nInformation Security Systems Officer

RESOURCE MANAGEMENT INC
Patuxent River, MD, United States
14 days ago
Apply on jobs.military.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Compensation
$120,000.0 - $140,000.0
Working hours
Shift work

Tech stack

Cyber Security Firmware Information Security Management Microsoft Visio Subsystems Software Vulnerability Management Information Technology Tools for Reporting Scap Compliance Checker Vulnerability Analysis

Requirements

The applicant must be knowledgeable and proficient in the following:

Benefits & conditions

Resource Management Concepts, Inc. (RMC) provides high-quality, professional services to government and commercial sectors. Our mission is to deliver exceptional management and technology solutions supporting the protection and preservation of the people and environment of the United States of America.\n \n RMC is hiring an\n Information Security Analyst for the role of \nInformation Security Systems Officer (ISSO) to support our \nNavy customer in Patuxent River, MD. The selected applicant will perform a variety of Information Assurance and Risk Management Framework (RMF) activities, including but not limited to:\n \n \n

  • Serving as an ISSO for a designated NAVAIR program.\n
  • Supports and develops Authorization to Operated (ATO) packages for upcoming boundaries that need to be authorized\n
  • Support the systems compliance with DoD security controls, Security Technical Implementation Guides (STIGs), and applicable policies. \n
  • Track and document security-relevant changes to hardware, software, and firmware. Ensures Hardware and software profiles exist for each boundary are compliant.\n
  • Work as a part of a Cybersecurity team while independently accomplish assigned responsibilities.\n
  • Creates Memorandums for the Record (MFRs) for any major changes to the boundaries. Submits these MFRs for review by the DAO. \n
  • Performing duties of the Risk Management Framework (RMF) ISSO role, including:\n

\n

  • Developing RMF authorization packages.\n
  • Performing validation activities for authorization packages.\n
  • Preparing/Updating RMF documentation.\n
  • Preparing IATTs and Use Case MFRs as required to support development and testing.\n
  • Implementing a Cybersecurity Plan.\n
  • Perform weekly validation of auditing to ensure audits have been completed for each boundary\n
  • Performing Cyber Tabletop exercises.\n
  • Performing asset and vulnerability management via VRAM reporting.\n
  • Performing vulnerability assessments and system authorization activities through collaboration with SMEs (System Administrators, Network Admins, Lab Managers, Program Managers, and ISSMs).\n
  • Performing system security assessments.\n
  • Evaluating and reporting software IAW DITPR/DADMS requirements.\n

\n

Requirement is the candidate to be onsite 100% of the time in a classified government facility.\n\n \nRequirements\n \n \n \n

  • A bachelor’s degree and a minimum of three (3) years of relevant experience are required. An associate degree plus four (4) additional years of relevant work experience or High School Diploma plus (6) additional years of relevant work experience may be substituted for a bachelor’s degree.\n
  • The applicant must meet the certification and clearance requirements established IAW the DoD Manual 8570-1M. The applicant must have one of the following certifications to start:\n

\n

  • CAP / CGRC\n
  • SecurityX CE\n
  • GSLC\n
  • CISM\n
  • CISSP\n

\n

An active DoD TOP SECRET clearance is required to start and move to SCI when program requirements dictate. The applicant may be subjected to a security investigation and must meet eligibility requirements for access to classified information. \n

As a Journeyman-level position, the selected candidate will be expected to perform all functional duties independently.\n, At RMC, we’re committed to your career growth! RMC differentiates itself from other firms through its investment in our employees. We invest our resources to train, certify, educate, and build our employees. RMC can offer you a great place to work with a small company feel and give you the experience, tuition assistance, and certifications that will take your career to the next level. We offer Monday to Friday full-time day shift work and can assist in paid relocation. This also includes a competitive paid vacation package with 11 paid federal holidays. Additionally, we also offer high-quality, low-deductible healthcare plans, pet insurance, and a competitive 401K package.\n \n Salary at RMC is determined by various factors, including but not limited to location, a candidate’s specific combination of education, knowledge, skills, competencies, and experience, as well as contract-specific requirements. The salary range for this position is $120,000 - $140,000.\n \n #LI-LL1\n \n PI286631164ā€, ā€œhiringOrganizationā€: {ā€œ@typeā€: ā€œOrganizationā€, ā€œnameā€: ā€œRMC - Resource Management Concepts Inc.ā€}, ā€œjobLocationā€: {ā€œaddressā€: {ā€œaddressCountryā€: ā€œUnited Statesā€, ā€œstreetAddressā€: ā€œNot specifiedā€, ā€œ@typeā€: ā€œPostalAddressā€, ā€œpostalCodeā€: ā€œ20670ā€, ā€œaddressLocalityā€: ā€œPatuxent Riverā€, ā€œaddressRegionā€: ā€œMaryland - MDā€}, ā€œ@typeā€: ā€œPlaceā€}, ā€œindustryā€: ā€œInformationā€, ā€œidentifierā€: {ā€œ@typeā€: ā€œPropertyValueā€, ā€œnameā€: ā€œRMC - Resource Management Concepts Inc.ā€, ā€œvalueā€: ā€œ286631164ā€}, ā€œbaseSalaryā€: {ā€œ@typeā€: ā€œMonetaryAmountā€, ā€œcurrencyā€: ā€œUSDā€, ā€œvalueā€: {ā€œ@typeā€: ā€œQuantitativeValueā€, ā€œvalueā€: ā€œ100000ā€, ā€œunitTextā€

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on jobs.military.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

5:30 min

Identifying non-coding software vulnerabilities and organizational risks

Tino Sokic Ā· World Congress 2023

4:11 min

Introduction to cloud-native application developer security

Micah Silverman Ā· World Congress 2022

2:05 min

Finding product boundaries using lack of cohesion metric grouping

Pratishtha Pandey Pratishtha Pandey Ā· World Congress 2024

2:19 min

Orchestrating over-the-air firmware updates for vehicle modules

Denis Grahovac Ā· World Congress 2021

3:44 min

Current industry adoption and future security initiatives

Alexander Allmendinger Ā· LIVE

2:20 min

Evaluating remote hardware allocations for localized infrastructure constraints

Paul Graham Paul Graham Ā· LIVE

Videos

See all

Related articles

See all