Information Systems Security Officer (Cybersecurity)
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
TL;DR
Information Systems Security Officer (Cybersecurity): Managing the accreditation, auditing, and maintenance of classified information systems with an accent on Risk Management Framework (RMF) and compliance with NISPOM and DAAPM. Focus on preparing ATO packages, performing vulnerability scanning, and implementing DISA STIGs to ensure operational security posture.
Location: Onsite in Buffalo, NY. Must be able to obtain US Security Clearance.
Salary: $80,000–$115,000 Annually
Company
is a performance-driven company focused on solving complex technical challenges in a trust-based culture.
What you will do
- Prepare and maintain RMF documentation, including ATO packages, System Security Plans (SSP), and POA&Ms for classified networks.
- Perform regular auditing and continuous monitoring of Information Systems to ensure RMF/ATO compliance.
- Coordinate Configuration Management (CM) changes with the ISSM, Security Control Assessor, and Authorizing Official.
- Execute vulnerability scanning and auditing using tools like Nessus and SCAP Compliance Checker (SCC).
- Collaborate with System Administrators to implement DISA STIGs and DoD cybersecurity requirements via Windows GPOs.
- Manage classified data transfers and maintain a complete inventory of IS software and hardware.
Requirements
- Minimum 5 years of experience in Information Assurance.
- Must hold or be able to attain and maintain a US Security Clearance (Secret/Top Secret).
- Knowledge of DAAPM, NISPOM Rule, JSIG, ICD 503, RMF, and NIST Special Publications.
- Proficiency with Nessus, SCC, USB Device Control, STIGs, Windows GPOs, and PowerShell scripts.
- Bachelor's degree in IT, Computer Information Systems, or related field (or equivalent experience).
- Must have authorization to access U.S. export-controlled information.
Culture & Benefits
- Annual bonuses and employee stock purchase plan.
- Open paid time off (PTO) policy.
- Comprehensive region-specific benefits package.
- Culture of trust and empowerment to solve interesting technical challenges.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →