Cyber Security Analyst / ISSO

at  Scientific Research Corporation

Norfolk, VA 23513, USA -

Start DateExpiry DateSalaryPosted OnExperienceSkillsTelecommuteSponsor Visa
Immediate31 Jan, 2025USD 97150 Annual31 Oct, 20245 year(s) or aboveCommunication Skills,Nginx,Mariadb,Flow Diagrams,Ssps,Linux,Postgresql,Hbss,Sscp,Continuous Monitoring,Windows,Cap,Mysql,Web Servers,Elasticsearch,Enterprise Services,Nessus,MongodbNoNo
Add to Wishlist Apply All Jobs
Required Visa Status:
CitizenGC
US CitizenStudent Visa
H1BCPT
OPTH4 Spouse of H1B
GC Green Card
Employment Type:
Full TimePart Time
PermanentIndependent - 1099
Contract – W2C2H Independent
C2H W2Contract – Corp 2 Corp
Contract to Hire – Corp 2 Corp

Description:

About Us:
Scientific Research Corporation is an advanced information technology and engineering company that provides innovative products and services to government and private industry, as well as independent institutions. At the core of our capabilities is a seasoned team of highly skilled engineers and scientists with multidisciplinary backgrounds. This team is challenged daily to provide cutting edge technology solutions to our clients.
Scientific Research Corporation offers a competitive salary, an extensive benefits package and a work environment that encourages excellence. For positions requiring a security clearance, selected applicants will be subject to a government security investigation and must meet eligibility requirements for access to classified information.

Requirements:

  • Must possess an active Top Secret clearance
  • 5 years of cybersecurity experience
  • Must currently hold a DoD 8570-compliant IAT II certification (SSCP or Security+CE with appropriateCE/OS certificate), and IAM II certification (CAP or CASP CE) or be able to obtain within six months. CE/OScertificate may include Windows or Linux
  • Experience with System Security Plans (SSPs), eMASS and/or Xacta, POA&Ms, ACAS/Nessus, SCAP, and DISA STIGs
  • Experience with Risk Management Framework processes
  • Have developed communication skills and the ability to express thoughts and ideas clearly and concisely
  • Must be a team player, dedicated to program support, capable of multitasking and working several complex and diverse tasks with simultaneous or near simultaneous deadlines
  • Be a self-starter who is accountable and requires minimal direction and supervision
  • Be open to new and innovative ideas
  • Must be able to be appointed ISSO for NCS systems within 6-months of employment

Desired Skills:

  • Extensive training or experience with Windows based Information Systems standards with a working knowledge of networking devices
  • Knowledge of Container Security and best practices securing containerized applications
  • Knowledge of configuration of various SQL databases: MS SQL, PostgreSQL, MongoDB, MariaDB, MySQL, Elasticsearch
  • Knowledge of Web Servers: Apache Web Server, Apache Tomcat, Red Hat JBOSS, nginx, MS IIS
  • Knowledge of data flows and the ability to work up readable network topology and data flow diagrams
  • Experience with NAVINTEL IA Enterprise Services: Continuous Monitoring
  • Experience with the following systems/platforms/tools: HBSS; ACAS/Nessus; SPLUNK

Description:
The SRC Navy Cryptologic Systems (NCS) Directorate supports a number of US Navy Programs, including the Intelligence Carry-On Program, Cryptologic Carry-On Program (CCOP), Ships Signals Exploitation Equipment (SSEE) Program, and Distributed Common Ground System – Navy (DCGS-N). We specialize in engineering support, software development, integration, testing, technical writing, Cybersecurity (administration, policy and engineering), production, technical support, warehousing, drafting, repair and management.

As an Information Systems Security Officer (ISSO), this position is responsible for supporting the Information System Owner to complete security assessment, continuous monitoring, and configuration management responsibilities of NCS. Responsibilities include, but are not limited to:

  • Developing and updating assessment and authorization documentation (Body of Evidence) for management and continuous monitoring of information systems
  • Performing ongoing compliance assessments using tools, such as Assured Compliance Assessment Solution (ACAS), Secure Content Automation Protocol (SCAP), and Trellis Virus Scan Enterprise. Review, document, and maintain all results
  • Verifying patches and virus definitions to the systems using existing automated tools
  • Adhering to pre-defined configuration management and change management policies and procedures for authorizing software prior to its implementation on systems
  • Performing security audits using to track multiple events including any signs of inappropriate or unusual activity, intrusion events, data transfers, etc.
  • Performing security assessments of NCS Family of Systems in accordance with NIST, Navy, and NAVINTEL IA guidance. Works with system engineers to take corrective action to resolve identified problems
  • Becoming a NAVINTEL IA ICOP Trusted Agent within 6-months
  • Performing Site Based Security Assessments (SBSAs) of systems and recommending authorization to the Designated Authorizing Official (DAO) as a certified Trusted Agent
  • Reporting security incidents in accordance with the Command Incident Response Plan
  • Ensuring systems are operated, used, maintained, and disposed of in accordance with all applicable security policies and practices

Responsibilities:

  • Developing and updating assessment and authorization documentation (Body of Evidence) for management and continuous monitoring of information systems
  • Performing ongoing compliance assessments using tools, such as Assured Compliance Assessment Solution (ACAS), Secure Content Automation Protocol (SCAP), and Trellis Virus Scan Enterprise. Review, document, and maintain all results
  • Verifying patches and virus definitions to the systems using existing automated tools
  • Adhering to pre-defined configuration management and change management policies and procedures for authorizing software prior to its implementation on systems
  • Performing security audits using to track multiple events including any signs of inappropriate or unusual activity, intrusion events, data transfers, etc.
  • Performing security assessments of NCS Family of Systems in accordance with NIST, Navy, and NAVINTEL IA guidance. Works with system engineers to take corrective action to resolve identified problems
  • Becoming a NAVINTEL IA ICOP Trusted Agent within 6-months
  • Performing Site Based Security Assessments (SBSAs) of systems and recommending authorization to the Designated Authorizing Official (DAO) as a certified Trusted Agent
  • Reporting security incidents in accordance with the Command Incident Response Plan
  • Ensuring systems are operated, used, maintained, and disposed of in accordance with all applicable security policies and practice


REQUIREMENT SUMMARY

Min:5.0Max:10.0 year(s)

Information Technology/IT

IT Software - Network Administration / Security

Other

Trade Certificate

Must currently hold a dod 8570-compliant iat ii certification (sscp or security+ce with appropriatece/os certificate) and iam ii certification (cap or casp ce) or be able to obtain within six months.

Proficient

1

Norfolk, VA 23513, USA