Live opening · Posted 11 days ago

Technical Information System Security Officer (ISSO) - W2 Position

RSA Tech · United States (Remote)
Linkedin No
You are 11 days behind. JobBeeper subscribers saw this role while it was still new.

At a glance

The key details from the original listing.

Posted 11 days ago
CompanyRSA Tech
LocationUnited States (Remote)
Work modeNo
SourceLinkedin
Listed11 days ago

Your early-applicant advantage

Live timing from JobBeeper.

Live data
7 min from Linkedin publishing this role to us finding it
13 min median time from a role going live to a subscriber being told
6 hours subscribers had this role before this page existed
71,508 roles found in the last 24 hours — the newest are not on this site yet
Start your free trial →

About the role

Description supplied by the original job listing.

Job: Technical ISSO
Location: REMOTE
Duration: Contract to Hire
Clearance and Location Requirements:
Able to be cleared for a Public Trust clearance.
Overview / Summary:
The candidate will provide technical expertise on Security control implementations and development of Information Security procedures for systems and applications. Although you will be the ISSO for these systems after they are authorized for use, candidates will also be required to perform pre-assessment activities, including a detailed analysis of the technology stacks comprising the vendor solutions. This position requires a fundamental understanding of engineering-compliant architectures and solutions. You will be part of a team working to assess vendor systems for technical compliance with NIST and agency standards.
Role Description:
Perform detailed architecture and technical design reviews on the full stack for vendor solutions (examples of some areas requiring detailed analysis):
Assess and document encryption standards for encryption at rest and in transit (what cipher sets are used? What type of encryption? etc)
Assess and document authentication mechanisms for all points in the system (Is MFA implemented at all authentication points? Is the MFA solution approved and compliant with NIST and agency standards?)
Assess and document session management and control for all layers of the system
Schedule and lead screen-sharing sessions with the vendors to gain a full understanding of the technology stack, document all security-relevant information required for the architecture review and create a full report for presentation to the CISO
Serves as the IT security POC (ISSO) for assigned systems to ensure agency information systems comply with FISMA OMB and agency Policies.
Oversee and manage relationships for assigned systems that may be contractor owned and contractor operated, ensuring vendors comply with agency security and privacy requirements.
Assist stakeholders with IT security-related activities to ensure project deadlines are met.
Ensure security activities are implemented throughout the SDLC from beginning to end.
Ensure all systems are operated, maintained, and disposed of IAW documented security policies and procedures, including but not limited to Assessment & Authorization (A&A).
Support the development and maintenance of all security documentation such as the System Security Plan, Privacy Impact Assessment, Configuration Management Plan, Contingency Plan, Contingency Plan Test Report, POA&M, annual FISMA assessment, and incident reports.
Research assigned IT security systems to provide insight into IT security architectures and IT security recommendations for assigned systems.
Report and respond to security incidents.
Assess vulnerabilities to ascertain if additional safeguards are needed and ensure systems are patched, and security hardened at all levels of the “stack,” and monitor to see that vulnerabilities are remediated as appropriate.
Promote Information Security Awareness and provide training.
Required Qualifications & Education:
Six (6) years of experience in the IT security field
Two (2) years of experience supporting A&A (NIST 800-53) and compliance activities
Four (4) years of hands-on technical experience as a System Architect or Security Engineer
Bachelor’s degree in Computer Science or a related field or an additional two years of industry experience.
Security+, CISSP, CISM, CISA, or equivalent Security certification.
Technical expertise with Nessus Tenable Security and Invicti reports.
Experience in reviewing 3rd party security assessment reports
Have detailed knowledge and experience with NIST Policies, Governance, Security Planning and Architecture, FISMA Compliance, RMF, Incident Analysis, and General Security Best Practices.
Ability to communicate, written and oral, to technical and non-technical stakeholders.
Possess strong written and oral communication skills to support customers, internal stakeholders, peers, and public audiences.
Desired Qualifications:
Direct experience with NIST 800-171 is preferred
Strong communication skills to interact with senior managers, junior staff, and business unit (non-technical) customers.

Work arrangement
No

Get JobBeeper Mobile App

Never miss a job opening! Get instant job alerts on your phone.

Subscribers see fresh openings within minutes. Download the JobBeeper App on Google Play to get real-time push notifications and apply before anyone else.

⚡ Instant Push Alerts 🎯 Tailored Filters 🚀 Direct Employer Links
GET IT ON Google Play

More openings worth a look

Recently tracked roles with full details and direct application links.

6 roles
Good roles move before most people even see them. Tell JobBeeper what you want and get fresh matches delivered in minutes.
Start your free trial →
⚡ Get fresh job alerts 📱 Get App