IT Security Specialist - ISSO - Information Systems Security Officer jobs in United States
info-icon
This job has closed.
company-logo

BAE Systems, Inc. · 1 hour ago

IT Security Specialist - ISSO - Information Systems Security Officer

BAE Systems, Inc. is an international defense, aerospace and security company seeking an IT Security Specialist to serve as the Information Systems Security Officer (ISSO). The ISSO will be responsible for ensuring the security and integrity of the organization's information systems and data, implementing security policies, conducting risk assessments, and managing incident responses.

Defense & Space
badNo H1BnoteU.S. Citizen Onlynote
Hiring Manager
Jenny Ridings
linkedin

Responsibilities

System Security Oversight: Ensure systems are operated, maintained, and disposed of in accordance with security policies and procedures outlined in the security plan
Program Implementation: Verify the implementation of delegated aspects of the system security program
Account Management: Ensure proper account management documentation is completed prior to adding and deleting system accounts
Documentation Management: Verify all system security documentation is current and accessible to properly authorized individuals
Risk Assessment and Mitigation: Conduct periodic assessments of authorized systems, identify vulnerabilities, and provide corrective actions to the Information System Security Manager - ISSM
Audit and Compliance: Ensure audit records are collected and analyzed in accordance with the security plan
Incident Response: Report all security-related incidents to the ISSM
System Recovery: Monitor system recovery processes to ensure security features and procedures are properly restored and functioning correctly
Change Management: Formally notify the ISSM of any changes to a system that could affect authorization
Configuration Control: Serve as a member of the Configuration Control Board (CCB), if designated by the ISSM
Security Policy and Compliance: Conduct regular reviews and updates of security policies to ensure they remain relevant and effective
Risk Management: Identify, assess, and mitigate potential security risks to the organization's information systems and data
System Security: Ensure the security and integrity of information systems, including networks, servers, workstations, and applications
Incident Response: Develop and implement incident response plans to respond to security incidents, including data breaches and system compromises
Vulnerability Management: Execute the continuous monitoring strategy
Security Awareness and Training: Develop and implement security awareness and training programs for employees and contractors
Audit and Compliance: Ensure user activity monitoring data is analyzed, stored, and protected in accordance with policies and procedures
Technical Security: Provide technical security expertise, including threat analysis, vulnerability assessment, and penetration testing
Communication and Collaboration: Communicate security risks and vulnerabilities to stakeholders, including senior management and employees
Continuous Improvement: Complete required training identified in the ISSM Required Training Table within 6 months of appointment

Qualification

Information SecurityVulnerability AnalysisRisk ManagementSecurity PolicySIEM SystemsOperating SystemsPythonPowerShellCISSP CertificationCISM CertificationCompTIA Security+Network ProtocolsAnalytical SkillsCommunication Skills

Required

Bachelor's Degree and 6 years work experience or equivalent experience
Experience in Information Security
Experience in vulnerability/risk analysis
Experience in security policy, risk management, and system security
Experience in reports such as System Security Plans (SSPs), Risk Assessments Reports, Certification and Accreditation (C&A) packages, and/or System Requirements Traceability Matrix (SR TM)
Experience in security information and event management (SIEM) systems
Strong understanding of operating systems (Windows, Linux, etc.)
Familiarity with network protocols and architectures
Ability to work in a fast-paced environment and prioritize multiple tasks
Excellent communication and interpersonal skills
Strong analytical and problem-solving skills
Ability to obtain and retain a security clearance
U.S. Citizen

Preferred

Degree in Computer Science, Information Assurance, or a related field
Certifications: CompTIA Security+ or CISSP or CISM
Experience with Department of War classified systems such as SIPRNet
Experience with NIST Cybersecurity Framework and other security frameworks
Proficient in Python, PowerShell, or other scripting languages

Benefits

Health, dental, and vision insurance
Health savings accounts
A 401(k) savings plan
Disability coverage
Life and accident insurance
Employee assistance program
Legal plan
Discounts on things like home, auto, and pet insurance
Paid time off
Paid holidays
Paid parental
Military
Bereavement
Any applicable federal and state sick leave
Company recognition program to receive monetary or non-monetary recognition awards

Company

BAE Systems, Inc.

company-logo
Improving the future and protecting lives is an ambitious mission, but it’s what we do. BAE Systems, Inc. is the U.S.

Funding

Current Stage
Late Stage

Leadership Team

leader-logo
Tom Arseneault
President & Chief Executive Officer, BAE Systems, Inc.
linkedin
leader-logo
Don Widener, PhD
Chief Technology Officer, Intelligence Solutions
linkedin
Company data provided by crunchbase