CGS is seeking an Information Systems Security Officer (ISSO) to support Dept. of Commerce systems and efforts to achieve their Authorization to Operate (ATO). The ISSO will conduct security assessment, and information system security oversight activities in accordance with NIST 800.53 and provide security guidance and IS validation using the National Institute of Standards and Technology (NIST) RMF, DoC, and local security policies.
Requirements
- Review systems to identify potential security weaknesses and recommend improvements
- Maintain responsibility for managing cybersecurity risk from an organizational perspective
- Identify organizational risks, prioritize those risks, and maintain a risk registry for escalating and presenting those risks to senior leadership
- Provide security guidance and IS validation using the National Institute of Standards and Technology (NIST) RMF, DoC, and local security policies
- Maintain vulnerability scanning tool compliance, such as HBSS or ACAS, and patch management, such as IAVM
- Support security authorization activities, including transitioning from the legacy Information Assurance Certification and Accreditation Process (DIACAP) to compliance with the DoC RMF
- Provide subject matter expertise for cyber security and trusted system technology
- Apply advanced technical knowledge and analysis of specialized functional areas in task requirements to develop solutions to complex problems
- Research, write, review, disposition feedback, and finalize recommendations regarding cyber security policy, assessment and authorization assessments (A&As), security test and evaluation reports, and security engineering practices and processes
Benefits
- Health, Dental, and Vision
- Life Insurance
- 401k
- Flexible Spending Account (Health, Dependent Care, and Commuter)
- Paid Time Off and Observance of State/Federal Holidays