Information Systems Security Officer

JMA Resources, Inc.
Mechanicsburg, PA, United States
3 months ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Experienced
Experience required
3 years minimum
Compensation
$83,000.0 - $115,000.0
Working hours
Shift work
Job source

Tech stack

Comptia Cloud+ CompTIA Security+ Cyber Security Information Systems Disaster Recovery Federal Information Processing Standards (FIPS) Intrusion Detection Systems Software Vulnerability Management Firewalls (Computer Science) SC Clearance Information Technology Vulnerability Analysis

Job description

JMA Resources is seeking an Information Systems Security Officer to support Risk Management Framework activities for information systems within a Navy environment. This role supports security control implementation, assessment, documentation, vulnerability management, and remediation activities. The ISSO works closely with PMO, Operations, and IT Security teams to support Authorization and Accreditation efforts, POA&M management, and ongoing security compliance., * Support security control implementation, testing, and assessment activities in alignment with the Risk Management Framework.

  • Assist with reviewing, documenting, mitigating, and closing system vulnerabilities through the appropriate change control and remediation processes.
  • Support Authorization and Accreditation activities, including security requirements review, documentation support, and package preparation.
  • Review, update, and maintain RMF cybersecurity documentation, including documentation related to POA&Ms, security controls, assessment results, and remediation activities.
  • Perform vulnerability risk analysis based on deficiencies identified during testing, scanning, or assessment activities.
  • Use IA tools, scanners, and security technologies to help evaluate the security posture of systems or enclaves.
  • Coordinate with PMO, Operations, and IT Security teams to support A&A activities and POA&M remediation.
  • Prepare or contribute to security assessment reports that document assessment results, findings, risks, and recommended corrective actions.
  • Support planning and coordination for incident response, business continuity, disaster recovery, vulnerability reporting, and threat reporting processes.
  • Write, edit, and maintain IT security documentation in alignment with applicable federal and DoD cybersecurity requirements.
  • Carry out other related duties as assigned, demonstrating flexibility and adaptability in meeting evolving client, platform, and company needs.

Requirements

Do you have experience in Vuls?, * Current or ability to obtain a Department of Defense (DoD) Secret Clearance is required. Note: To obtain a security clearance, you must be a U.S. citizen and meet the 13 adjudicative guidelines., * 3 or more years of experience supporting DIACAP and/or RMF activities, with RMF experience preferred.

  • Experience supporting RMF testing, analysis, and documentation needed to complete RMF package submissions.
  • Experience performing vulnerability risk analysis based on deficiencies identified during RMF testing or security assessments.
  • Experience using IA tools and scanners to evaluate the security posture of a system or enclave.
  • Experience with Enterprise Mission Assurance Support Service, or eMASS.
  • Familiarity with federal IT security standards and guidance, including FISMA, FIPS, NIST Special Publications, and NIST SP 800-37.
  • Understanding of the RMF process in accordance with the Navy RMF Process Guide.
  • Current certification in at least one of the following, as required by contract: CAP, CND, CompTIA Cloud+, GSLC, or CompTIA Security+.
  • Strong technical writing skills, including the ability to prepare, review, and maintain security documentation.
  • Strong verbal and written communication skills.
  • Strong problem-solving skills and attention to detail.
  • Ability to work independently and collaboratively with technical and program teams.

Preferred Qualifications:

  • Degree in Computer Science, Cybersecurity, Information Technology, or a related field.
  • Experience supporting Navy cybersecurity, A&A, or RMF activities.
  • Experience with security technologies such as firewalls, intrusion detection systems, intrusion prevention systems, and vulnerability assessment tools.
  • Experience supporting POA&M development, tracking, remediation, and closure.

Creating an Environment of Respect and Opportunity

Benefits & conditions

Pulled from the full job description

  • Health insurance
  • 401(k) matching
  • Paid time off
  • Vision insurance
  • Dental insurance
  • Paid holidays
  • Flexible schedule, * Position: Full Time
  • Work Arrangement:
  • Hybrid - On-site for a week each quarter at our client site in Mechanicsburg, Pennsylvania.
  • Travel Requirements: Is required.
  • Location Preference: Must reside within a 50-mile radius of Mechanicsburg, Pennsylvania, due to the on-site/hybrid nature of the position.
  • Work Hours: A typical workday consists of eight hours, totaling a forty-hour workweek. We understand that there may be times when employees will need to adjust their work hours due to client needs or personal reasons. To help balance these demands, we offer some flexibility in work schedules.

What We Offer:

  • Competitive salary and discretionary bonuses.
  • Comprehensive health benefits, including medical, dental, and vision insurance.
  • Flexible Paid Time Off (PTO) and holidays to help you maintain a healthy work-life balance.
  • Opportunities for professional development and continued learning.
  • Hybrid/remote work arrangement with flexible hours.
  • 401(k) retirement plan with company match.
  • Employee recognition programs and company events.

About the company

JMA Resources participates in E-Verify to confirm the identity and employment eligibility of all newly hired employees.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on indeed.com

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

4:11 min

Introduction to cloud-native application developer security

Micah Silverman · WWC 2022

4:01 min

Finding personal fulfillment in the cybersecurity industry

LIVE

3:44 min

Current industry adoption and future security initiatives

Alexander Allmendinger · LIVE

1:45 min

Transitioning from software development to security roles

Stefania Chaplin · WWC 2022

3:22 min

Transitioning from software engineering to security roles

Anna Oliveira · Coffee With Developers

4:27 min

Embracing a new perspective on mobile cyber attacks

Tom Tovar · WWC 2023

Videos

See all

Related articles

See all