Minimum Clearance Required to Start:Top Secret SCI
Overall Assignment Description: Information System Security Specialists enhance Counter Insider Threat information systems security, policies, procedures, and tools to ensure the confidentiality, integrity, and availability of systems, networks, and data.
- Provide guidance, assistance, and coordination to systems developers, systems administrators, and other IT specialists to ensure verified and timely implementation of IT security standards for systems both under development and already deployed.
- Document, manage, and control the integrity of changes to all systems security documentation, including standard operating procedures and user guides that provide detailed instructions for implementing IT systems security policies.
- Assist in the selection of minimum-security controls to establish a baseline of measures to prevent security breaches of the information system, document the selected security controls in the security plan and initial Risk Assessment Report (RAR), and, document an approved continuous monitoring strategy.
- Document the security control implementation, as appropriate, in the security plan, providing a functional description of the control implementation (including planned inputs, expected behavior, and expected outputs).
- Conduct security testing and verify which security controls are implemented correctly, operating as intended, and producing the desired outcome in meeting security requirements.
- Conduct remedial actions on security controls based on the findings and recommendations of the Security Assessment Report and reassess remediated control(s), as appropriate.
- Perform vulnerability scans and ensure the accountable parties have responded appropriately to vulnerability findings, troubleshoot security threats and vulnerabilities in response to incident reports, and identify/isolate problem sources; and recommend solutions or corrective actions.
- Monitor and analyze systems logs daily to identify systems security trends and assess the security effectiveness of installed systems based on analysis of reported security problems.
- Participate in multi-functional teams and manage work through JIRA
- Bachelor’s Degree
- Possess a minimum of three (3) years of experience in Certifying and Accrediting systems including at least one (1) year of experience in applying the National Institute of Standards and Technology (NIST) Special Publication 800-53 Risk Management Framework
- Security+ CE certification is required
- Certified in a DOD 8570 IAM Level II baseline certification (CAP
CASP+ CE, CISM, CISSP (or Associate), GSLC, CCISO, or HCISPP)
- Experience in using JIRA or an alternative Agile Project Management tool
- Experience in using Confluence or alternative knowledge management tool
The position may require a COVID vaccination or an approved accommodation/exemption for a disability/medical condition or religious belief as required by federal, state, provincial or local mandates or customer requirements.