Similar available jobs
in Chantilly, VA
Information Systems Security Engineer - Level 1 - Full-time
Chantilly, VA 20153
The job duties of the ISSO are as follows:
- Responsible for the implementation of the National Institute of Standards and Technology (NIST) Special Publication 800-37, Guide for Applying the Risk Management Framework (RMF) Steps 6 for assigned information systems/assets. Required to become proficient on the Customer's Assessment and Authorization tool to track and document the RMF step 6; which is to maintain ongoing situational awareness about the security and privacy posture of the system and organization to support risk management decisions.
- EachISSO will be assigned as Primary and alternate on average for 4-7 systems depending on the complexity of the system. As a PrimaryISSO, the individual is responsible for leading the assetRMF continuous monitoring team and submitting weekly status reports. Daily tasks include:
- Supporting the Information System Security Manager (ISSM) & Information System Security Engineer (ISSE) Lead.
- Coordinating with the Information System Security Analysts/Engineers (ISSA/ISSE), and system administrators for:
- Plans of Actions and Milestones (POA&Ms) management
- Authorization to Operate (ATO) and Initial Authorization to Test (IATT), and
- Assisting ISSA/ISSE in RMF steps 1-3.
Completing daily continuous monitoring control assessments to report security and privacy posture to management (e.g., body of evidence entry).
REQUIREMENTS
Required Skills, Experience, and Education:
Candidate must have 7 years of relevant/related work experience; which can be a combination of work history and education. This equates to a Doctorate and 0 years of experience (or) Masters and 1 years, (or) Bachelors and 3 years, (or) Associates and 5 years (or) HS and 7 years. The candidate must have certifications to meet minimum requirements for DoD 8570 IAT Level 2 certification requirements (level 3 requirements are acceptable as well prior to hire):
- GIAC Security Essentials (GSEC)
- Global Industrial Cyber Security Professional (GICSP)
- Implementing and Administering Cisco Solutions (CCNA)
- Analyst (CYSA+)
- COMPTIA Security+
- GIAC Security Essentials (GSEC)
- Global Industrial Cyber Security Professional (GICSP)
- Implementing and Administering Cisco Solutions (CCNA)
- Systems Security Certified Practitioner (SSCP)
DoD 8570 compliance with IASAE Level 1 is required.
Required Clearance: Active TS/SCI, with CI Poly.