Description
Description
SAIC has an immediate opening for a highly motivated Information System Security Officer (ISSO), classified as the IT Security Specialist, Level I level, supporting the security and compliance of information systems under a government contract.
Under close direction of a manager, team leader, or more experienced specialist, the incumbent will apply basic technical knowledge in the performance of system certifications/accreditations and information security-related tasks. The ideal candidate has experience with NIST and RMF frameworks, security compliance, continuous monitoring, and vulnerability management.
Key Responsibilities
- Apply basic technical knowledge in support of system certifications, accreditations, and information security tasks under close supervision of senior staff
- Assist in developing, documenting, reviewing, and maintaining RMF security documentation, including: System Security Plans (SSPs), Contingency Plans (ISCPs), Incident Response Plans (IRPs), Business Impact Analyses (BIAs), System Characterization Documents (SCDs), Configuration Management Plans (CMPs), Privacy Impact Analyses (PIAs), Plan of Action & Milestones (POA&Ms), Account Management Plans (AMPs), and Security Impact Analyses (SIAs)
- Create, track, and maintain POA&Ms for multiple information systems; work with stakeholders and ISSMs to ensure accurate documentation, remediation, and communication throughout the POA&M lifecycle
- Assist in conducting risk analysis of planned and installed information systems to identify vulnerabilities and threats; recommend mitigation actions
- Assist in conducting vulnerability scanning of information systems; compile compliance reports based on scan findings; validate scan accuracy and identify false positive results
- Assist in the development of security contingency plans, disaster recovery procedures, and delivery of incident response training
- Gather artifacts and support Continuous Monitoring Assessments, Security Assessments, and internal/external security audits
- Provide cybersecurity guidance to project teams and stakeholders through system development, configuration, and maintenance
- Prepare and present status reports on findings, POA&M progress, and RMF activities to management and stakeholders
Qualifications
Required Experience
Bachelor's degree in computer science, Information Systems, Information Technology, Cybersecurity, or a related discipline
- 4 years of experience may replace a completed bachelors degree
- Candidates must obtain a Public Trust Clearance prior to start date.
- Minimum of three (3) years of combined IT experience, including at least one of the following:
- a. Installing, maintaining, or managing IT network devices, physical/virtual servers, or operating system/database platforms (e.g., Linux, Windows, UNIX, Solaris, Oracle, SQL, MySQL);
- b. Supporting information systems as an Information Security or Cybersecurity professionals
The following competencies are considered critical to successful day-to-day performance in this role.
Working knowledge of NIST SP 800-30, 800-37, 800-40, and 800-53, and/or other RMF frameworks
- Familiarity with common vulnerability scoring systems (e.g., CVSS) and vulnerability scanning tools (e.g., Nessus, Qualys)
- Ability to differentiate between software flaws and misconfiguration issues
- Strong written and verbal communication skills; ability to work effectively across technical and non-technical teams
- Strong attention to detail with excellent organizational and documentation skills
The following credentials and experience are not required but will strengthen a candidate's application and contribute to immediate productivity in the role:
One or more certifications: Security+, SSCP, CAP/CGRC, CISA, CISSP, or GSEC
- Experience with RMF system lifecycle documentation and implementation
- Experience with cybersecurity or information system tracking tools
- Knowledge of configuration management and change control processes
- Proficiency with Microsoft Office Suite
Apply on company website