Back to Search Results
Get alerts for jobs like this Get jobs like this tweeted to you
Company: SAIC
Location: Oklahoma City, OK
Career Level: Associate
Industries: Technology, Software, IT, Electronics

Description

Description

SAIC has an immediate opening for a highly motivated Information System Security Officer (ISSO), classified as the IT Security Specialist, Level I level, supporting the security and compliance of information systems under a government contract. 

 

Under close direction of a manager, team leader, or more experienced specialist, the incumbent will apply basic technical knowledge in the performance of system certifications/accreditations and information security-related tasks. The ideal candidate has experience with NIST and RMF frameworks, security compliance, continuous monitoring, and vulnerability management.

 

Key Responsibilities

  • Apply basic technical knowledge in support of system certifications, accreditations, and information security tasks under close supervision of senior staff
  • Assist in developing, documenting, reviewing, and maintaining RMF security documentation, including: System Security Plans (SSPs), Contingency Plans (ISCPs), Incident Response Plans (IRPs), Business Impact Analyses (BIAs), System Characterization Documents (SCDs), Configuration Management Plans (CMPs), Privacy Impact Analyses (PIAs), Plan of Action & Milestones (POA&Ms), Account Management Plans (AMPs), and Security Impact Analyses (SIAs)
  • Create, track, and maintain POA&Ms for multiple information systems; work with stakeholders and ISSMs to ensure accurate documentation, remediation, and communication throughout the POA&M lifecycle
  • Assist in conducting risk analysis of planned and installed information systems to identify vulnerabilities and threats; recommend mitigation actions
  • Assist in conducting vulnerability scanning of information systems; compile compliance reports based on scan findings; validate scan accuracy and identify false positive results
  • Assist in the development of security contingency plans, disaster recovery procedures, and delivery of incident response training
  • Gather artifacts and support Continuous Monitoring Assessments, Security Assessments, and internal/external security audits
  • Provide cybersecurity guidance to project teams and stakeholders through system development, configuration, and maintenance
  • Prepare and present status reports on findings, POA&M progress, and RMF activities to management and stakeholders

 

Qualifications

Required Experience

 

  • Bachelor's degree in computer science, Information Systems, Information Technology, Cybersecurity, or a related discipline 

  • 4 years of experience may replace a completed bachelors degree
  • Candidates must obtain a Public Trust Clearance prior to start date.
  • Minimum of three (3) years of combined IT experience, including at least one of the following:
    • a. Installing, maintaining, or managing IT network devices, physical/virtual servers, or operating system/database platforms (e.g., Linux, Windows, UNIX, Solaris, Oracle, SQL, MySQL); 
    • b. Supporting information systems as an Information Security or Cybersecurity professionals

 

The following competencies are considered critical to successful day-to-day performance in this role. 

  • Working knowledge of NIST SP 800-30, 800-37, 800-40, and 800-53, and/or other RMF frameworks

  • Familiarity with common vulnerability scoring systems (e.g., CVSS) and vulnerability scanning tools (e.g., Nessus, Qualys)
  • Ability to differentiate between software flaws and misconfiguration issues
  • Strong written and verbal communication skills; ability to work effectively across technical and non-technical teams
  • Strong attention to detail with excellent organizational and documentation skills

 

The following credentials and experience are not required but will strengthen a candidate's application and contribute to immediate productivity in the role:

  • One or more certifications: Security+, SSCP, CAP/CGRC, CISA, CISSP, or GSEC

  • Experience with RMF system lifecycle documentation and implementation
  • Experience with cybersecurity or information system tracking tools
  • Knowledge of configuration management and change control processes
  • Proficiency with Microsoft Office Suite

 


 Apply on company website