Information Systems Security Officer with Security Clearance - Tampa, FL, United States - By Light Professional IT Services

    Default job background
    Technology / Internet
    Description
    Overview By Light is hiring an ISSO to join our team
    This position supports the Joint Communications Support Element (JCSE), as part of a team assisting with security accreditation, risk mitigation and reporting in support of DoD policy, directives, instructions and guidance
    Develops and tracks status of RMF artifacts for system security accreditation, amendments and System Security Update Plan (SSUP)
    Support will be provided Monday-Friday, 8 hours, between the core hours of
    Responsibilities


    • Develop Security plan of action and milestones (POA&M) for all open security findings identified on the end to end enterprise infrastructure (Data Center, SATCOM Gateway, and deployed kits).
    • Develop, staff and maintain security-related statutory/regulatory documentation as required by DoDI 8510, including but not limited to: Cybersecurity Strategy (CS) and Program Protection Plan (PPP).
    • Conduct weekly meetings to track the security process, status of the accreditation package and finding resolution on the enterprise infrastructure.
    • Maintain documentation identifying what cybersecurity STIG, checklist, or control requirements apply for every component or software in the enterprise infrastructure (Data center, SATCOM Gateway, and deployed kits)
    • Administration of IA scans with appropriate and approved tools (e.g
    Security Content Automation Protocol (SCAP), Assured Compliance Assessment Solution (ACAS), etc.) of all items as directed
    Scans shall be run using the most recent security definitions of each tool.

    • Track all implementation information for assurance directed guidelines for all hardware as well as applicable software ensuring proper security for the JCSE Enterprise
    Provide tracking and summary reports based on findings to leadership

    Implementation actions include but are not limited to STIGs, compliant patch implementation/management, Information Assurance Vulnerability Management (IAVM) compliance, integration/ implementation of network or firewall approved devices, and react appropriately to cyber threats.


    • Support and perform DoD Risk Management Framework (RMF) in accordance with CNSSI 1253 and NIST all revisions) for IA controls; 8570/8140 for IA Workforce training and DCID 6/3 for protection of sensitive compartmented information

    This also includes the updates required for the JCSE packages and all updated instructions which support the Assess and Authorize (A&A) process.


    • Assist with developing and maintaining system policies and procedures for network security, virus protection, user accounts, maintenance and utilization.
    • Provide technical support and guidance to the cybersecurity team as part of maintaining the JCSE IA processes and procedures in support of computer network defense in-depth protection for the JCSE enterprise infrastructure
    Recommend network configuration, policy, training, operational or other changes/updates based on assessed risks.

    • Coordinate with internal and external organizations, agencies and activities to support resolution of security issues, accreditation and waiver requests that impact the ability to obtain connection approval.
    • Recommend connection approval, disapproval or modification based on security risks and system vulnerabilities.
    • Provide system administrator (ex

    Linux, Windows, Firewalls, Intrusion Prevention/Detection Systems, End Point Security ) support installing, operating, maintaining, troubleshooting, administrating, and cybersecurity hardening of operating systems on both the classified and unclassified systems (SIPR and NIPR).


    • Maintain configuration documentation for the JCSE Enterprise to include: network diagrams, technical sensor/administrative & policy POCs, and related information.
    • Ensure proper protection of data in transit, in accordance with DoD policy
    Required Experience/Qualifications


    • Bachelor's degree and 8-12 yrs
    of relevant experience; additional years of applicable experience may be accepted in lieu of a degree.

    • DoD 8570 IAM Level 1 Certification (SEC+, CAP, GSLC) Special Requirements/Security Clearance
    • TS/SCI
    • Support will be provided Monday-Friday, 8 hours, between the core hours of