StratasCorp Technologies · 2 hours ago
Information System Security Engineer (ISSE) III
StratasCorp Technologies is seeking an Information System Security Engineer (ISSE) III to assist with developing, maintaining, and tracking Risk Management Framework (RMF) system security plans. The role includes providing cybersecurity support and executing the RMF process to ensure compliance and security within the IT operations division.
Cyber SecurityInformation TechnologyLogistics
Responsibilities
Assessment & Authorization (A&A)
Cybersecurity Compliance and Audit Readiness
Information Assurance Vulnerability Management (IAVM)
Vulnerability Scanning and Remediation
Application and Implementation of Security Technical Implementation Guides (STIGs) and Security Requirements Guide (SRGs)
Execute the RMF process in support of obtaining and maintaining Interim Authority to Test (IATT), AO approval, Authorization to Operate (ATO), and Denial of Authorization to Operate (DATO)
Identify and tailor IT and CS security control baselines based on RMF guidelines and categorization of the RMF boundary. Perform Ports, Protocols, and Services Management (PPSM). Perform IT and CS vulnerability-level risk assessments
Execute security control testing as required by a risk assessment or annual security review (ASR)
Mitigate and remediate IT and CS system level vulnerabilities for all assets within the boundary per STIG requirements
Develop and maintain Plans of Actions and Milestones (POA&M) in Enterprise Mission Assurance Support Service (eMASS)
Qualification
Required
Seven (7) years professional experience capturing and refining information security operational and security requirements, and ensuring those requirements are properly addressed through purposeful architecting, design, development, and configuration; and implementing security controls, configuration changes, software/hardware updates/patches, vulnerability scanning, and securing configurations
Bachelor's degree in computer science, information technology, or an equivalent technical degree from an accredited college or university
IAT-III certification (any of the following): CASP+ CE, CCNP Security, CISA, CISSP (or Associate), JGCED, GCIH, CCSP