V

Information Systems Security Officer (ISSO)

Valiant Integrated Services
Full-time
On-site
Schofield, Hawaii, United States

  

Information Systems Security Officer (ISSO)

Description Summary

Valiant Integrated Services is seeking an experienced, highly skilled Information System Security Analyst to act as Information Systems Security Officer (ISSO) to join our professional team protecting mission training services for a Mission Training Complex (MTC) on Schofield Barracks, HI.

Duties and Responsibilities

  • Develop and maintain an organizational or system-level cybersecurity program that includes cybersecurity architecture, requirements, objectives and policies, cybersecurity personnel, and cybersecurity processes and procedures.
  • Provide support to the System Owner and the ISSM for maintaining the appropriate operational IA posture for a system, program, or enclave.
  • Provide support to the customer on all matters involving the security of their information systems.
  • Assist with the management of all security aspects of the information system and as assigned performs day-to-day security operations of the system.
  • Assist in the development of the system security policy and ensures compliance with that policy on a routine basis.
  • Prepare, validate, and maintain security documentation including, but not limited to: system security plan (SSP), risk assessment (RA), contingency plan (CP), privacy impact assessment (PIA), eAuthentication assessment, FIPS categorization.
  • Provide configuration management for security-relevant information system software, hardware, and firmware, controlling changes to the system and assessing the security impact of those changes.
  • Identify and mitigate security business and system risks.
  • Identify and manage POA&Ms through remediation as well as develop corrective action plans for each POA&M.
  • Maintain a repository for all organizational or system-level cybersecurity-related documentation such as DIACAP/RMF processes within eMASS or other automated process.
  • Maintain Defense Information Technology Portfolio Registry (DITPR) for client systems and software.
  • Ensure implementation of Information System (IS) security measures and procedures, including reporting incidents to the Command Information System Security Manger (ISSM) and appropriate reporting chains as well as coordinating system-level responses to unauthorized disclosures in accordance with DoDM 5200.01 Vol 3 for classified information or DoDM 5200.01 Vol 4 for CUI, respectively.
  • Implement and enforce all DoD IS and Platform Information Technology (PIT) system cybersecurity policies and procedures, as defined by cybersecurity-related documentation.
  • Ensure that all users have the requisite security clearances and access authorization, and are aware of their cybersecurity responsibilities for DoD IS and PIT systems under their purview before being granted access to those systems.
  • In coordination with the ISSM, initiate protective or corrective measures when a cybersecurity incident or vulnerability is discovered.
  • Establish a process for authorized users to report all cybersecurity-related events and potential threats and vulnerabilities to the ISSO.
  • Ensure that all DoD IS cybersecurity-related documentation is current and accessible to properly authorized individuals.
  • Ensures proper Configuration Management procedures are followed. Prior to implementation and contingent upon necessary approval with the ISSM.
  • Initiates requests for temporary and permanent exception, deviations, or waivers to IA requirements such as Plan of Action and Milestones (POA&Ms).
  • Ensures IA and IA-enabled software, hardware and firmware comply with appropriate security configuration guides.
  • Provide status updates of assigned duties to the appropriate agency heads as defined in their respective Service Level Agreement (SLA).
  • Respond to all applicable data calls, CTO’s, FRAGO’s, IAVA’s ,etc within the requested timeframe.
  • Attend all Cybersecurity Workforce Meetings when requested.

Required Education and Experiences

  • A bachelor’s degree plus 3 years of recent specialized experience OR an associate’s degree plus 7 years of recent specialized experience OR a major certification plus 7 years of recent specialized experience OR 11 years of recent specialized experience.
  • Required to have active U.S. Top Secret/SCI security clearance with the ability to pass a CI/Polygraph exam.
  • Baseline DoDI 8570 IA Certifications are required – a current CompTIA Security+ or greater certification. A higher level certification, such as GSLC, CAP, CASP, CISM, CISSP, is also appropriate.

Desired Skills and Qualifications

  • A working knowledge of RMF and the security authorization processes and procedures.
  • Knowledge of NIST Special Publications and their counterparts, especially SP800-37, SP800-53, ICD 503, and CNSS 1253. Ability to communicate clearly and present information to the customer in a format they can understand.
  • Experience in several of the following areas: knowledge of current security tools, hardware and software security implementation; different communication protocols; and encryption techniques/tools.
  • Familiarity with commercial security products, security authorization techniques, security incident management, and PKI and authorization services.  
  • Must be able to prioritize tasks, deliver solutions on time and be a team player with the ability to work independently and proactively while being flexible and prioritizing competing priorities, often under time constraints.
  • Have strong analysis, oral and written communication, and change management skills with ability to plan, organize, prioritize, track, manage, and learn new skills.
  • It is preferred that a candidate have at least one year of experience under the DoD Information Assurance Certification and Accreditation Process (DIACAP) and/or Risk Management Framework (RMF) accreditation process and has a familiarity with Enterprise Mission Assurance Support Service (eMASS).
  • Technical familiarity with Windows 7 Enterprise/Windows 10 Professional, Windows Server 2012, and Red Hat Linux. 
  • Experience with providing IA or IT support to a US Army client desirable, but not required.
  • Proficiency with using the Internet and with Microsoft Office products including e-mail, Word, Excel, Access and Project is required. 
  • Completion of required certifications required within six (6) months of hire date.

https://www.valiantintegrated.com/careers