Information System Security Officer

Nabout Leidos
United States
17 days ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Starter
Experience required
1 year minimum
Compensation
$69,550.0 - $125,725.0
Working hours
Regular working hours

Tech stack

Microsoft Windows Active Directory Command-Line Interface Configuration Management CompTIA Security+ Cyber Security Information Systems Computer Networks Databases Linux Information Security Management Security Content Automation Protocol
+5 more
Security Information and Event Management Information Technology SolarWinds (Software) Splunk Vulnerability Analysis

Job description

The Information System Security Officer (ISSO) will be responsible for supporting our Classified Information System Cybersecurity/Information Assurance Program. The Junior ISSO will report to the Information System Security Manager (ISSM) on all aspects of classified information system security compliance.\n \n \nPrimary Responsibilities\n \n \n

  • Assessing and monitoring system compliance, auditing, security plan development and delivering information systems security education and awareness\n
  • Investigating information system security violations and help prepare reports specifying corrective and preventative actions\n
  • Support the creation, review and update of cybersecurity documentation and other technical writing\n
  • Support the auditing of information systems to ensure compliance with security policies and procedures while reporting any discrepancies to the ISSM, ISO or FSO.\n
  • Assisting in the Risk Management Framework (RMF) authorization process by developing and maintaining artifacts for the IS Body of Evidence (BoE).\n
  • Reviewing Configuration Management (CM) requests of all associated hardware, software, and security relevant functions are maintained and documented as part of CCB approval process.\n
  • Sanitization and release of hardware in accordance with security policies or Authorizing Official (AO) guidance.\n
  • Testing, evaluating and application of required technical security controls and periodic inspections of information systems.\n

Requirements

  • DoD 8140/DoD Cyber Workforce Framework (DCWF) work role (for example, CompTIA Security+, CySA+, CISSP, CISM or equivalent), or the ability to otherwise satisfy DoD 8140 qualification requirements through approved education, training, or experience.\n
  • Position Typically requires at least 1-3 years of applicable, related experience in computer-related discipline\n, * Experience working with and/or supporting computer technologies (such as databases, operating systems, computer network hardware, software programs, hardware troubleshooting or electronics)\n
  • Some understanding of security configurations across multiple operating systems in various environments, including Windows, Linux, utilizing Active Directory/Group Policy, Delinea, etc. is required.\n
  • Candidate must be highly organized, self-motivated with excellent documentation and time management skills and\n
  • Must possess the ability to communicate well with others and work with minimal supervision.\n, * Some Experience with IT (Windows, Linux) and/or security related certifications (e.g., ISC2 Certified in Cybersecurity (CCC)certification, CompTIA CySA+ certification, GIAC Certified Incident Handler (GCIH) certification)\n
  • Experience working in DoD classified operating and/or laboratory environments\n
  • Some Experience with various information system security tools that address vulnerability analysis and mitigation. These may include SPLUNK, SolarWinds, Trellix, Tenable, and SCAP.\n
  • Familiarity with implementation of Government directives and policies derived from NIST, STIG, DoD, or other Government Regulatory compliance standards within a professional industry\n
  • Familiarity in the execution of the Assessment & Authorization processes, as defined within the Risk Managed Framework (RMF), eMASS\n
  • Ability to support technical security consultation for complex, cross-domain, heterogeneous classified networked environments in collaboration with internal/external Customers, Information Technology (IT) with Team support\n
  • Familiarity with the execution and management of cyber incident response; preservation, containment, and eradication\n
  • Proficiency in interpreting logs from command line results and SIEM tools (e.g., Splunk, SolarWinds, and Command Line)\n

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on jobs.military.com

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

1:45 min

Transitioning from software development to security roles

Stefania Chaplin · WWC 2022

3:04 min

Database evolution and the funding behind vector databases

Erik Bamberg · LIVE

2:38 min

Establishing comprehensive monitoring and log management

Michael Eder +1 · LIVE

52 sec

Running persistent Linux environments directly on Windows

Ben Breard Ben Breard · WWC 2025

4:01 min

Managing application isolation via pluggable database models

Wei Hu Wei Hu · WWC 2022

3:10 min

Correlating dispersed logs using structured request tracing

Michael Eder +1 · LIVE

Videos

See all

Related articles

See all