Members of the ISSO team support the assessment and authorization (A&A) process for information systems. The successful candidate will have requisite cyber security experience with methods and tools used to improve the s…
Sign up with Clera and we'll reach out the moment a role actually fits you — no more spraying applications into the void.
Full-time
bachelor degree
Posted 25d ago
~40 hrs/week
Responsibilities
Support the assessment and authorization process for information systems to improve the security posture of critical systems. Collaborate with developers and engineers to design and implement secure hybrid-cloud environments.
Requirements
Requires an active TS/SCI with Polygraph and a bachelor's degree or equivalent experience in Cybersecurity or IT. Candidates must have at least 5-8 years of cybersecurity expertise and proficiency with vulnerability tools and NIST standards.
Full job description
Members
of the ISSO team support the assessment and authorization (A&A) process for
information systems. The successful candidate will have requisite cyber
security experience with methods and tools used to improve the security posture
of critical systems such as identifying risks, vulnerabilities, anomalies,
patching, auditing, automation, security hardening, best practices, and
evaluating system changes. In addition, the candidate will collaborate with
developers and engineers on projects to create a secure hybrid-cloud
environment.
Requirements
Mandatory Requirements:
Candidate must have an active TS/SCI with a Polygraph
Bachelor’s degree in Cybersecurity, IT, or other related
technical discipline; or the equivalent combination of education, technical
training, or work/military experience
Minimum eight (8) years applied experience or relevant
degree plus five (5) years of Cybersecurity expertise with demonstrated ability
to successfully shepherd IT projects of varying types through the authorization
lifecycle
Strong verbal and written communication/cooperation within a
team context
Supported control implementation assessment and reporting
and monitoring processes using cyber security and assessment management systems
Understanding of perimeter controls (firewalls), access
control mechanisms, and network architectures
Demonstrated essential understanding of methods for
hardening operating systems (e.g., CentOS, RedHat, Windows)
Skilled with and/or demonstrated technical aptitude with
vulnerability and risk assessment tools such as Elasticsearch or Splunk SIEMs,
Rapid7 Nexpose, and IDS/IPS monitoring and alerting
Strong understanding of methodologies for researching and
documenting software and hardware vulnerabilities
Experienced working closely with stakeholders, developers,
and external teams, including customer security manages (ISSMs), organizational
leadership, and key personnel
Applied experience with the customer’s assessment and
authorization tracking tools
Knowledgeable regarding Common Control Provider (CCP)
requirements and methodology
Demonstrated knowledge and experience with networking
topologies and hardware, including commonly used/referenced network devices,
IDS and IPS, etc.
Applied experience with open-source and commercial tools and
systems such as nmap, Nessus, Rapid7, Splunk, Nipper, Elasticsearch, Jira,
Confluence, Cisco, VMware, Citrix, or Trellix, as well as GOTS tools used by
the customer
Demonstrated experience with the design and implementation
of defense-in-depth solutions
Skilled in cross-team collaboration and effective
communication to fulfill specific authorization requirements
Demonstrated skill documenting processes and procedures in
CONOPS and system security, contingency, configuration management and other
plans
Demonstrated ability to facilitate customer concurrences
required for risk-based decisions, especially those requiring waivers
Experience assisting the customer with decisions impacting
the security posture and compliance of their systems and networks with
requirement as documented in NIST 800-53 and its revisions
Extensive familiarity with communications protocols, such as
TCP/IP, UDP, HTTP/S, SSH, LDAP, etc.
Demonstrated experience with security, monitoring and
auditing cloud-based technologies, products and services, such as Amazon Web
Services (AWS) or Microsoft Azure
Knowledge of the customer's organization, their network
systems and infrastructure, processes and procedures, and request and approval
tools
Ability to work within fast-paced customer environments
Desired Knowledge/Skills:
Experience
in scripting/program languages such as Bash, PowerShell, or Python
Cognitio is a strategic consulting and engineering firm established and managed by a team of former senior technology executives from the U.S. Intelligence Community. Our accomplished team has a track record of safeguarding some of the nation’s greatest secrets, equipping U.S. leadership with actionable intelligence that helps protect lives and driving technology innovation that has kept key agencies generations ahead of our adversaries.
Cognitio leverages that vast knowledge to enable companies across disparate industries to effectively manage technology, maximize technology investments and reduce overall institutional risk.
Connect with us here on LinkedIn, we really appreciate it.
Offices: 1750 Tysons Blvd, Ste 1500, 8280 Greensboro Drive, Ste 550, McLean, Virginia 22102, US
Enterprise TechnologyFederal Government TechnologyResearch and AnalysisManagement ConsultingCybersecurity Risk Assessmentsand Commercial Technology
Cognitio is a strategic consulting and engineering firm established and managed by a team of former senior technology executives from the U.S. Intelligence Community. Our accomplished team has a track record of safeguarding some of the nation’s greatest secrets, equipping U.S. leadership with actionable intelligence that helps protect lives and driving technology innovation that has kept key agencies generations ahead of our adversaries.
Cognitio leverages that vast knowledge to enable companies across disparate industries to effectively manage technology, maximize technology investments and reduce overall institutional risk.
Connect with us here on LinkedIn, we really appreciate it.
Offices: 1750 Tysons Blvd, Ste 1500, 8280 Greensboro Drive, Ste 550, McLean, Virginia 22102, US
Enterprise TechnologyFederal Government TechnologyResearch and AnalysisManagement ConsultingCybersecurity Risk Assessmentsand Commercial Technology