Information Systems Security Officer (ISSO) 2
Position Summary
Base-2 Solutions is seeking an Information Systems Security Officer (ISSO) 2 to support information assurance, cybersecurity operations, security authorization, configuration management, and security documentation for information systems, programs, or enclaves.
Essential Duties and Responsibilities
- Provide support for a program, organization, system, or enclave's information assurance program.
- Provide support for proposing, coordinating, implementing, and enforcing information systems security policies, standards, and methodologies.
- Maintain operational security posture for an information system or program to ensure information systems security policies, standards, and procedures are established and followed.
- Assist with the management of security aspects of the information system and perform day-to-day security operations of the system.
- Evaluate security solutions to ensure they meet security requirements for processing classified information.
- Perform vulnerability/risk assessment analysis to support security authorization.
- Provide configuration management (CM) for information systems security software, hardware, and firmware.
- Manage changes to system and assess the security impact of those changes.
- Prepare and review documentation to include System Security Plans (SSPs), Risk Assessment Reports, Certification and Accreditation (C&A) packages, and System Requirements Traceability Matrices (SRTMs).
- Support security authorization activities in compliance with National Institute of Standards and Technology Risk Management Framework (NIST RMF).
- Provide support to senior ISSOs for implementing, and enforcing information systems security policies, standards, and methodologies.
- Assist with preparation and maintenance of documentation.
- Assist in the evaluation of security solutions to ensure they meet security requirements for processing classified information.
- Assist with Configuration Management (CM) for information system security software, hardware, and firmware.
- Maintain records on workstations, servers, routers, firewalls, intelligent hubs, network switches, etc. to include system upgrades.
- Propose, coordinate, and implement information systems security policies, standards, and methodologies.
- Develop and maintain documentation for Security Authorization in accordance with ODNI and DoD policies.
- Provide CM for security-relevant information system software, hardware, and firmware.
- Ensure compliance with system security policy.
- Provide support to the information System Security Manager (ISSM) for maintaining the appropriate operational Cybersecurity posture for a system, program, or enclave.
- Develop and update the system security plan and other Cybersecurity documentation.
- Track and ensure appropriate user identification and authentication mechanism of the information System (IS).
- Obtain system authorization for ISs under their purview.
- Plan and coordinate implementation of IT security programs and policies.
- Manage and control changes to the system assessing the security impact of those changes.
- Provide daily oversight and direction to contractor ISSOs.
- Interact with customers, IT staff, and high-level corporate officers to define and achieve required Cybersecurity objectives.
Required Qualifications
- Work-related experience in the fields of IT, cybersecurity or security authorization meeting an applicable education and experience pathway in the equivalency section.
- Experience in at least two of the following areas is required: knowledge of current security tools, hardware/software security implementation; communication protocols; or encryption tools and techniques.
- Familiarity with commercial security products, security authorization techniques, security incident management, and PKI and authorization services.
Preferred Qualifications
- None specified.
Required Education and Experience Equivalency
- Bachelor's degree in Computer Science, Cyber Security or IT Engineering with Eight (8) years of combined work-related experience in the fields of IT, cybersecurity or security authorization.
- No bachelor's degree with Twelve (12) years of combined work-related experience in the fields of IT, cybersecurity or security authorization (8 years plus 4 additional years in lieu of a Bachelor's degree).
Required Certifications
- DoD 8570 IAM Level I certification required - one of: CAP, CND, Cloud+, GSLC, Security+ CE, HCISPP.
Required Security Clearance
- Active Top Secret/SCI with Full Scope Polygraph