JobHabor

Senior Information System Security Officer

Saic
Location
Colorado Springs, CO, United States
Workplace
Onsite
Employment
Salary
Apply on the employer’s site

Posted today

SAIC is seeking a technical Senior Information System Security Officer (ISSO) to support the company’s secure operating facilities in Colorado Springs, CO. The Horizon 2 contract supports the US Space Force. The primary Government customer is Space Systems Command and its Program Offices that oversee the Space Domain Awareness and Combat Power Branches & the Battle Management Command, Control and Communications portfolios.

You will support all facets of SAIC’s Information Protection Program at our Colorado Springs location. You will assist the Information Systems Security Manager and provide oversight, guidance, and technical support, on IT and information system security issues affecting the mission of the customer, by implementing common information system security practices, policies, and standards. You will have access to information systems to perform advanced vulnerability and compliance scanning and your background in applying sound and effective Information Assurance security practices, in both Windows and Linux environments, will be the driving force behind the success of our customer missions.

This is an excellent opportunity for an experienced cybersecurity professional with a strong technical background to support the ongoing compliance of systems. Join us in safeguarding the nation's space assets and explore the limitless opportunities that await in this dynamic role. You'll have the invaluable opportunity to be mentored in this role, ensuring not only your professional growth, but also the continued excellence of our operations. You will get to use your strong communication (verbal and written) skills and interpersonal skills in a dynamic customer centric environment, which may require sporadic off-hours support. If this is what you are looking for, keep reading.

Fun stuff you will do on the job

  • Conduct continuous monitoring and self-inspections of computer systems to ensure security compliance with official guidance and policy directives, and proactively report progress to management, make recommendations for security posture improvements, and ensure systems are ready for audits.
  • Review and interpret security vulnerability scans, communicate their contents to management and technical stakeholders, and push them to remediation.
  • Proactively report security status and concerns to management and make recommendations as appropriate.
  • Participate in and support directorate responses for ongoing information system audits.
  • Develop and update standard government security documentation such as System Security Plans, Contingency Plans, Interconnection Security Agreements, Risk Acceptances/Waivers, Privacy Threshold Analyses, Privacy Impact Assessments, and other ad-hoc documentation as needed.
  • Review and approve/deny relevant system Change Requests as needed.

Ensure configuration management is appropriate for all Information Systems (IS) software and hardware, in accordance with DoD STIGs (Security Technical Implementation Guides) and industry best practices.

  • Execute system audit log reviews in accordance with established policy requirements using Security Information and Event Management (SIEM) tools such as Splunk, Kibana, etc.
  • Assist creation of new policies/procedures as needed for directorate systems.
  • Support ad-hoc data call and reporting requirements initiated by DHS CIO, CISA and other headquarters offices.

This is You

  • Bachelor’s degree (preferable Information Security related), 14+ years experience (4 years of experience may be used in lieu of degree) with:
  • Cybersecurity, cyber engineering, information assurance, system administration, or equivalent combination to reflect knowledge and experience.
  • The Risk Management Framework, National Institute of Standards and Technology, Committee on National Security Systems cyber security requirements and guidance, and cyber security related risk management methodologies.
  • Expert knowledge and experience using DoD tools and capabilities for vulnerability assessments and compliance reporting (eMASS, XACTA, ACAS, STIGs, Nessus, SCAP, Splunk, etc.).
  • Mastery understanding of the JSIG, ICD 503, NIST Risk Management Framework (RMF), NIST SP 800-53/53A, and CNSSI 1253, and the Assessment & Authorization (A&A) process.
  • Successful participation Information Assurance self-inspections, ATO renewals, and Cybersecurity compliance inspections.
  • Working in a SAP and/or SCI environment.
  • Controlling, labeling, virus scanning, and appropriately transferring data (upload/download) between information systems at varying classification levels.
  • Experience conducting security audits/system assessments of information systems.
  • Possess certification(s) that meet or exceed DoD 8140 IAT Level II requirements (ex. CompTIA Security+, CISSP).
  • Must be willing to be nominated for access to Sensitive Compartment Information and Special Access Programs and willing to consent to a Polygraph examination.
  • Must have an in-scope security background investigation (T5 or SSBI), adjudicated for SCI eligibility and enrolled in the Continuous Evaluation program (if applicable).

You will wow us even more if you have these skills:

  • A masters degree (preferably in cyber security, Information Security or related security studies).
  • Experience with Incident Response and Disaster Recovery Procedures.
  • Experience creating/updating plans, processes, and procedures, in support of system and data security requirements, as well as establishing artifacts required for system certification.
  • Familiarity with virtualized hosting, such as VMware.
  • Extensive training or experience with Windows-based Information Systems with a working knowledge of LINUX operating systems.
  • Understanding of Contractor SAP Security Officer (CSSO) functions, responsibilities, and disciplines (i.e., PERSEC, PHYSEC, facility alarm operations, Security Training and Education, visitor access requests).
  • Program Security responsibilities to include, but not limited to: OPSEC, Program Protection, Personnel Security clearances, Security Training and Education, and Classification management.
  • Working knowledge of COMSEC responsibilities.
  • Have an understanding of DD254s to support government contracts.

Skills

  • Windows
  • Linux
  • SIEM
  • Splunk
  • Kibana
  • Nessus
  • NIST
  • SAP
  • Security+
  • CISSP
  • VMware

More jobs at Saic

All 427

Similar roles