Information Systems Security Officer (ISSO) - Chantilly, VA

ICR LLC
Chantilly, VA, United States
about 1 month ago
Apply on www.indeed.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Experienced
Experience required
2 years minimum
Compensation
$120,000.0 - $145,000.0
Working hours
Regular working hours
Job source

Tech stack

Xacta Configuration Management Cyber Security Information Systems Databases Firmware Identity and Access Management Intrusion Detection Systems Network Switches Network Routers Firewalls (Computer Science) Operating System Security
+3 more
Network Server Servicenow Plan of Action and Milestones

Job description

  • Oversee day-to-day information system (IS) security operations including hardware and software implementations
  • Carry out technical administration of IS in accordance with internal ICR and customer security requirements, primarily Risk Management Framework (RMF)
  • Weekly audit reviews of information systems
  • Team member to assist with data transfers
  • Upkeep, monitor, analyze, and respond to network and security events
  • Document compliance actions within the approved automated compliance tracking system or develop a plan of actions and milestones (POA&M) with the Information Systems Security Manager (ISSM) to address non-compliance in the allotted time frame
  • Ensure systems are operated, maintained, and disposed of in accordance with internal security policies and practices outlined in the security plan
  • Ensure configuration management (CM) for security relevant IS software, hardware, and firmware is maintained and documented in accordance with baseline
  • Ensure all security-related information system documentation is current and accessible to properly authorized individuals
  • Ensure records are maintained for workstations, software, servers, routers, firewalls, network switches, telephony equipment, etc. throughout the information system’s life cycle
  • Evaluate proposed changes or additions to the information system, and advise the ISSM of their security relevance
  • Assist and conduct security IS education
  • Participate in internal/external security audits/inspections; perform risk assessments
  • Inform ISSM on technical IS security matters
  • Assist in conduct of investigations into computer security violations and incidents, reporting as necessary to both the Contractor Program Security Officer (CPSO) and Program Managers
  • Ensure proper protection and / or corrective measures have been taken when an incident or vulnerability has been discovered
  • Communicate, implement and manage a formal Information Security / Information Systems Security Program together with ISSM and CPSO
  • Implement and enforce Information Security Policies and Procedures together with ISSM and CPSO
  • Review and oversee RMF Package authorizations together with ISSM and CPSO

Requirements

  • Current TS/SCI within the last five years with polygraph
  • DoD 8570/8140 IAM II/IAT II certification or higher
  • Knowledgeable of multiple vendor operating systems security requirements
  • Hands-on experience with industry standard Information Assurance tools
  • Experience with obtaining and maintaining system ATOs leveraging the RMF process
  • Hands on auditing and investigation experience

Desired Skills:

  • Hands on experience with ICD 503/JSIG/DAAPM
  • Experience working in environment supporting IC and/or DoD customers
  • Experience implementing new and complex technologies at multiple classification levels within large enterprise environments
  • Experience with RMF database repositories (eMass, ServiceNow, Xacta)
  • Ability to understand information systems equipment configurations (switches, routers, IDS, firewalls, servers, storage arrays, etc.)
  • Preferred Bachelor’s degree from an accredited college in a related discipline, or equivalent experience/combined education, with 2 years of professional experience

Benefits & conditions

  • This position offers a comprehensive benefits package that includes company equity, retirement plan, company-paid health care benefits, flexible paid time off policy, and opportunities for pay increase and bonus during the year.
  • ICR, Inc. considers several factors when extending job offers, including but not limited to candidate’s key skills, relevant work experience, education, training, certifications and location.
  • Employment Status: Full Time

Other Requirements:

  • U.S. Citizenship required
  • A drug screen will be required as part of the hiring process
  • Ability to transfer/obtain/maintain a U.S. government (TS//SCI and/or SAP) security clearance required
  • Remote work is not authorized for this position
  • EOE/AA: ICR is an Equal Opportunity Employer, making decisions without regard to race, color, religion, creed, sex, sexual orientation, gender identity, marital status, national origin, age, veteran status, disability, or any other protected class.
  • Background Check: Candidates who receive a conditional offer of employment will be subject to a background check.

Salary Range: $120,000 - $145,000 This position offers a comprehensive benefits package that includes company equity, retirement plan, company-paid health care benefits, flexible paid time off policy, and opportunity for a raise and bonus during the year. ICR, Inc. considers several factors when extending job offers, including but not limited to candidates’ key skills, relevant work and/or military experience, education, training, certifications and work location. ICR is proud to be an equal opportunity employer and considers qualified applicants for employment without regard to race, color, creed, religion, national origin, sex, sexual orientation, gender identity and expression, age, disability, veteran status, or any other protected factor.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.indeed.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

5:03 min

Navigating new cybersecurity compliance frameworks and laws

Kurt Eder · LIVE

2:19 min

Orchestrating over-the-air firmware updates for vehicle modules

Denis Grahovac · World Congress 2021

3:04 min

Database evolution and the funding behind vector databases

Erik Bamberg · LIVE

4:01 min

Finding personal fulfillment in the cybersecurity industry

LIVE

2:20 min

Utilizing custom firmware for variable torque manipulation

Daniel Meilak Daniel Meilak +1 · World Congress 2026 Europe

4:01 min

Managing application isolation via pluggable database models

Wei Hu Wei Hu · World Congress 2022

Videos

See all

Related articles

See all