Назад
Company hidden
обновлено 10 дней назад

Information Systems Security Officer (Cybersecurity)

80 000 - 115 000$
Формат работы
onsite
Тип работы
fulltime
Грейд
senior
Английский
b2
Страна
US
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Information Systems Security Officer (Cybersecurity): Operating, accrediting, auditing, and maintaining information systems that process classified information with an accent on RMF documentation, continuous monitoring, compliance auditing, and DoD security requirements. Focus on maintaining ATO and SSP packages, implementing STIG controls, managing classified-system configuration changes, and mitigating device classification risks.

Location: Onsite in Buffalo, NY, with the role based at headquarters in East Aurora, NY

Salary: $80,000–$115,000 annually

Company

hirify.global operates a performance-focused environment developing and supporting technically complex systems and infrastructure.

What you will do

  • Prepare and maintain RMF documentation, including ATO packages, SSPs, risk assessment reports, SOPs, and POA&Ms for classified networks and systems.
  • Audit, update, and continuously monitor information systems to verify that security controls remain implemented and compliant with RMF and ATO requirements.
  • Maintain inventories of information systems, software, and peripheral hardware.
  • Support data transfer agents and the Facility Security Officer with removable-media file transfers under Assured File Transfer procedures.
  • Coordinate configuration-management changes with the ISSM, Security Control Assessor, and Authorizing Official.
  • Schedule and document auditing, patching, maintenance, scanning, risk mitigation, system operation, and secure disposal activities.

Requirements

  • Bachelor’s degree in information technology, computer information systems, or a related field preferred; a two-year IT degree plus four additional years of related experience may substitute.
  • At least five years of experience in information assurance.
  • Knowledge of DAAPM, NISPOM Rule, JSIG, ICD 503, RMF, and NIST Special Publications.
  • Experience with vulnerability scanning, auditing, SIEM, DLP, hardening tools, Nessus, SCAP Compliance Checker, STIGs, Windows GPOs, and PowerShell automation.
  • Experience performing data transfers and following data transfer procedures.
  • Appropriate U.S. Secret or Top Secret security clearance, or the ability to attain and maintain one; access to U.S. export-controlled information is required.

Nice to have

  • COMSEC-related experience.

Culture & Benefits

  • Performance-oriented culture focused on solving challenging technical problems.
  • Annual bonus opportunities and an employee stock purchase plan.
  • Open paid time off policy and region-specific employee benefits.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →