ASRC Federal Holding Company logo

Information System Security Officer (Isso) - Senior

ASRC Federal Holding Company

  • Aberdeen Proving Ground, MD
  • 4 days ago

    Highlights

    Bachelor's degree (BA/BS) in Computer Science, Information Technology, Engineering, or a related field or 4 additional years of experience (for a total of 5 years) in lieu of the degree5 or more years of hands-on RMF EMASS Authorization dutiesWorking knowledge of DoD and Army cybersecurity regulations including Army Regulation 25-2, DoD 8140, and DoD RMF policyExperience with Active Directory account management and STIG/SRG audit processesFamiliarity with the Army Account Validation System (AVS) or equivalent DoD workforce compliance tracking platforms. Direct experience with eMASS, POA&M and RMF processes and responsibilitiesExperience serving as an Enhanced Trusted Agent for PKI hardware token issuanceExperience performing Software Assurance or Hardware Assurance reviews for DoD networksFamiliarity with NSA and Army data sanitization and destruction policyExperience coordinating Negligent Disclosure of Classified Information or classified spill incident responseCISSP, CASP+, or CISM certificationExperience supporting DEVCOM or Army G-6 cybersecurity programs.

    Numbers & Facts

    LocationAberdeen Proving Ground, MD
    IndustryAerospace and Defense
    Company Size5,000 to 9,999 employees
    Year Founded2003
    Websitehttp://www.asrcfederal.com

    Description

    Program:

    DEVCOM-CBC G-6

    Location:

    On-site at Aberdeen Proving Ground, MD

    US Gov. Security Clearance:

    A DoD Secret or higher

    Position Type:

    Full-Time, Exempt

    ASRC Federal Technology Solutions LLC is looking for an experienced Information System Security Officer with an active Secret clearance or higher to support their work with DEVCOM-CBC G-6. This position supports the development, implementation, and maintenance of cybersecurity policies, standards, and procedures, ensuring compliance with applicable Department of Defense (DoD), Army, and DEVCOM CBC regulations.In this role, you will provide cybersecurity support to the DEVCOM-CBC G-6 Cybersecurity Branch, focusing on all aspects of Risk Management Framework (RMF) activities, cybersecurity assessments, and incident response. This role requires a deep understanding of cybersecurity principles, a strong analytical ability, and excellent communication skills to effectively convey complex information to both technical and non-technical audiences, while maintaining a broad portfolio of compliance and accounts management responsibilities across unclassified, classified, and standalone systems.KEY RESPONSIBILITIES

    Maintain current Authority to Operate (ATO) status for DEVCOM systems and provide RMF guidance and support to other ACC locations with similar systems.Develop, update, and/or modify the system-level artifacts (e.g., TTPs, plans, policies, procedures, hardware/software lists, data flow, system architecture diagrams, PIAs, Ports/Protocols/Services, MOA/MOU, etc...) and ensure they are associated with corresponding controls in eMASS.Obtain, run, analyze, and import all applicable vulnerability scanners and compliance checkers as required, including STIGs, Nessus/ACAS Scans, etc...Track and report IAVAs related to DEVCOM systems.Create, modify, and/or maintain all aspects of the implementation plan and test results, as defined by DOD, Army, NETCOM, and DEVCOM requirements.Manage Plans of Action and Milestones (POA&M), including development, status updates, milestone tracking, and closure.Manage assigned network packages within eMASS and maintain accurate, current authorization documentation.Create, modify, and/or maintain all aspects of CONMON.Utilize existing or develop custom solutions to facilitate RMF requirements, reduce timelines and provide up-to-date status reporting of complianceUpdate and track cybersecurity test results, implementation plans, and risk assessments.Evaluate STIG checklists and document compliance status, deficiencies, and required remediation actions.Perform first-response coordination for Negligent Disclosure of Classified Information incidents in accordance with organization SOPs for incident responseConduct vulnerability management activities, including identifying, tracking, and coordinating corrective actions.

    REQUIRED QUALIFICATIONS

    Bachelor's degree (BA/BS) in Computer Science, Information Technology, Engineering, or a related field or 4 additional years of experience (for a total of 5 years) in lieu of the degree5 or more years of hands-on RMF EMASS Authorization dutiesWorking knowledge of DoD and Army cybersecurity regulations including Army Regulation 25-2, DoD 8140, and DoD RMF policyExperience with Active Directory account management and STIG/SRG audit processesFamiliarity with the Army Account Validation System (AVS) or equivalent DoD workforce compliance tracking platforms

    PREFERRED QUALIFICATIONS

    Direct experience with eMASS, POA&M and RMF processes and responsibilitiesExperience serving as an Enhanced Trusted Agent for PKI hardware token issuanceExperience performing Software Assurance or Hardware Assurance reviews for DoD networksFamiliarity with NSA and Army data sanitization and destruction policyExperience coordinating Negligent Disclosure of Classified Information or classified spill incident responseCISSP, CASP+, or CISM certificationExperience supporting DEVCOM or Army G-6 cybersecurity programs

    CLEARANCE LEVEL

    This position requires an active Secret clearance. An interim Secret clearance is acceptable until the full clearance is granted.

    EDUCATION REQUIREMENTS

    Bachelor's degree in Information Technology, Computer Science, or a related field or 4 additional years of experience in lieu of the degree

    CERTIFICATION

    DoDI 8140.03 qualification for DCWF Work Role Information Systems Security Manager (722 Intermediate). Accepted foundational qualifications include certifications mapped to Work Role 722 Intermediate in the current DoD 8140 Qualification Matrix, such as SecurityX, CASP+, CCISO, CCSP, CISSO, Cloud+, Security+, and SSCP.

    Preferred

    CISSPSecurityXSSCP

    WORK ENVIRONMENT AND PHYSICAL DEMANDS:

    This position primarily operates in a professional office environment at Aberdeen Proving Ground, MD, working within or alongside the DEVCOM-CBC G-6 Cybersecurity Branch. The role involves extended use of computer equipment and may require the candidate to move between buildings on the installation to support users and coordinate with government staff. Some work may involve access to classified facilities and systems. Reasonable accommodations may be made to enable individuals with disabilities to perform the essential functions of this position.

    Benefits

    Military Leave, On Site Cafeteria, Parking, Prescription Drug Coverage, Professional Development, 401K, Employee Referral Program, Flexible Spending Accounts, Employee Events, Tuition Reimbursement, Work From Home, Life Insurance, Merchandise Discounts

    About Company

    ASRC Federal comprises a family of companies that provide mission-critical services to federal government agencies dedicated to defense, civil and intelligence support. Our customer-focused service delivery model and emphasis on operational excellence are foundational elements infused in all our companies. The reliability and quality of day-in, day-out service delivery from our family of companies ensure our customers that we keep our sights on their mission-critical priorities.

    Similar Jobs

    See more jobs