Information System Security Officer
- Discuss this with your agent
- Open in Claude
- Open in ChatGPT
Role details
Tech stack
Job description
- Proposing, coordinating, implementing, and enforcing information system security policies, standards and methodologies.
- Conducting vulnerability assessments using automated benchmarks and tools such as Assured Compliance Assessment Solution (ACAS), Defense Information Systems Agency (DISA) Security Technical Implementation Guides (STIGs), and Security Content Automation Protocol (SCAP) Compliance Checker.
- Implementing operating systems and network devices security configuration in accordance with Defense Information Systems Agency (DISA) approved Security Technical Implementation Guides (STIGs).
- Performing security control continuous monitoring, reviewing system security plans and associated artifacts, security audits, risk analysis and developing mitigation strategies for DoD information systems.
- Identifying Common Criteria and National Information Assurance Partnership (NIAP) certified technologies and the DISA Approved Products List (APL).
- Preparing certification letters and Memoranda of Agreement (MoA) with system owners for interface and networking implementations.
- Providing guidance on cross-functional cybersecurity efforts, ensuring alignment with organizational and program goals and milestones.
- Collaborating on documentation for Information System Authority to Operate (ATO) decisions, including SSPs, SOPs, POA&Ms, and Knowledge Articles.
- Conducting comprehensive risk assessments and vulnerability analyses to identify and mitigate potential threats to satellite communication infrastructures.
This description outlines the general nature and scope of the role. Additional duties may be assigned as necessary.
Requirements
What You’ll Bring:
- Candidates must meet DoD 8140-M Intermediate level qualification requirements: BS degree in Information Technology, Cybersecurity, Computer Science, or related area of study, required. If a bachelor’s degree is not held, qualified candidates must have a Security+, SecurityX, or other 8140-M Intermediate-level certification. Please upload copies of any relevant IT certifications you hold.
- Demonstrated knowledge of Information Assurance/Cybersecurity (IA/CS) and Risk Management Framework (RMF) DODI 8510.01.
- Experience with security controls and implementation delineated in Committee of National Security Systems Instruction (CNSSI) 1253 and National Institute of Standards and Technology (NIST) Special Publication (SP) 800-53, and the Joint Special Access Program Implementation Guide (JSIG).
- Able to perform vulnerability assessments using Assured Compliance Assessment Solution (ACAS), Defense Information Systems Agency (DISA) Security Technical Implementation Guide (STIG), the Security Content Automation Protocol (SCAP) Compliance Checker, incorporating automated benchmarks.
- Implementing operating systems and network device security configuration in accordance with Defense Information Systems Agency (DISA) approved Security Technical Implementation Guides.
- Performing security control continuous monitoring, security audits, risk analysis and developing mitigation strategies for DoD information systems.
- Identifying Common Criteria and National Information Assurance Partnership (NIAP) certified technologies and the DISA Approved Products List (APL).
Equally Important:
- Ability to build positive, collaborative relationships across teams and with external partners.
- Effective communicator with strong verbal and written skills.
- Proactive, self-directed work style with the ability to operate independently.
- Analytical thinker with proven problem-solving capabilities.
- Highly organized, with the ability to balance competing priorities in a fast-paced environment.
Benefits & conditions
- The anticipated annual salary range for this position is $115,000 - $145,000, commensurate with an individual’s experience, qualifications, and skill set. ASEC is committed to providing fair and equitable compensation. The low end of this salary range is accounting for a candidate that meets or exceeds all of the listed requirements., * 100% employee-owned company. Learn more about our Employee Stock Ownership Plan (ESOP) here !
- Comprehensive benefits package, including 11 paid holidays, medical/dental/vision coverage, HSA/FSA options, disability insurance, and more!
- 401(k) with company match
- Tuition assistance for undergraduate and graduate education
- Veteran-friendly employer
- Thriving employee culture
About the company
ASEC is committed to providing access and reasonable accommodation in its services, activities, programs, and employment opportunities in accordance with the Americans with Disabilities Act and other applicable laws., ASEC offers meaningful, mission-driven work within a culture that supports your professional and personal growth. We partner with our government customers to deliver innovative solutions across engineering, information technology, training, and logistics. Above all, we are committed to doing what’s right for the Warfighter-plain and simple. Explore what makes ASEC different by visiting our website.
Apply for this position
This job is hosted externally. Click below to view the full posting and apply.
Apply on dice.comGood distractions
Talks and stories from around this role — technically off-topic, practically not.
Moments
Explore playlistsVideos
See allRelated articles
See all
Understanding and Mitigating Common Web Vulnerabilities
9 Ways to Make Money Hacking
Dev Digest 134 - Where pixels sing?
Is Software Engineering Over-Saturated?