Salary
💰 $130,000 - $180,000 per year
About the role
- Lead the implementation and enforcing information systems security policies, standards, and methodologies and assist with preparation and maintenance of documentation
- Assist in the evaluation of security solutions to ensure they meet security requirements for processing classified information
- Assist with the CM for information system security software, hardware, and firmware
- Oversee the maintenance of records on workstations, servers, routers, firewalls, intelligent hubs, network switches, etc. to include system upgrades
- Propose, coordinate, implement, and enforce information systems security policies, standards, and methodologies
- Develop and maintain documentation for C&A in accordance with ODNI and DoD policies
- Provide CM for security-relevant information system software, hardware, and firmware
- Develop system security policy and ensure compliance
- Maintain operational security posture for an information system or program
- Provide support to the Information System Security Manager (ISSM) for maintaining the appropriate operational IA posture for a system, program, or enclave
- Develop and update the system security plan and other IA documentation
- Oversee and assist with the management of security aspects of the information system and perform day-to-day security operations of the system
- Administer the user identification and authentication mechanism of the Information System (IS)
- Performs vulnerability/risk assessment analysis to support certification and accreditation
- Manages changes to system and assesses the security impact of those changes
- Prepares and reviews documentation to include System Security Plans (SSPs), Risk Assessment Reports, Certification and Accreditation (C&A) packages, and System Requirements Traceability Matrices (SRTMs)
- Supports security authorization activities in compliance with National Institute of Standards and Technology Risk Management Framework (NIST RMF)
Requirements
- A technical BS degree from an accredited university, or Certified Information Systems Security Professional (CISSP),and/or Certified Information Systems Auditor
- Certified Authorization Professional (CAP) certification will be required within 6 months of award, if not CISA
- A minimum of 7 years of experience in performing system and application certifications and accreditations
- Top Secret Security Clearance or the ability to obtain one
- Must be able to pass a background check
- May require additional background checks as required by projects and/or clients at any time during employment
- Proven record of learning and adapting new technologies
- Time management skills and the ability to communicate effectively with both stakeholders and technical staff
- Able to work independently with minimal supervision as well as working with a team
- Solid oral and written communication skills that can be adapted to both the technical, and administrator level
- Strong attention to detail
- Proficient in MS Office, Word, Outlook, PowerPoint, and Excel
- Knowledge of National Institute of Standards and Technology Risk Management Framework (NIST RMF) (Desired)
- Advanced practical experience in managing all phases of systems C&A activities ranging from early concept development to system retirement (Desired)
- Expert in the processes and documentation requirements for numerous C&A methodologies (Desired)
- Demonstrated experience supporting Government Agencies preferably the Department of State (Desired)