What are the responsibilities and job description for the System Security Officer position at Dynanet Corporation?
Description
Position Details:
Job Title: System Security Officer
Job Type: Full-time
Location: Remote, DC
Revised: 3/26/2025
Dynanet Corporation Overview:
Dynanet started with a focus on IT infrastructure and operations, helping organizations enhance their networks and overcome the limitations of 1990s technology. From strengthening communication channels to introducing innovative ways to collaborate and share information, Dynanet played a crucial role in shaping the early stages of digital transformation. The company’s efforts helped organizations build the very fabric of connectivity that now powers our modern world. Over the last three decades, Dynanet has grown into a trusted partner for organizations looking to innovate boldly and transform seamlessly. While technology continues to evolve and unlock new opportunities, for nearly 30 years, Dynanet remains committed to delivering cutting-edge solutions that drive lasting change for its customers. Through agility, foresight, and an unwavering dedication to excellence, Dynanet continues to empower organizations to thrive in a rapidly changing digital landscape. Our story is more than just a story of technology - it’s a story of vision, growth, and transformation that has shaped the past and continues to pave the way for the future.
About the Role:
Dynanet is seeking a qualified System Security Officer (SSO) to support the Centers for Medicare & Medicaid Services (CMS). The SSO will proactively manage and enhance the security posture of CMS systems by identifying, analyzing, and addressing vulnerabilities, participating in security tool enhancement efforts, and ensuring compliance with CMS-specific security standards.
Roles & Responsibilities:
- Vulnerability Management: Perform thorough reviews of vulnerability management tools to identify false positives and non-exploitable vulnerabilities.
- Security Testing: Conduct Static Application Security Testing (SAST) and Dynamic Application Security Testing (DAST) using internal security tools; document and report findings to development and operations teams.
- Security Tooling Enhancement: Engage with security pilot programs to test and adopt emerging security tools and hardening techniques.
- Cross-Functional Awareness: Maintain awareness of development, business, and operations activities to assess potential security impacts and provide informed recommendations.
- Compliance Assurance: Collaborate with internal stakeholders to ensure integration of security best practices across all stages of the Software Development Life Cycle (SDLC).
Requirements
Preferred Professional Skills:
- CMS Experience: Demonstrated experience working within CMS or with federal agencies focusing on security compliance.
- Regulatory Knowledge: Working knowledge of: CMS Acceptable Risk Safeguards (CMS ARS), CFACTS (CMS Governance, Risk, and Compliance tool), and CSRAP (CMS Third-Party Security Assessment process)
- Framework Familiarity: Familiarity with CMS security policies, processes, and federal security frameworks (e.g., FISMA, NIST 800-53).
- Analytical Skills: Strong analytical and communication skills, with the ability to effectively translate security findings to technical and non-technical audiences.
- Team Collaboration: Ability to operate independently while being a proactive and collaborative team member.
Dynanet Team Requirements and Expectations:
- Possess Strong written and verbal communication skills.
- Highly organized with an ability to prioritize, balance, and effectively advance multiple competing priorities in a high-volume, fast-paced environment.
- Ability to interact in a professional and collaborative manner with fellow Dynanet Teammates and the clients, and business partners that we work with.
- Ability and desire to challenge and educate yourself to support and advance IT services delivery in the Federal agencies we serve.
- Excellent judgment and creative problem-solving skills.
- Respond to team members and client requests via email, MS teams, or other communication means during core business hours.
- Active listening skills to understand clients' needs, and collaboration skills to work with other developers and designers.
Employee Benefits Overview:
- Industry Competitive Compensation
- Medical and Dental Insurance
- Paid Time Off/Holidays
- 401(k) Retirement Plans with Matching
- Remote Work
- Paid Training
- Employee Referral Program
- Employee Development Program