BAE Systems, Inc. · 1 hour ago
IT Security Specialist - ISSO - Information Systems Security Officer
BAE Systems, Inc. is an international defense, aerospace and security company seeking an IT Security Specialist to serve as the Information Systems Security Officer (ISSO). The ISSO will be responsible for ensuring the security and integrity of the organization's information systems and data, implementing security policies, conducting risk assessments, and managing incident responses.
Responsibilities
System Security Oversight: Ensure systems are operated, maintained, and disposed of in accordance with security policies and procedures outlined in the security plan
Program Implementation: Verify the implementation of delegated aspects of the system security program
Account Management: Ensure proper account management documentation is completed prior to adding and deleting system accounts
Documentation Management: Verify all system security documentation is current and accessible to properly authorized individuals
Risk Assessment and Mitigation: Conduct periodic assessments of authorized systems, identify vulnerabilities, and provide corrective actions to the Information System Security Manager - ISSM
Audit and Compliance: Ensure audit records are collected and analyzed in accordance with the security plan
Incident Response: Report all security-related incidents to the ISSM
System Recovery: Monitor system recovery processes to ensure security features and procedures are properly restored and functioning correctly
Change Management: Formally notify the ISSM of any changes to a system that could affect authorization
Configuration Control: Serve as a member of the Configuration Control Board (CCB), if designated by the ISSM
Security Policy and Compliance: Conduct regular reviews and updates of security policies to ensure they remain relevant and effective
Risk Management: Identify, assess, and mitigate potential security risks to the organization's information systems and data
System Security: Ensure the security and integrity of information systems, including networks, servers, workstations, and applications
Incident Response: Develop and implement incident response plans to respond to security incidents, including data breaches and system compromises
Vulnerability Management: Execute the continuous monitoring strategy
Security Awareness and Training: Develop and implement security awareness and training programs for employees and contractors
Audit and Compliance: Ensure user activity monitoring data is analyzed, stored, and protected in accordance with policies and procedures
Technical Security: Provide technical security expertise, including threat analysis, vulnerability assessment, and penetration testing
Communication and Collaboration: Communicate security risks and vulnerabilities to stakeholders, including senior management and employees
Continuous Improvement: Complete required training identified in the ISSM Required Training Table within 6 months of appointment
Qualification
Required
Bachelor's Degree and 6 years work experience or equivalent experience
Experience in Information Security
Experience in vulnerability/risk analysis
Experience in security policy, risk management, and system security
Experience in reports such as System Security Plans (SSPs), Risk Assessments Reports, Certification and Accreditation (C&A) packages, and/or System Requirements Traceability Matrix (SR TM)
Experience in security information and event management (SIEM) systems
Strong understanding of operating systems (Windows, Linux, etc.)
Familiarity with network protocols and architectures
Ability to work in a fast-paced environment and prioritize multiple tasks
Excellent communication and interpersonal skills
Strong analytical and problem-solving skills
Ability to obtain and retain a security clearance
U.S. Citizen
Preferred
Degree in Computer Science, Information Assurance, or a related field
Certifications: CompTIA Security+ or CISSP or CISM
Experience with Department of War classified systems such as SIPRNet
Experience with NIST Cybersecurity Framework and other security frameworks
Proficient in Python, PowerShell, or other scripting languages
Benefits
Health, dental, and vision insurance
Health savings accounts
A 401(k) savings plan
Disability coverage
Life and accident insurance
Employee assistance program
Legal plan
Discounts on things like home, auto, and pet insurance
Paid time off
Paid holidays
Paid parental
Military
Bereavement
Any applicable federal and state sick leave
Company recognition program to receive monetary or non-monetary recognition awards
Company
BAE Systems, Inc.
Improving the future and protecting lives is an ambitious mission, but it’s what we do. BAE Systems, Inc. is the U.S.
Funding
Current Stage
Late StageLeadership Team
Recent News
2024-05-12
2024-05-12
2024-05-08
Company data provided by crunchbase