Tista Science and Technology Corporation

Information System Security Officer (ISSO)

Job ID 2024-5184
Job Locations US-Remote-United States

Overview

TISTA Science and Technology Corporation is seeking an Information System Security Officer to join our team.

 

The ISSO will be responsible for providing the client support in proposing, coordinating, implementing, and enforcing information systems security policies, standards, and methodologies. The ISSO supports Security authorization and continuous monitoring activities in compliance with National Institute of Standards and Technology (NIST) Guidance and the United States Department of Agriculture (USDA) policy and procedures.

Responsibilities

  • The person filling this role will work as part of a team of IT Security professionals who support the security compliance and cloud initiatives of the agency
  • Conduct security assessment and authorization activities and tasks and obtain an Authorization to Operate (ATO) in line with NIST and client guidance and directives 
  • Determine the baseline IT Security requirements for IT Systems, diagram system authorization boundaries, determine system categorization based on FIPS-199 
  • Manage IT system vulnerabilities
  • Conduct technical evaluation and system design review to assess the effectiveness of existing controls and provide meaningful recommendations 
  • Monitor progress, manage risk, and ensure key stakeholders are kept informed about progress and expected outcomes, and propose and take corrective action as appropriate 
  • Assist in Federal Information Processing Standard (FIPS) categorization of applications/systems 
  • Participate in risk assessments, vulnerability scans and penetration testing of new and existing systems to identify, investigate and document security weaknesses 
  • Document and implement security controls using NIST standards
  • Review and generate authorization and assessment system documentation as needed: System Security Plans (SSP), Configuration Management Plans (CMP), Security Assessment Reports (SARs), Privacy Threshold Assessments (PTA), Privacy Impact Analysis (PIA), Disaster Recovery Plans (DRP), Information System Contingency Plans (ISCP), Incident Response Plans (IRP), Risk Assessment Reports (RARs), Standard Operating Procedures (SOPs) and Plans of Action and Milestones (POA&MS)
  • Create and maintain project content in the Governance, Risk, and Compliance (GRC) tool per client’s guidance
  • Identify and report detailed Plan of Action and Milestone (POA&Ms); manage and monitor for corrective actions 
  • Review and analyze system scan reports
  • Provide guidance on security requirements for systems hosted in cloud (including FedRAMP) versus on-premise 
  • Research and stay up-to-date on industry standards and any new vulnerabilities and risks 
  • Assess systems to analyze risk and report weaknesses findings 
  • Work with developers and DBAs in addressing findings 
  • Assess and review current technology infrastructure to identify key risk areas, and ensure adequate levels of controls are in place to address those risks 
  • Participate in and support internal and external compliance initiatives including audit requests, tabletop exercises, security training, and other tasks associated with improving the company’s security posture 

Qualifications

  • 5+ years of demonstrated experience in the Information Security (Cybersecurity or Information Assurance) field 
  • Recognized IT security and cloud certifications
  • Fundamental understanding of cloud security
  • Demonstrates a proficiency with developing, maintaining and managing security authorization and assessment packages 
  • Experience with developing, managing and mitigating POA&Ms 
  • Displays technical experience with conducting research and providing review recommendations on software and technologies for vulnerabilities 
  • Technical experience with reviewing vulnerability scans and providing mitigation recommendations
  • Possess experience in participating in Security Control Assessments (SCA)
  • Experience writing security related documentation, policies and procedures
  • Experience with NIST Special Publications and guidance 
  • Strong problem solving and analysis skills, self-motivated, and able to work and communicate in a team environment 
  • Experience with maintaining security packages in a Governance, Risk, and Compliance tool 
  • Strong written and oral communication skills

  

Education: 

  • Bachelor’s degree or higher in Computer Science, Information Technology, Information Security, or similar fields
  • 5+ years of demonstrated experience in the Information Security (Cybersecurity or Information Assurance) field 
  • 10 years of additional relevant experience may be substituted for education 
  • Required Certifications: 
    • Certified Cloud Security Professional (CCSP)
    • MS AZ-900 (Microsoft Azure Fundamentals)
  • Desired Certifications: 
    • Certified Information Systems Security Professional (CISSP)
    • Certified Authorization Professional (CAP)

Location: 

  • Remote

Clearance: 

  • Public Trust 

Salary Inforamtion: 

  • The pay for this position ranges from $110,000 to $125,000.
  • The actual salary offer will carefully consider a wide range of factors, including your skills, qualifications, experience, and location.
  • Also, certain positions are eligible for additional forms of compensation, such as bonuses.
  • TISTA associates are eligible to participate in our comprehensive benefits plan! More information can be found here: https://tistatech.com/working-at-tista/

 

 

 

Options

Sorry the Share function is not working properly at this moment. Please refresh the page and try again later.
Share on your newsfeed