Job Description
Job Description
Job Title: ISSO Location: Gaithersburg, VA Type: Contract To Hire Compensation: $62.72 - $64.64/ hr W2 Contractor Work Model: Onsite Security Clearance: TS/SCI with CI Poly
Overview Leave placeholder text here for recruiter to input
Responsibilities
- Develop risk mitigation strategies that contribute to the effectiveness, efficiencies, and performance outcomes for strategic projects, program goals, and business processes
- Respond to updates and maintenance needs of security documentation, especially System Security Plans, Plans of Actions and Milestones (POA&Ms), Security Impact Assessment for proposed system changes, and Concept of Operations
- Maintain system security plans and related configuration records in customer Service+ (ServiceNow), XACTA-360 platform, and Leidos-CIO security tools
- Drive necessary security changes through steering groups and control (review) boards to meet Risk Management milestones
- Work independently as well as collaboratively to drive security process improvements, addressing gaps in meeting customer or Leidos security requirements and due diligence responsibilities
- Provide guidance and engage the program lab team to implement secure software and hardware processes, apply government security standards, and commercial best security practices
- Resolve highly complex security problems by applying technical knowledge, conceptualizing, reasoning, and interpretation of requirements
- Communicate with Leidos and NGA leadership regarding matters of significant importance to the organization/project
- Apply in-depth understanding of information security technical principles, theories, concepts, and their application across a range of programs
- Develop and maintain security documentation per NGA/IC/DoD-DISA/NIST/Industry standards and policies
- Initiate and coordinate all Assessment and Authorization (A&A) and renewal activities with the NGA Designated Authorization Officials (DAO or DAOR)
- Address any Information Assurance or Cybersecurity notices, orders, tasking, or directives as required following the NGA operations vulnerability and patch management processes
- Measure effectiveness of defense-in-depth architecture and Zero Trust policy implementations against known vulnerabilities
- Perform security audits and assessments, including creating, tracking, and assisting in remediation of Plan of Action and Milestones (POA&Ms)
- Coordinate with System Administrators and others to remediate vulnerabilities and report results
- Track open vulnerabilities and obtain and document approvals while managing POA&M status
- Update Security CONOPS and Information Technology Disaster Recovery (ITDR) plans for each Security Plan
- Manage security profiles and implementation for systems and services scheduled for Assessment and Authorization (A&A)
- Work with Systems Engineers and Administrators, Senior ISSO, ISSMs, Lab Team, and Leidos Corporate Security to develop and maintain security plans and associated documentation
- Maintain records and documentation on program IT systems, upgrades, patches, and connectivity configurations
- Evaluate security solutions and implementation strategies for program IT systems and services and maintain operational security posture of development, integration, and deployed capabilities
- Provide training and approve user access and IAA (identification, authorization, and authentication) mechanisms for information systems
- Conduct security and risk assessments as required using a range of security accreditation frameworks (e.g., NIST, RMF, Common Criteria, DoD, the Intelligence Community Directives (ICDs)), and mitigate risks by applying security controls effectively to achieve an acceptable degree of operational risk
- Perform testing and security assessments to sustain required accreditations
- Promote the use of secure hardware and software within the systems affected by government and corporate approval standards
- Ensure all required security policies and practices are effectively applied to systems and that security controls implementing these policies achieve proper levels of confidentiality, integrity, availability, and privacy protection throughout the system life cycle
- Assist with the execution, analysis, and remediation activities for the vulnerability management program (scanning, assessment, reporting, and mitigation verification) across accreditation entities and three distinct classification domain enclaves (U), (S) and (TS), using the Nessus and Tenable-ACAS vulnerability scanning tools
Requirements
- US citizenship is required per contract
- BS degree and 8 to 12 years of prior relevant experience to operate within the scope of responsibilities
- Active TS-SCI clearance with Polygraph
- Experience that demonstrates an understanding and application of the ICD-503 and NIST risk management framework
- Experience desired with XACTA; XACTA 360 (preferred); HBSS; ACAS; Nessus, SPLUNK
- Has 3+ years of experience operating, analyzing, and resolving vulnerability scan results using tools such as Nessus, Tenable Security Center, or a comparable commercial or GOTs product
- Active Certified Information Systems Security Professional (CISSP) certification or ISACA Certified Information Security Manager (CISM) certification
- Intelligence Community experience preferred
System One, and its subsidiaries including Joulé and Mountain Ltd., are leaders in delivering outsourced services and workforce solutions across North America. We help clients get work done more efficiently and economically, without compromising quality. System One not only serves as a valued partner for our clients, but we offer eligible employees health and welfare benefits coverage options including medical, dental, vision, spending accounts, life insurance, voluntary plans, as well as participation in a 401(k) plan.
System One is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex (including pregnancy, childbirth, or related medical conditions), sexual orientation, gender identity, age, national origin, disability, family care or medical leave status, genetic information, veteran status, marital status, or any other characteristic protected by applicable federal, state, or local law. #M-2 #LI-CK1 Ref: #856-Baltimore-S1
