Job Requirements
Clarksburg, WV
Top Secret Polygraph Unspecified
Mid Level Career (5+ yrs experience)
Salary not specified
Join Premium to unlock estimated salaries
Job Description
Company Overview
XPECT Solutions, LLC. has built a strong reputation by supporting our clients in meeting their strategic goals and mission objectives. We provide high quality resources for a wide range of IT and security solutions at best-value pricing. Our success is built on a solid foundation of well-vetted, highly technical personnel, a disciplined project management approach, and an overarching commitment to customer service. We develop, test, deploy, and support exceptional solutions that enhance system functionality, while maximizing reliability and availability, and ensure the tightest security.
Job Overview
The Information Systems Security Officer (ISSO) supports Federal Government customer in Clarksburg, WV. The ISSO supports the establishment, implementation, and maintenance of a life-cycle security model that develops, maintains, and dispositions information systems, services, and data, and safeguards their confidentiality, integrity, and availability.
The ISSO works with system owners to keep assigned systems operating in accordance with customer and federal security policy, supports Security Assessment and Authorization (SAA) activities in coordination with the Enterprise Information Security Section (EISS), maintains authorization artifacts and control evidence in the customer’s governance, risk, and compliance (GRC) tooling, and reports information system security incidents through the appropriate channels.
The position is hybrid, with on-site work at the in Clarksburg, WV.
Core Responebilties (to include but not limited to):
- Coordinate with system owners to ensure assigned systems are operated and maintained in accordance with federal and customer security policies and practices.
- Support the SAA process for assigned systems, verifying and validating conformance to federal and customer policies, regulations, FISMA, and specified security requirements, in parallel with EISS certification testing methodologies and strategies.
- Document security posture changes in the official GRC tool by uploading artifacts and evidence, writing security control responses, and assessing security controls.
- Maintain authorization work products on the contract cadence: System Security and Privacy Plan (SSPP) and Security Requirements Traceability Matrix (SRTM) quarterly; Plan of Action and Milestones (POA&M) monthly; Account Management Plan, Audit Logging Management Plan, SOPs, Business Impact Analysis, Incident Response Plan, Information System Contingency Plan, and security risk assessments as needed.
- Review system specifications, proposed system and engineering change requests, and modifications to determine impact on system security, and participate in change management through the Scaled Agile Framework (SAFe).
- Evaluate security vulnerabilities with regard to confidentiality, integrity, and availability, and recommend appropriate solutions, strategies, or mitigations.
- Review product acquisitions as they relate to information security.
- Support tier-level and data categorization and provide data categorization reports as assigned.
- Provide input to Interconnection Security Agreements (ISAs) and Security Assessment Reports (SARs) as needed.
- Coordinate with the ISSM and ISSM team to verify and validate that information systems conform to federal and customer policies, regulations, and standards; coordinate security-related issues with the Information Systems Security Engineer (ISSE).
- Report and coordinate all information system security incidents to the ISSM through the appropriate channels and provide vulnerability feedback. Incident response may require support after core working hours.
- Monitor trends in technology, perform system security analyses, and recommend strategies and solutions to improve system security; advise on standards and procedures for IT infrastructure management and security policy.
- Support development of standards and processes, and provide presentations, briefings, and training as assigned.
Requirements:
- Active Top Secret clearance
- 4+ years of information security experience (6+ years preferred).
- Associate’s degree (Bachelor’s degree preferred).
- Experience in information security practices within federal and/or state government.
- Experience applying the NIST Risk Management Framework (RMF) and NIST SP 800-53 security controls, with working knowledge of OWASP, Common Criteria, DISA, and SANS Institute practices.
- Hands-on experience producing and maintaining RMF authorization artifacts, including SSP/SSPP, SRTM, POA&M, contingency and incident response plans, and inputs to SARs.
- Hands-on technical experience in networking, system administration, and/or development.
- Knowledge, skills, and ability to address the applicable Revised Section 508 Standards.
- Ability to work a hybrid schedule with on-site presence at the in Clarksburg, WV, when requested.
- Willingness to complete security processing, including a possible counterintelligence-focused polygraph depending on assignment.
Preferred Additional Skills and Qualifications:
- CISSP (highly recommended), or CompTIA Security+ or equivalent. Equivalent or higher-level certifications are accepted.
- Cloud certification.
- Experience with Joint Cybersecurity Authorization Management (JCAM), Telos Xacta, GitLab, Atlassian Jira, Atlassian Confluence, SharePoint, Splunk, BigFix, and Tenable Security Center.
- Experience working in SAFe development environments.
- Working knowledge of CI/CD pipelines, virtualization, software-defined infrastructure, and cloud computing technologies.
- Experience supporting authorizations for both legacy and cloud-hosted or automated environments.
Benefits
Xpect Solutions, Inc. is a one-of-a-kind employer with a talented team that is cleared at various levels and is certified in dozens of industry-recognized certifications. Our talented staff are the key to our success. They bring the knowledge, experience and technical skills to deliver the best solutions to our customers.
We support our team by providing open communication, win-win partnerships with clients and vendors, a team-oriented culture that supports an employee focus on professional development and growth for a long-lasting and happy career.
We offer a benefits package that is designed to keep our most important assets – our employees – healthy, happy, energized and moving forward. Our philosophy is simple – empower our employees with the benefits, resources and the financial incentives they need to be successful.
Benefits and Perks:
- A competitive Medical, Dental, and Vision plan
- Retirement Savings Plan
- Life Insurance
- AD&D Insurance
- Short Term and Long Term Disability Insurance
- 3 weeks of annual PTO
- 11 days of Holiday PTO
- Performance Awards
- Referral Bonus Plan (of up to $5,000)
- Education Reimbursement/Training (of up to $2,500/year)
group id: RTX147f67