
Citrix Systems
NMap
Open Source Technology
Powershell
Red Hat Enterprise Linux - RHEL
TCP/IP
Computer Networking Systems
In-Plane Switching (IPS)
Information Technology
Nessus
Nexpose
Splunk
Cisco networks
VMware

Job description

Do you want to join a team that is building tailored technical solutions to modernize our government's mission and our client's business? Do you have a desire to change how people work? Are you interested in helping to protect our nation's cyber interests? Join our growing team supporting customer missions as a Senior Information System Security Officer in Tysons, Virginia ., Members of the ISSO team support the assessment and authorization (A&A) process for information systems. The successful candidate will have requisite cyber security experience with methods and tools used to improve the security posture of critical systems such as identifying risks, vulnerabilities, anomalies, patching, auditing, automation, security hardening, best practices, and evaluating system changes. In addition, the candidate will collaborate with developers and engineers on projects to create a secure hybrid-cloud environment.

Requirements

  • Minimum of 10+ years applied experience or relevant degree plus 5 years of cybersecurity expertise with demonstrated ability to successfully shepherd IT projects of varying types through the authorization lifecycle.
  • Strong verbal and written communication/cooperation within a team context.
  • Supported control implementation assessment and reporting and monitoring processes using cyber security and assessment management systems.
  • Understanding of perimeter controls (firewalls), access control mechanisms, and network architectures.
  • Demonstrated essential understanding of methods for hardening operating systems (e.g., CentOS, RedHat, Windows).
  • Skilled with and/or demonstrated technical aptitude with vulnerability and risk assessment tools such as Elasticsearch or Splunk SIEMs, Rapid7 Nexpose, and IDS/IPS monitoring and alerting.
  • Strong understanding of methodologies for researching and documenting software and hardware vulnerabilities.
  • Experienced working closely with stakeholders, developers, and external teams, including customer security manages (ISSMs), organizational leadership, and key personnel.
  • Applied experience with the customer's assessment and authorization tracking tools.
  • Knowledgeable regarding Common Control Provider (CCP) requirements and methodology.
  • Demonstrated knowledge and experience with networking topologies and hardware, including commonly used/referenced network devices, IDS and IPS, etc.
  • Applied experience with open-source and commercial tools and systems such as nmap, Nessus, Rapid7, Splunk, Nipper, Elasticsearch, Jira, Confluence, Cisco, VMware, Citrix, or Trellix, as well as GOTS tools used by the customer.
  • Demonstrated experience with the design and implementation of defense-in-depth solutions.
  • Skilled in cross-team collaboration and effective communication to fulfill specific authorization requirements.
  • Demonstrated skill documenting processes and procedures in CONOPS and system security, contingency, configuration management and other plans.
  • Demonstrated ability to facilitate customer concurrences required for risk-based decisions, especially those requiring waivers.
  • Experience assisting the customer with decisions impacting the security posture and compliance of their systems and networks with requirement as documented in NIST 800-53 and its revisions.
  • Extensive familiarity with communications protocols, such as TCP/IP, UDP, HTTP/S, SSH, LDAP, etc.
  • Demonstrated experience with security, monitoring and auditing cloud-based technologies, products and services, such as Amazon Web Services (AWS) or Microsoft Azure.
  • Knowledge of the customer's organization, their network systems and infrastructure, processes and procedures, and request and approval tools.
  • Ability to work within fast-paced customer environments.

Desired Qualifications:

  • Experienced in scripting/program languages such as Bash, PowerShell, or Python .

Benefits & conditions

  • The expected salary range within the Washington, DC metropolitan area is: $210,000 - $235,000. Final compensation is unique to each individual and will be determined based on factors such as experience, education, geographic location, and contractual requirements. This is not a guarantee.
  • Benefits include Health/Dental/Vision, 401(k), Paid Time Off, STD/LTD/Life Insurance/Voluntary Life Insurance, Stipends, Referral Bonuses, and more.

About the company

At Bcore, our strength comes from how we deliver impact to the mission. Whether it's architecting critical IT solutions, producing actionable intelligence, or developing cutting edge technology, we succeed because of the expertise, collaboration, and agility of our teams. Our Mission Services division combines enterprise IT, cloud solutions, DevSecOps, systems engineering, software development, and operational support. Bcore accelerates decisive advantage for warfighters and intelligence professionals by fusing human insight, rapid-fire engineering, precision-measured outcomes, and relentless grit into mission-ready solutions.

Apply for this position