Information Assurance II

B.R.S. Inc.
San Antonio, TX, United States
about 2 months ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Working hours
Regular working hours
Job source

Tech stack

Audit Trail Cyber Security Information Systems Databases Identity and Access Management Office Automation Public Key Infrastructure SC Clearance Tenable Nessus Patch Management 3-tier Architectures

Job description

Vista Global Solutions, LLC (VGS) is a government contracting and consulting firm supporting several federal agencies and military installations across the U.S. We are seeking an Information Assurance/Specialist Lvl. III to join our ongoing mission at Joint Base San Antonio.

What You’ll Do:

  • Provide risk assessments and reviews for software and hardware to be deployed on the JBSA sites.
  • Promptly report any suspected or confirmed security breaches or policy violations to the agency’s IA Manager (IAM).
  • Address security incidents and remediate vulnerabilities that are within the DHA address IP space that belong to neighboring networks.
  • Ensure systems will be Information Assurance and Security Compliant with all current configurations in accordance with DHA RMF accredited baselines
  • Perform a Basic Cyber Assessment, using the NIST SP 800-171 DoD Assessment Scoring Template, and enter the results electronically in Supplier Performance Risk System (SPRS) for each covered Contractor information system that is relevant to an offer, contract, task order, or delivery order
  • Analyze and improve system security practices
  • Assist the system owner and ISSO in various aspects of designing, developing, and writing certification and accreditation (C&A) documentation packages, including support of the ATO and its systems and/or environment, including but not limited to POA&M and other artifacts.
  • Follow National Institute of Standards and Technology (NIST) and/or RMF standards in performance of job functions
  • Administer the Government Mission Assurance Category (MAC) Three (MAC3) and Government MAC Two (MAC2); Sensitive but Unclassified office automation environment security features, including but not limited to, access control, malicious code protection, vulnerability and patch management, audit logs and records management, attack sensing and warning for all supporting network, computing, and information components
  • Administer and support DOD, MHS, and DHA IA security compliance reviews including ad-hoc, annual, and quarterly scans, security information requests and certification and accreditation activities
  • Administer and support security reviews of all new or modified systems, devices, and configurations to ensure a consistent security posture
  • Administer all security related documentation including System Security Authorization Agreements (SSAA), recording mitigation strategies, waivers, approvals, ports and protocol registration, and user rights tracking
  • Assist in the detailed investigation and documentation of security incidents as required
  • Support the Government’s directive to maintain and sustain all aspects of CAC login and PKI technology and/or other Government authorized or required two factor identification protocol or system
  • Maintain application approval databases and user rights forms
  • Utilize Government scanning tools, such as Retina, AppDetective, and Assured Compliance Assessment Solution (ACAS) and or Government provided security protocols, including forensics analysis and Intrusion Prevention System
  • Assist Information Systems Security Manager (ISSM) in meeting their duties and responsibilities
  • Implement and enforce all DoD IS and PIT system cybersecurity policies and procedures, as defined by cybersecurity-related documentation
  • Ensure that all users have the requisite security clearances and access authorization, and are aware of their cybersecurity responsibilities for DoD IS and PIT systems under their purview before being granted access to those systems
  • Coordinate with the ISSM to initiate protective or corrective measures when a cybersecurity incident or vulnerability is discovered and ensure that a process is in place for authorized users to report all cybersecurity-related events and potential threats and vulnerabilities to the ISSO
  • Ensure that all DoD IS cybersecurity-related documentation is current and accessible to properly authorized individuals

What You Bring: This position is pending a background check for Secret Clearance)/ Tier 3 in support of your primary duty assignment onsite. Certification requirements to meet IAT III, IAM III. Education requirements are a Bachelor’s degree or equivalent experience and IAM III certifications (CISSP, CASP or CISM)

Requirements

Do you have experience in Vuls?, Do you have a Bachelor’s degree?

Benefits & conditions

Pulled from the full job description

  • Tuition reimbursement
  • Health insurance
  • 401(k) matching
  • Paid time off
  • Vision insurance
  • Dental insurance
  • Flexible spending account, VGS offers a competitive benefits package to include: paid holidays, paid time off including sick and vacation leave, medical, dental and vision insurance, flexible spending accounts, short and long term disability, company paid life insurance, 401(k) with a company match and discretionary profit sharing and tuition reimbursement

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on indeed.com

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

5:30 min

Identifying non-coding software vulnerabilities and organizational risks

Tino Sokic · WWC 2023

3:56 min

Leveraging GitOps for AI auditing and instant rollbacks

Jaroslaw Gajewski Jaroslaw Gajewski · WWC Europe 2026

3:04 min

Database evolution and the funding behind vector databases

Erik Bamberg · LIVE

1:37 min

Leveraging continuous intelligence tracking for rapid vulnerability alerting

Matthew Brady Matthew Brady · WWC Europe 2026

1:09 min

Managing enterprise execution with the Operate runtime

Marcin Makowski Marcin Makowski · WWC Europe 2026

4:01 min

Managing application isolation via pluggable database models

Wei Hu Wei Hu · WWC 2022

Videos

See all

Related articles

See all