What are the responsibilities and job description for the Information System Security Officer (Cybersec position at SandTech Solutions LLC?
Requirements:
- Active TS/SCI Security Clearance
- Candidate must possess the ability and eligibility to gain access to a secured USG facility
- Current DoD 8570 baseline certification for IAT II (one of the following: GSEC, Security , SCNP and SSCP)
- Bachelor’s degree or equivalent work experience and certifications
- 3-5 years of Cyber Security experience
- 2 years of IT experience (Networking/System Administration)
- Working knowledge of security system controls, policies, technical security safeguards, and operational security measures
- Familiarity with DoD STIG process.
- Excellent verbal and written communication skills.
- Executing the security assessment and authorization (or ATO) process with independent assessors
- Executing Continuous Monitoring and maintaining the security posture of IT systems day to day
Desired Skills:
- Past or current ISSM/ISSO experience
- DoD IS knowledge and experience
- Must be highly organized and detail oriented
- Must be able to take initiative and work independently or as a member of a team.
- Proficiency in the following areas: multi-tasking, critical thinking; and the ability to work quickly, efficiently, and accurately in a dynamic and fluid environment
- Familiar with NIST publications, specifically RMF and NIST controls
- Experience developing A&A documentation from scratch and performing assessments; RMF step 1 - 4
Primary Responsibilities:
Reasonable accommodations may be made to enable individuals with disabilities to perform the essential functions
- Must be able to work in a constantly changing regulatory environment with short-, mid-, and long-term timelines for remediating any non-compliance
- Must be able to work well within a team environment and able to adapt quickly to change
- Identify key stakeholders in A&A efforts and ensure system documentation reflects current system security configurations to include hardware and software components, data flow, interconnections, and ports, protocols, and services, etc.
- Maintain cybersecurity procedures and processes as assigned
- Able to analyze, interpret, and apply Federal cybersecurity guidance to customer needs
- Communicate the security posture of systems through designated reporting mechanism
- Assist in preparation and review documentation to include System Security Plans (SSPs), Risk Assessment Reports (RAR), and other Assessment & Authorization (A&A) artifacts
- Assist in the research and address information security issues as required, and develop and maintain the Plan of Action and Milestones (POA&M) and support remediation activities
- Develop and advise development of Assessment and Authorization (A&A) artifacts and security documentation to include, but not limited to System Security Plans (SSP), Plan of Action and Milestone (POAM), Contingency Plan, Incident Response Plan, Configuration Management Plan
- Assist with pre-assessment preparation
- Perform Risk Management Framework (RMF) activities to achieve Authority to Operate (ATO).
- Perform continuous monitoring of security controls to ensure that they are implemented correctly, operating as intended, and producing the desired outcome with respect to meeting the cybersecurity requirements for assigned IT systems.
- Advise system owners on all matters, technical and otherwise, involving the security of assigned IT systems.
- Strong verbal and written skills required providing management status reports and document system changes.
- Analyze problems and provide focused solutions to effectively communicate information to various audiences verbally and through written communications.
Physical Requirements:
- Prolonged periods of sitting at a desk and working on a computer.
- Must be able to lift up to 15 pounds at times.
Job Information Summary:
Location: National Military Command Center (NMCC) - The Pentagon
Job Type: 40 hours per week
At SandTech, our employees enjoy benefits to support their physical, financial, and emotional wellness. These benefits include comprehensive medical, dental and vision plans, 401(k), life insurance, paid time off program with paid holidays and various wellness programs. Additionally, our career path planning assists employees with their professional goals.
AAP/EEO Statement
It is the policy of SandTech Solutions to provide an equal employment opportunity for all applicants and employees. The Company does not unlawfully discriminate on the basis of race, religion, color, sex, gender identity, sexual orientation, national origin, ancestry, age, medical condition, disability, workers’ compensation status, or veteran status.