Назад
Company hidden
5 дней назад

ISSO Specialist (Cybersecurity)

Формат работы
onsite
Тип работы
fulltime
Грейд
middle
Английский
b2
Страна
US
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
ISSO Specialist (Cybersecurity): Supporting compliance, authorization, continuous monitoring, and vulnerability remediation for large-scale communications systems with an accent on RMF, NIST controls, STIGs/SCAP, and system security documentation. Focus on assessing security controls, maintaining SSP and POA&M artifacts, scanning systems for vulnerabilities, and preparing for compliance assessments.

Location: 100% onsite in Lexington, Massachusetts; must be within 100 miles of Lexington. Flexible schedules may include 9/80 or 4/10 arrangements.

Company

hirify.global provides IT systems, cybersecurity, compliance, and software support for defense research organizations and Air Force programs.

What you will do

  • Support system security compliance activities and validate adherence to policies, procedures, regulations, and laws.
  • Develop and maintain System Security Plans, POA&Ms, Risk Assessment Reports, Continuous Monitoring Strategies, and related artifacts with Program Managers and the ISSM.
  • Track audit findings, vulnerabilities, remediation plans, milestones, and mitigation actions.
  • Conduct network, system, and application vulnerability scans, configuration assessments, and remediation activities.
  • Prepare technical documents, incident reports, security findings, and situational awareness information.
  • Participate in compliance assessments and align IT security priorities with the cybersecurity strategy.

Requirements

  • Must be a US citizen and hold an active Top Secret clearance with SCI eligibility; a CI polygraph may be required.
  • Must be able to work 100% onsite and live within 100 miles of Lexington, Massachusetts.
  • At least four years of experience in system auditing, regulatory compliance, government policies and regulations, and security control assessment.
  • At least four years of experience with STIGs/SCAP, Assessment and Authorization, RMF, continuous monitoring, and implementation and monitoring of security controls.
  • At least four years of experience with NIST 800-53, NIST SP 800-37, system categorization, system authorization, and security control selection.
  • Current DoD 8570 IAT Level II certification is required; Security+ CE is the minimum certification requirement.

Nice to have

  • Bachelor’s degree.
  • Experience with HBSS and NIST 800-171.

Culture & Benefits

  • 15 PTO days, 10 paid holidays, and 1.5 paid days for approved volunteer work.
  • One week of paid maternity or paternity leave after one year of full-time employment.
  • Up to $5,000 annually in tuition reimbursement for eligible job-related college or university courses after six months of employment.
  • 401(k) plan with Fidelity, company matching, and immediate vesting of the company match.
  • Up to $150 monthly reimbursement for eligible cell phone and internet expenses, subject to working remotely at least two days per week.
  • BYOD reimbursement of up to $1,500 every three years after six months of employment.

Hiring process

  • Phone screening followed by an extensive Zoom interview with team members.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →