Job Requirements
Lexington, MA
Secret Polygraph not specified
Mid Level Career (5+ yrs experience)
Salary not specified
Join Premium to unlock estimated salaries
Job Description
Position: ISSO
Location: Lexington, MA (Onsite)
Length: 3+ Year Contract
Active Secret Clearance Required
Job Description:
The ISSO develops and maintains information systems security programs, policies, and procedures for assigned systems and environments. This role supports the security configuration and management of collateral classified and unclassified systems and networks across Linux, Unix, Solaris, Windows, and virtualized environments.
The ISSO monitors system vulnerabilities, ongoing attacks, recovery processes, security incidents, configuration changes, and user activity. This position also supports compliance with Risk Management Framework (RMF) requirements and ensures systems are operated, maintained, and disposed of in accordance with applicable security policies and System Security Plans (SSPs).
Essential Duties and Responsibilities:
• Assist the divisional ISSM and system administrators with developing and maintaining System Security Plans (SSPs) and related artifacts, including Plans of Action and Milestones (POA&Ms), Risk Assessment Reports, and Continuous Monitoring Strategies.
• Assist with security configuration and management of classified and unclassified systems and networks in traditional and virtualized environments.
• Ensure systems are operated, maintained, and disposed of in accordance with RMF security policies and procedures.
• Monitor resources for warnings regarding system vulnerabilities and ongoing attacks.
• Monitor system recovery processes to verify that security features and procedures are properly restored and functioning.
• Support security assessments, tests, reviews, and compliance assessments.
• Take appropriate action when incidents or vulnerabilities affecting classified systems or information are identified.
• Conduct network, system, and application vulnerability scanning, configuration assessments, and remediation activities.
• Apply configuration management policies and procedures governing the authorization and use of hardware and software.
• Maintain configuration management documentation, including change tracking and maintenance logs.
• Collect, analyze, store, and protect system audit records in accordance with applicable policies and procedures.
• Ensure account management documentation is complete and current.
• Develop and maintain POA&Ms identifying system weaknesses, required resources, corrective-action timelines, and mitigation activities.
• Ensure users possess the required security clearances and authorizations and understand their security responsibilities.
• Develop and update SSPs, manage system changes, and assess the security impact of proposed changes.
• Ensure user activity monitoring data is analyzed, stored, and protected in accordance with applicable policies and procedures.
Qualifications:
• Active Secret clearance required.
• Minimum of 3 years of IT security experience in a DoD environment.
• At least 5 years of relevant experience securing Windows, Linux, Unix, Solaris, and virtualized environments.
• Experience securing networks and systems using DISA STIGs and/or Security Requirements Guides (SRGs).
• Knowledge of computer security principles and policies, including RMF, STIGs, the National Industrial Security Program Operating Manual (NISPOM), and the Defense Security Service Assessment and Authorization Manual (DAAPM).
• Experience with vulnerability scanning and auditing tools and processes.
• Excellent written and verbal communication skills.
• Strong organizational and time management skills.
• Security+ certification, or the ability to obtain it within 6 months of hire.
Preferred:
• Security 8570/8141 compliance certification, or the ability to obtain it within 6 months of hire.
• Experience with ACAS, Nessus, Splunk, OpenRMF, or McAfee ePO.
Location: Lexington, MA (Onsite)
Length: 3+ Year Contract
Active Secret Clearance Required
Job Description:
The ISSO develops and maintains information systems security programs, policies, and procedures for assigned systems and environments. This role supports the security configuration and management of collateral classified and unclassified systems and networks across Linux, Unix, Solaris, Windows, and virtualized environments.
The ISSO monitors system vulnerabilities, ongoing attacks, recovery processes, security incidents, configuration changes, and user activity. This position also supports compliance with Risk Management Framework (RMF) requirements and ensures systems are operated, maintained, and disposed of in accordance with applicable security policies and System Security Plans (SSPs).
Essential Duties and Responsibilities:
• Assist the divisional ISSM and system administrators with developing and maintaining System Security Plans (SSPs) and related artifacts, including Plans of Action and Milestones (POA&Ms), Risk Assessment Reports, and Continuous Monitoring Strategies.
• Assist with security configuration and management of classified and unclassified systems and networks in traditional and virtualized environments.
• Ensure systems are operated, maintained, and disposed of in accordance with RMF security policies and procedures.
• Monitor resources for warnings regarding system vulnerabilities and ongoing attacks.
• Monitor system recovery processes to verify that security features and procedures are properly restored and functioning.
• Support security assessments, tests, reviews, and compliance assessments.
• Take appropriate action when incidents or vulnerabilities affecting classified systems or information are identified.
• Conduct network, system, and application vulnerability scanning, configuration assessments, and remediation activities.
• Apply configuration management policies and procedures governing the authorization and use of hardware and software.
• Maintain configuration management documentation, including change tracking and maintenance logs.
• Collect, analyze, store, and protect system audit records in accordance with applicable policies and procedures.
• Ensure account management documentation is complete and current.
• Develop and maintain POA&Ms identifying system weaknesses, required resources, corrective-action timelines, and mitigation activities.
• Ensure users possess the required security clearances and authorizations and understand their security responsibilities.
• Develop and update SSPs, manage system changes, and assess the security impact of proposed changes.
• Ensure user activity monitoring data is analyzed, stored, and protected in accordance with applicable policies and procedures.
Qualifications:
• Active Secret clearance required.
• Minimum of 3 years of IT security experience in a DoD environment.
• At least 5 years of relevant experience securing Windows, Linux, Unix, Solaris, and virtualized environments.
• Experience securing networks and systems using DISA STIGs and/or Security Requirements Guides (SRGs).
• Knowledge of computer security principles and policies, including RMF, STIGs, the National Industrial Security Program Operating Manual (NISPOM), and the Defense Security Service Assessment and Authorization Manual (DAAPM).
• Experience with vulnerability scanning and auditing tools and processes.
• Excellent written and verbal communication skills.
• Strong organizational and time management skills.
• Security+ certification, or the ability to obtain it within 6 months of hire.
Preferred:
• Security 8570/8141 compliance certification, or the ability to obtain it within 6 months of hire.
• Experience with ACAS, Nessus, Splunk, OpenRMF, or McAfee ePO.
group id: digipros