Назад
Company hidden
7 дней назад

Information Security Officer 2 (Cybersecurity)

82 300 - 220 000$
Формат работы
onsite
Тип работы
fulltime
Грейд
middle
Английский
b2
Страна
US
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Information Security Officer 2 (Cybersecurity): Monitoring and authorizing multiple classified information systems, maintaining security authorization documentation, and managing configuration baselines with an accent on RMF compliance, continuous monitoring, incident response, and vulnerability assessment. Focus on identifying architecture flaws with STIG, SCAP, and Nessus, coordinating system changes, and supporting recovery and authorization activities for systems requiring an active TS//SCI clearance with polygraph.

Location: Cambridge, Massachusetts, United States

Salary: $82,300–$220,000 base salary per year

Company

hirify.global is an independent nonprofit research and development company working on national-security, space, biomedical, and other complex engineering challenges.

What you will do

  • Support continuous monitoring and authorization of multiple classified information systems under the direction of the ISSM.
  • Maintain security authorization packages, system security plans, documentation, configuration baselines, and change records.
  • Conduct audits, continuous monitoring, incident response, recovery reviews, and compliance assessments.
  • Coordinate hardware, software, and firmware changes with the ISSM and AO/DAO and assess their impact on system authorization.
  • Identify system architecture flaws using STIG, SCAP, Nessus, and related security tools.
  • Mentor and coach ISSO 1 personnel and assume ISSM responsibilities when required.

Requirements

  • Bachelor’s degree in Information Technology or a related field, or equivalent industry experience.
  • 3–5 years of relevant industry experience.
  • IAM I/IAT II certification or higher.
  • Understanding of RMF, NIST SP 800-53, JSIG, DAAG, ICD 503, incident response, vulnerability management, SCAP, STIG, and security-relevant tools.
  • Understanding of information technology fundamentals, network types, servers, switches, and firewalls.
  • Active TS//SCI security clearance with polygraph is required, and the clearance must be maintained.

Nice to have

  • Experience auditing systems using PowerShell or Bash.
  • Experience with basic scripts, queries, and managing POA&Ms with ISSMs.

Culture & Benefits

  • Collaborative, multidisciplinary research and development environment.
  • Workplace flexibility programs supporting work-life balance.
  • Employee clubs, including photography and yoga.
  • Health and finance workshops, off-site social events, and discounts to local museums and cultural activities.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →