BAE Systems, Inc. · 2 hours ago
Cybersecurity, Senior ISSO
BAE Systems, Inc. is a leading company in Aerospace and Defense, dedicated to supporting and protecting information systems critical to national security. In the Cybersecurity, Senior ISSO role, you will be responsible for ensuring compliance with the Risk Managed Framework and supporting various cybersecurity efforts, including documentation and continuous monitoring of security controls.
Defense & Space
Responsibilities
Responsible for supporting adherence to all aspects of a rigorous Risk Managed Framework (RMF) compliance program as stipulated by NISPOM/DAAPM, JSIG, ICD 503, STIGs and associated NIST publications
Support the Information System Security Manager in obtaining and maintaining Authority to Operate (ATO) approvals for various systems by adhering to the Risk Management Framework (RMF)
Support the ISSM to ensure all security certification and accreditation documents in relation to all classified systems are up-to-date
Ensure continuous monitoring (e.g. weekly, monthly, etc.) in accordance with cognizant security authority requirements are being implemented and met
Support cybersecurity efforts throughout the RMF process for one or more assigned programs(s) to include supporting the development and management of System Security documentation, Plans of Action and Milestones (POA&Ms), assessing and auditing systems security controls, and continuous monitoring of controls
Qualification
Required
An active DoD Top Secret Clearance is required in addition to IAM Level I certification commensurate with DoD 8570.1M requirements (or ability to obtain certification within 6 months)
5 or more years of ISSO or relevant cybersecurity experience and minimum of a high school diploma
High level of personal motivation and initiative to learn and acquire new skills, and adapt seamlessly to an ever-changing security environment
Customer focused, excellent communicator and ability to work with limited supervision
Strong organizational skills
Able to interface with other IA team members, other security disciplines (industrial security, physical security, special programs security, etc.), program personnel and government security representatives
Experience with compliance and vulnerability scanning tools (Nessus, SCAP, ACAS, SCC)
Experience with validating compliance of various systems (Windows, Linux, Network Devices and peripherals)
Experience with IA configuration management and change request processes
Experience with conducting regular audits to ensure that systems are being operated securely, and information systems security policies and procedures are being implemented as defined in security plans
Preferred
Working knowledge of system functions, security policies, technical security safeguards, and operational security measures
Experience with the review and creation of mitigation reports from compliance and vulnerability scanning tools (Nessus, SCAP, ACAS, SCC)
Experience with the preparation for Assessment and Authorization's (A&A)
Experience with the development of core documentation including System Security Plans, Standard Operating Procedures, Plan of Actions and Milestones, Remediation Plans, and Configuration Management Plans
Experience with development and delivery of IA-related briefings and training material
Ability to translate operational requirements into technical requirements and architectures needed to meet program objectives
Experience with conducting all aspects of a self-inspection
Experience with periodic and on-demand system audits and vulnerability assessments, including user accounts, application access, file system and integrity scans to determine compliance
Prepares incident reports of analysis methodology and results
Knowledge of new and emerging information technology (IT) and cybersecurity technologies
Benefits
Health, dental, and vision insurance
Health savings accounts
A 401(k) savings plan
Disability coverage
Life and accident insurance
Employee assistance program
A legal plan
Paid time off
Paid holidays
Paid parental
Military
Bereavement
Any applicable federal and state sick leave
Company recognition program
Monetary or non-monetary recognition awards
Company
BAE Systems, Inc.
Improving the future and protecting lives is an ambitious mission, but it’s what we do. BAE Systems, Inc. is the U.S.
Funding
Current Stage
Late StageLeadership Team
Recent News
2024-05-12
2024-05-12
2024-05-08
Company data provided by crunchbase