ISSO - Information Systems Security Officer
AnaVation
Eligibility Criteria
-
Associates Degree in Computer Security or related field of study; (ISC)2 Information Security Certification(s) (e.g., CISSP, CAP, etc.); or in lieu of education, five (5) years of documented experience that addresses all requirements of the position.
-
Minimum of 3 years of experience assessing and documenting results for systems, infrastructure, and applications in on-premises and cloud environments, including AWS GovCloud and/or Azure GovCloud.
-
Experience evaluating systems against NIST SP 800-53 security controls and NIST SP 800-171 requirements.
-
Experience supporting Risk Management Framework (RMF) processes, including the preparation and maintenance of authorization packages and supporting artifacts.
-
Strong knowledge of FISMA requirements and Federal information assurance and cybersecurity compliance practices.
-
Experience preparing, reviewing, and maintaining security documentation such as CMP, IRP, ISCP, and POA&M.
-
Experience identifying vulnerabilities and coordinating remediation efforts with infrastructure, development, and program teams.
-
Experience reviewing and interpreting results from vulnerability scans, SCAP scans, STIG assessments, and patch/compliance activities.
-
Familiarity with both on-premises and cloud-based environments, with AWS preferred.
-
Strong understanding of security controls, risk mitigation, incident response, configuration management, and continuous monitoring practices.
-
Excellent verbal and written communication skills, with the ability to clearly document requirements, findings, risks, and recommendations.
-
Ability to work collaboratively with Government customers, program managers, technical teams, and other ISSOs.
-
Active Top Secret (TS) clearance with eligibility for Sensitive Compartmented Information (SCI) with ability to obtain CI polygraph
-
Certifications: CompTIA Security+ or CISSP or CISM
-
Experience using a cyber risk and compliance management system, such as Xacta, RiskVision, or similar platforms.
-
Familiarity with scan types and compliance tools including patch/update reviews, SCAP, and DISA STIG assessments to help ensure patch and configuration compliance.
-
Working knowledge of operating systems, network security, and application security to support the implementation of information security and assurance principles.
-
Knowledge of Splunk software and related tools.
-
Knowledge of TACLANE, encryption devices, and COMSEC technologies.
About AnaVation
-
