Overview
Information Systems Security / Information System Security Officer (ISSO) LOCATION: Columbia, MD JOB STATUS:Full-time CLEARANCE:Ability to obtain TS CERTIFICATION:CAP, CISSM, or CISSP TRAVEL:Less than 5% Astrion has an exciting opportunity for an experiencedInformation Systems Security Officer (ISSO). The ISSO supports the ISSM by verifying implementation of required security controls, conducting continuous monitoring and self-inspections, tracking corrective actions, supporting user access and training requirements, and ensuring classified systems are operated in accordance with the approved SSP, NISPOM Rule, CSA guidance, and local security procedures; this position is located in Columbia Maryland. REQUIRED QUALIFICATIONS / SKILLS
- Bachelor's degree with 2-4 years of experience.
- Experience in supporting U.S. Government clients.
- Be able to apply knowledge of IA policy, procedures, and workforce structure to develop, implement and maintain a secure network environment.
- A CAP, CISM, CySA, or CISSP certification is required.
- S. citizenship with active Top Secret eligibility and the ability to maintain such eligibility.
PREFERRED QUALIFICATIONS / SKILLS
- Proficiency with Secure Internet Protocol Network establishment and maintenance.
- Proficiency with various compute applications and testing tools (Word, Excel, PowerPoint, WASSP, MBSA).
- Strong background in certification and accreditation process of information systems and ability to write, review and coordinate systems security plans.
RESPONSIBILITES:
- Information System Security Officer - responsible for supporting the day-to-day security oversight of classified information systems and ensuring users, systems, and processes remain compliant with NISPOM Rule, DCSA/CSA guidance, approved security documentation, and local procedures.
- Ensure compliance - with the approved System Security Plan (SSP), security policies, procedures, and system-specific requirements.
- Support the ISSM - in maintaining the classified information system security program.
- Coordinate and conduct system self-inspections and document results.
- Track, validate, and report corrective actions to the ISSM
- Support continuous monitoring activities, including review of audit logs, account activity, configuration changes, vulnerability status, and system security posture.
- Assist with configuration management and identify security-relevant changes that may require ISSM review or reauthorization.
- Ensure users receive required system security briefings, training, user agreements, and access authorizations before system access is granted.
- Monitor user compliance with classified system rules, including password/authentication protection, need-to-know, media handling, removable media restrictions, and reporting requirements.
- Support incident response for data spills, suspected compromises, audit anomalies, unauthorized activity, or other reportable security concerns
- Assist with maintaining authorization documentation, including SSPs, POA&Ms, risk assessments, security assessment results, contingency plans, configuration records, and authorization artifacts.
- Coordinate with the ISSM, FSO/AFSO, Insider Threat Program, IT, program leadership, and Government security representatives as required.
- Ensure classified systems are operated only within their approved authorization boundary, classification level, caveats, and accredited configuration
#CJ
|