Description
Description
SAIC seeks an Information Systems Security Officer (ISSO) to join our team of professionals providing technical and program services to the U.S. Government (USG). SAIC provides research, engineering, design, analysis, acquisition, development, integration, test, and operations support USG Intelligence Community (IC) and Department of Defense (DoD) customers. We support development and delivery of next generation and generation after next national security systems based on land, at sea, in air, and in space.
The ISSO sought here serves a USG Program Office leading Research & Development (R&D) of evolutionary, revolutionary, and transformational Experimental Satellite Ground solutions. This position provides Systems Engineering & Technical Advisory (SETA) support services. This position has a target salary range of $120,000 to $160,000. Your responsibilities include some or all the following:
Support systems security authorization and continuous monitoring activities for assigned systems
Support the preparation, review, and submission of security authorization packages, including SSPs, POA&Ms, and related authorization artifacts
System Patch Management: Utilize patch deployment tools and hardening guidelines to ensure security compliance of the customer's networked and cloud compute infrastructure
System Hardening: Apply and verify Security Technical Implementation Guides (STIGs) and vendor hardening guides to secure operating systems and applications
Vulnerability Scanning & Remediation: Conduct regular vulnerability scans to detect vulnerabilities and developer & implement remediation actions
Cloud Security: Experience with cloud-based patching and hardening techniques leveraging commercial cloud provider tools and best practices
Security & Configuration Management: Implement security controls (e.g. VLANs, firewall rules, and encryption) to protect network systems and data
Risk Management: Analyze vulnerability scan findings to identify risks, develop remediation plans, and track progress
Documentation: Maintain security documentation, including system baseline, hardening procedures, and all hardware software changes
Track systems risks, assessment findings, POA&M activities, and remediation status to ensure timely resolution
Facilitate recurring stakeholder meetings and provide compliance status updates, reporting, and risk summaries
Collaborate with FVEY partners to enhance security posture and best practices across a federated network
Qualifications
Required Qualifications
Active TS/SCI clearance with Poly
Must have bachelor's degree with minimum of nine (9) years of relevant work experience or seven (7) years with master's degree
- Information security certification: Security+, CISM, or CISSP
Experience with vulnerability assessment tools (Nessus, ACAS, or SCAP)
Experience with scripting languages for automating patches and hardening tasks
Knowledge of NIST Risk Management Framework (RFM)
Critical thinking, problem-solving, and analytical skills
Interpersonal and communications skills for written reports, group discussion, and oral presentations
Desired Qualifications
Certifications: Cisco, AWS, or Microsoft
Knowledge of network protocols, routing, switching, and firewalls
Proficient skills and experience work in Scaled Agile Framework (SAFe) environment
Proficient skills using JIRA and Confluence
Knowledge, skills, abilities, and/or experience in one of more of the following:
R&D of satellite ground technologies and systems
System acquisition, design, development, integration, test, and/or flight operations
Small Satellite (SmallSat) systems (single vehicles, clusters, and/or constellations)
Experience working in an NRO SPO
Apply on company website