Information System Security Officer (Cybersecurity)
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
TL;DR
Information System Security Officer (Cybersecurity): Managing security posture for mission-critical applications across Unclassified, Secret, and Top Secret enclaves with an accent on FISMA/NIST compliance and ATO documentation. Focus on implementing cloud security controls in AWS/Azure and conducting continuous risk assessments to mitigate vulnerabilities.
Location: On-site in Clarksburg, WV. Top Secret (TS) Clearance with SCI eligibility is required.
Company
provides specialized cybersecurity and information system security services for national security missions.
What you will do
- Act as the principal cybersecurity advisor for system owners and stakeholders across multiple network enclaves.
- Design and evaluate security controls and frameworks for cloud-based systems (AWS GovCloud, Azure) to ensure data integrity and availability.
- Manage the Authority to Operate (ATO) process and maintain critical documentation, including System Security Plans and POA&Ms.
- Perform continuous monitoring, vulnerability assessments, and security audits using tools like Nessus and Splunk.
- Coordinate with the OCIO and Security Division to handle security incident reporting and response.
- Collaborate with development and infrastructure teams to resolve security problems within an Agile/SAFe framework.
Requirements
- Top Secret (TS) Clearance with SCI eligibility.
- 3-5 years of experience in cybersecurity.
- Expertise in federal frameworks: RMF, NIST 800-53, CNSS, and FISMA.
- Experience with cloud security in AWS GovCloud, C2S, SC2S, or Microsoft Azure.
- Proficiency with tools such as Splunk, Nessus, ACSA, and GRC tools (Xacta/JCAM).
- Hold a relevant certification such as Security+, CGRC, CASP, or CISSP.
Nice to have
- Advanced certifications: CISM, CAP, or AWS Certified Security – Specialty.
- Experience in high-side or multi-enclave (U/S/TS) environments.
- Familiarity with CI/CD pipelines and Infrastructure as Code tools like Terraform or Ansible.
- Knowledge of NIST 800-53 Rev. 5.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →