Support the security posture of systems, applications, and networks by applying Information Assurance technologies and ensuring compliance with FISMA and security standards.
Required Qualifications:
Associates Degree in Computer Security or related field of study; (ISC)2 Information Security Certification(s) (e.g., CISSP, CAP, etc.); or in lieu of education, five (5) years of documented experience that addresses all requirements of the position.
Minimum of 3 years of experience assessing and documenting results for systems, infrastructure, and applications in on-premises and cloud environments, including AWS GovCloud and/or Azure GovCloud.
Experience evaluating systems against NIST SP 800-53 security controls and NIST SP 800-171 requirements.
Experience supporting Risk Management Framework (RMF) processes, including the preparation and maintenance of authorization packages and supporting artifacts.
Strong knowledge of FISMA requirements and Federal information assurance and cybersecurity compliance practices.
Experience preparing, reviewing, and maintaining security documentation such as CMP, IRP, ISCP, and POA&M.
Experience identifying vulnerabilities and coordinating remediation efforts with infrastructure, development, and program teams.
Experience reviewing and interpreting results from vulnerability scans, SCAP scans, STIG assessments, and patch/compliance activities.
Familiarity with both on-premises and cloud-based environments, with AWS preferred.
Strong understanding of security controls, risk mitigation, incident response, configuration management, and continuous monitoring practices.
Excellent verbal and written communication skills, with the ability to clearly document requirements, findings, risks, and recommendations.
Ability to work collaboratively with Government customers, program managers, technical teams, and other ISSOs.
Active Top Secret (TS) clearance with eligibility for Sensitive Compartmented Information (SCI) with ability to obtain CI polygraph
Preferred Qualifications:
Certifications: CompTIA Security+ or CISSP or CISM
Experience using a cyber risk and compliance management system, such as Xacta, RiskVision, or similar platforms.
Familiarity with scan types and compliance tools including patch/update reviews, SCAP, and DISA STIG assessments to help ensure patch and configuration compliance.
Working knowledge of operating systems, network security, and application security to support the implementation of information security and assurance principles.
Knowledge of Splunk software and related tools.
Knowledge of TACLANE, encryption devices, and COMSEC technologies.