Information Systems Security Officer
- Discuss this with your agent
- Open in Claude
- Open in ChatGPT
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Role details
Tech stack
Job description
- Serve as the principal information-security advisor to the System Owner for assigned FCDAS networks and information systems.
- Develop, monitor, and enforce compliance with OSPO, NOAA, Department of Commerce, federal, and FISMA information-security requirements.
- Coordinate development and maintenance of System Security Plans and supporting documentation for the FCDAS Administrative LAN, COSMIC satellite network, and other assigned systems.
- Maintain the security authorization package in the Cyber Security Assessment and Management system.
- Develop, monitor, update, and report plans of action and milestones, mitigation activities, corrective actions, and vulnerability status.
- Plan, execute, and document continuous-monitoring activities, vulnerability scanning, configuration reviews, patching, control assessments, and cybersecurity reporting.
- Manage day-to-day security operations and assist System Owners in developing and enforcing information-system security policies.
- Assess the security impact of proposed hardware, software, network, configuration, and operational changes.
- Coordinate secure-configuration implementation and testing while ensuring changes do not adversely affect satellite operations.
- Support investigation of unusual or unauthorized activity and coordinate with administrators, System Owners, NOAA OCIO, and the NOAA Computer Incident Response Team.
- Prepare security documentation, evidence, artifacts, reports, and technical information for authorization, accreditation, audits, assessments, and incident response.
- Respond to short-notice cybersecurity data calls and ensure security deficiencies are communicated and corrected.
The PWS assigns the ISSO responsibility for SSPs, CSAM authorization records, POA&Ms, continuous monitoring, day-to-day security operations, change control, and security-impact assessments.
Requirements
- A Bachelor’s degree from an accredited college or university.
- Must possess and maintain an appropriate professional cybersecurity certification, such as Certified Information Systems Security Professional (CISSP), consistent with CITR-006 requirements.
Required Experience:
- At least 8 years of progressively responsible cybersecurity, information assurance, information-system security, or risk-management experience.
- At least 5 years of experience supporting federal or similarly regulated information systems subject to FISMA, NIST security controls, Department of Commerce requirements, or comparable cybersecurity frameworks.
- At least 3 years of experience serving as an ISSO, Information System Security Manager, cybersecurity compliance lead, or equivalent security official.
- At least 3 years of experience developing and maintaining System Security Plans, authorization packages, security-control documentation, contingency documentation, and supporting security artifacts.
- At least 3 years of experience using CSAM or a comparable governance, risk, compliance, and authorization-management system.
- At least 3 years of experience creating, monitoring, updating, and closing POA&Ms and coordinating vulnerability mitigation with system owners, administrators, engineers, and operational personnel.
- At least 3 years of experience planning and documenting continuous monitoring, vulnerability scanning, patch management, configuration compliance, or security-control testing.
- At least 3 years of experience conducting security-impact assessments for hardware, software, network, configuration, or operational changes.
- At least 2 years of experience supporting cybersecurity incident investigation or coordinating with an agency incident-response organization.
- Experience securing systems supporting satellite operations, mission systems, operational technology, building controls, physical-security systems, or critical infrastructure is preferred.
- Must meet CITR-006 training requirements and continuing-education requirements established by the applicable certification organization.
- Must be able to obtain and maintain the Department of Commerce suitability determination required for key personnel.
Essential Requirements:
- US Citizenship
- Active Secret Clearance
Salary bands have not yet been determined for this opportunity. I2X Technologies considers factors such as (but not limited to) scope and responsibilities of the position, candidate’s work experience, education/training, key skills, internal peer equity, as well as market and business considerations when extending an offer.
Physical Demands:
The physical demands described here are representative of those that must be met by an employee to successfully perform the essential functions of this job with or without reasonable accommodation.
While performing the duties of this job, the employee will regularly sit, walk, stand and climb stairs and steps. May require walking long distance from parking to work station. Occasionally, movement that requires twisting at the neck and/or trunk more than the average person, squatting/ stooping/kneeling, reaching above the head, and forward motion will be required. The employee will continuously be required to repeat the same hand, arm, or finger motion many times. Manual and finger dexterity are essential to this position. Specific vision abilities required by this job include close, distance, depth perception and telling differences among colors. The employee must be able to communicate through speech with clients and public. Hearing requirements include conversation in both quiet and noisy environments. Lifting may require floor to waist, waist to shoulder, or shoulder to overhead movement of up to 20 pounds. This position demands tolerance for various levels of mental stress.
Benefits & conditions
I2X Technologies is an Engineering and Information Technology Company focused on providing Services to the Federal and State Government. I2X offers a competitive compensation program and comprehensive benefits package to our employees.
About the company
I2X Technologies is a reputable technology services company to the Federal Government. Whether the focus is on space exploration, national security, cyber security, or cutting-edge engineering applications, I2X is ready to offer you the chance to make a real-world impact in your field and for your country. We provide long-term growth and development. Headquartered in Colorado, I2X is engaged in programs across the country and in more than 20 states. Our programs support multiple Federal agencies, including the Department of Defense.
Apply for this position
This job is hosted externally. Click below to view the full posting and apply.
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Good distractions
Talks and stories from around this role — technically off-topic, practically not.
Moments
Explore playlistsVideos
See allRelated articles
See all
9 Ways to Make Money Hacking
Dev Digest 134 - Where pixels sing?
How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again
IT Salaries in UK