Senior ISSO (Cleared)
Ignite
Fort Belvoir, virginia
Job Details
Full-time
Full Job Description
Ready to Ignite your career and work alongside some of the most innovative and brightest professionals in innovative technology? Join us and unleash your potential working in an Agile environment while modernizing enterprise systems and applications needed to support the men and women charged with safeguarding the American people and enhancing the Nation’s security, and prosperity.
As a Senior ISSO, you will be a key member of the Cybersecurity Team responsible for the Information Assurance and Security of application, database, and enterprise network services. You will also be responsible for activities associated with delivery of Cybersecurity policy implementation and network solutions associated with customer-defined systems and software projects; responsibilities include:
- Implement Cybersecurity Program strategy
- Apply information security in accordance with National directives security policy including, but not limited to, NIST SP 800-30, NIST 800-37, NIST 800-53a, NIST SP 800-61, NIST 800-171
- Assess entire system lifecycle requirements and network security impacts
- Support creation of, and ensure approval for, Department of Defense Risk Management Framework (RMF) Assess and Authorize (A&A) Process for development and sustainment projects
- Support program and customer management, and government Authorizing Official (AO) for all information security status, policies, and procedures
- Document RMF Security Implementation Plan artifacts. Coordinate and assist development team with application artifact documentation
- Assist government personnel in preparing and presenting Information Assurance Compliance System (IACS) packages to the Control Assessor (SCA) Assess and analyze the current threat environment
- Enhance – Implement Cybersecurity vulnerability/A&A hardening testing
- Optimize – Cybersecurity development environment certification
- Architect & Engineer security – develop security goals, capabilities, controls, and architecture
- Design & Implement security – vulnerability management, build security into development
- Integrate & Test Security – test patches and settings, document A&A artifacts
- Validate & Verify security – validate patch status and software control status
- Implement security – apply patches and security settings, performance incident handling and remediation
- Maintain security posture – audit security settings, track security training, monitor threats, track reaccreditation
- Enable assurance for information security during all phases of agile software development and deployment
- Continuously evaluate and recommend innovative proven best business practices and tools to enhance defense-in-depth
- Identify, assess, and recommend zero-day cyber threat remediation
- Address Cybersecurity issues to help maintain Continuity of Operations Plans (COOP)
- Perform information security vulnerability testing and mitigate any nonconformance
- Supports reviews and audits of continuous system monitoring and contingency planning. Updates associated documentation as needed
- Create and manage Plan of Action & Milestones (POA&M)
- Implement and validate Security Technical Implementation Guide (STIG) requirements for all development and implementation projects
- Understand and assist developers with static code analysis processes
- Report and help investigate security-related incidents and security violations as requested by the Computer Security Incident Response Center (CSIRC)
- Monitor and inspect for approved software usage and implementation of approved antivirus and other security related software
- Develop and maintain security training programs are developed and maintained
Requirements
- Must be a U.S. Citizen with an active Secret clearance
- Will work onsite at Fort Belvoir, VA 3 days per week with days remote
- College degree (B.S., M.S.) in Information Assurance, Computer Science, Information Management Systems or a related discipline
- Certifications: minimum Security+ CE or equivalent, CISSP or CASP preferred
- Demonstrated knowledge of NIST Information Technology Security Special Publications (SP) 800 series, with emphasis on NIST SP 800-37, “Guide for Applying the Risk Management Framework to Federal Information Systems” and NIST SP 800-53A, “Guide for Assessing the Security Controls in Federal Information Systems”
- Professional Experience: 10+ years related technical experience
- Working knowledge of and ability to assist others in the use of information security provisioning and monitoring tools to support process improvement
- Working knowledge of Federal Information Security Management Act (FISMA) reporting requirements and processes
- Experience working on unusually complicated problems and providing solutions that are highly creative and ingenious, exhibiting ingenuity, creativity, and resourcefulness
- Experience with continuous integration tools and environments
- Experience with scripting languages like Perl, VBScript, Ruby, etc.
- Experience with Computer Network Defense (CND) processes, procedures, and tools
- Acting independently to expose and resolve problems
- Demonstrated experience with HP Fortify Software Security Center
- Demonstrated experience with Assured Compliance Assessment Solution (ACAS)/Tenable Nessus Vulnerability Scanner
- Demonstrated experience with DISA Security Technical Implementation Guide (STIG) implementation and Security Content Automation Protocol (SCAP) tool usage
- Demonstrated familiarity and experience with Firewalls, Intrusion Prevention Systems, WebGateways, and/or enterprise Antivirus software technologies
- Demonstrated experience using IACS
- Demonstrated ability to identify and manage risk
- Ability to apply advanced principles, theories, and concepts, and contribute to the development of innovative IA principles and ideas
Benefits
- 401(k) with matching and 100% Vested
- Health Insurance - 3 plans to select from
- Dental insurance
- Vision Insurance
- Health savings account
- Life insurance
- Short Term Disability
- Long Term Disability
- AD&D
- Paid time off
- Professional development assistance
- Training
- Tuition reimbursement
- Flexible schedule
- Flexible spending account
- Referral program
- Paid Legal Plan
- and more....
Ignite IT is an Equal Employment Opportunity/Affirmative Action Employer. We evaluate qualified applicants without regard to race, color, religion, sex, national origin, disability, Veteran status, sexual orientation, or other protected characteristic. In accordance with EO 13665 Final Rule, Ignite IT will not discharge or in any other manner discriminate against employees or applicants because they have inquired about, discussed, or disclosed their own pay or the pay of another employee or applicant.
Applicants selected must be able to possess and maintain a government clearance
US CITIZENSHIP REQUIRED'