Information System Security Officer
SRA International, Inc., A CSRA Company
Cyber Security Analyst Advisor
GDIT is seeking an Information Systems Security Officer (ISSO) to join our team supporting the U.S. Environmental Protection Agency (EPA) Office of Land and Emergency Management (OLEM) Office of Superfund Remediation and Technology Innovation (OSRTI) Analytical Services Branch (ASB). As the ISSO, you will develop and implement an information security program to ensure the operational security of a critical mission-support system. You will update, maintain, and drive procedures and policies designed to protect the system from both internal and external threats. The system is currently hosted in an AWS Cloud environment.
Performance shall include:
Identify cyber security vulnerabilities and assist with the implementation of appropriate mitigations or countermeasuresConduct and support, when assessed or audited, periodic reviews of the information system to ensure compliance with the security and privacy authorization package (currently NIST 800-SP53 Rev. 4/5)Coordinate changes to the system infrastructure or software to ensure continued compliance with security and privacy requirementsCoordinate the response to the annual continuous monitoring assessment audit, and ensure the system’s continued Authorization to Operate (ATO)Ensure audit evidence are collected, reviewed, and documented, including any risk exceptionsIdentify and notify the program manager when changes occur that might affect the authorization determination for the information systemProvide analysis of systems, hardware, software, and maintenance needsProvide document review and updates of all security- and privacy-related documentationDevelop, coordinate and conduct training and tabletop exercises related to continuity of operations, contingency planning, incident handling, awareness, etc.Coordinate with other EPA organizational entities to ensure compliance with EPA and other federal requirements, specifications, and reportingPrepare reports on the status of system security and privacy, vulnerabilities, and responses to other customer inquiries and data callsWhat You’ll Need to Succeed:
Education: Masters or Bachelor's degree in Computer Science, Information Security, Cyber Security, or relevant disciplineRequired Experience: Eight (8) years of related experience. Without a master’s degree, ten (10) years of related experience is required.Required Technical SkillsPrior performance in roles such as system administration, networking administration, or ISSOKnowledge of NIST SP-800-53, Rev 4 and Rev 5Familiarity with system security and privacy within cloud environments (AWS, specifically)Demonstrated experience with risk management and auditingCertificationsCISSP, CISA, CISM, and/or cloud-based security certification (e.g. CCSP, COMPTIA Cloud+, or equiv)preferred. Clearance Required: Position of Trust or greater (can be obtained after starting)Excellent verbal and written communications skills, including the ability to communicate complicated technical and security concepts to both technical and non-technical stakeholders.
Confirm your E-mail: Send Email
All Jobs from SRA International, Inc., A CSRA Company