Scientific Research Corporation · 2 hours ago
Information Systems Security Officer (ISSO)
Scientific Research Corporation is an advanced information technology and engineering company that provides innovative products and services to government and private industry. They are seeking an Information Systems Security Officer (ISSO) to support USSPACECOM systems in achieving their Authorization to Operate (ATO) through comprehensive security assessments and risk management framework processes.
Responsibilities
Reviewing systems to identify potential security weaknesses and recommending improvements to amend vulnerabilities, implement changes, and document upgrades
Maintaining responsibility for managing cybersecurity risk from an organizational perspective
Identifying organizational risks, prioritizing those risks, and maintaining a risk registry for escalating and presenting those risks to senior leadership
Providing security guidance and IS validation using the National Institute of Standards and Technology (NIST) RMF, and local security policies
Providing configuration management (CM) recommendations for information system security software, hardware, and firmware and coordinating changes and modifications with the ISSM, Security Control Assessor (SCA), and Authorizing Official (AO)
Maintaining vulnerability scanning tool compliance, such as Trellix (HBSS) or ACAS (Nessus), and patch management, such as IAVM to ensure IT staff pushes patches to all systems in an effort to maintain compliance with all applicable directives, manage system changes, and assess the security impact of those changes
Providing subject matter expertise for cybersecurity and trusted system technology
Applying advanced technical knowledge and analysis of specialized functional areas in task requirements to develop solutions to complex problems
Research, write, review, disposition feedback, and finalize recommendations regarding cybersecurity policy, assessment and authorization assessments (A&As), security test and evaluation reports, and security engineering practices and processes
Conduct research and write risk assessment reports to include risk thresholds, evaluation, and scoring
Supporting analysis of the findings and provide expert technical guidance for mitigation strategies, including implementation advice on the cybersecurity risk findings, and other complex problems
Qualification
Required
Bachelor's degree
A minimum of five (5) years experience as an Information Assurance (IA) Analyst, ISSE, ISSO, or similar role in ATO package development, including generating security documentation for requirements, security control assessment, STIG and IAVA compliance, Standard Operating Procedures, test results, etc
eMASS experience
Professional security certification such as: CCNA, CySA+, GICSP, GSEC, CompTIA Security+ CE, SSCP, or higher
Strong desktop publishing skills using Microsoft Word, Excel, Visio, and Adobe
Experience with industry writing styles such as grammar, sentence form, and structure
Ability to multi-task in a deadline-oriented environment
Preferred
CISSP, CASP, or a similar certificate is preferred
Master's degree in cybersecurity or related field
Strong initiative, detail orientation, organizational skills, and aptitude for analytical thinking
Demonstrated ability to work well independently and as a part of a team
Excellent work ethic and a high commitment to quality
Benefits
Medical, dental, and vision plans
401(k) with a company match
Life insurance
Vacation and sick paid time off accruals starting at 10 days of vacation and 5 days of sick leave annually
11 paid holidays
Tuition reimbursement
A work environment that encourages excellence and more
Company
Scientific Research Corporation
Scientific Research Corporation provides innovative solutions to the U.S. government, private industry, and international markets.