OC
Information Assurance Engineer / Information System Security Officer (IA Engineer/ISSO)
Onyx Consulting Services
🇺🇸 United States
Manager or above
3 months ago
- CISSP
- FISMA
- NIST
- FedRAMP
- Incident Response
- CISM
- CISA
- CompTIA Security+
- Risk Management Framework
- RMF
- SIEM
- IAM
- AWS
- Azure
- Vulnerability Management
3 months ago
Covered Labor CategoriesSenior IT Consultant (Senior Cloud ISSO / Senior Security Engineer)
- Experience:Â 10+ years
- Certification:Â CISSP or equivalent certification
- Support the development and maintenance of cybersecurity policies, standards, procedures, strategies, and communications supporting the customer's mission.
- Ensure security services are performed in accordance with:
- NIST SP 800-37
- NIST SP 800-53
- Federal Information Security Modernization Act (FISMA)
- Organization-level policies, directives, and guidelines
- Design and implement security controls that protect information systems, applications, and networks.
- Develop security architectures, policies, standards, and procedures aligned with federal cybersecurity requirements.
- Support secure cloud and on-premises environments.
- Conduct security assessments and vulnerability reviews of information systems.
- Identify security weaknesses and recommend mitigation strategies.
- Ensure compliance with applicable federal standards, including:
- NIST
- FISMA
- FedRAMP
- Collaborate with stakeholders to remediate identified findings.
- Participate in cybersecurity incident response activities.
- Assist in developing and testing incident response plans and playbooks.
- Support investigation and resolution of security incidents.
- Monitor security tools, system logs, and network activity to identify suspicious behavior.
- Analyze alerts and security data for indicators of compromise.
- Support ongoing continuous monitoring activities.
- Assist with internal and external cybersecurity audits and remediation efforts.
- Develop, maintain, and report Plans of Action and Milestones (POA&Ms).
- Track remediation efforts through completion.
- Provide status updates to customer leadership.
Required Qualifications
- Bachelor's degree in Computer Science, Information Technology, Cybersecurity, or a related discipline.
- Minimum experience requirements:
- Senior Cloud ISSO / Senior Security Engineer:Â 10+ yearsÂ
- Relevant cybersecurity certifications such as:
- CISSP
- CAP
- CISM
- CISA
- CompTIA Security+
- GIAC certifications
- Equivalent DoD-approved certifications
- Demonstrated experience supporting information security programs within Federal Government or other highly regulated environments.
- Strong knowledge of:
- NIST Risk Management Framework (RMF)
- NIST SP 800-37
- NIST SP 800-53
- FISMA
- FedRAMP
- Experience with enterprise security technologies, including:
- Firewalls
- Intrusion Detection/Prevention Systems (IDS/IPS)
- Security Information and Event Management (SIEM)
- Encryption technologies
- Identity and Access Management (IAM)
- Authentication protocols
- Excellent analytical, problem-solving, and organizational skills.
- Strong written and verbal communication skills.
- Ability to work effectively in a collaborative, cross-functional environment.
Clearance Requirements
- Active Public Trust clearance required.
- Ability to obtain and maintain a Secret security clearance.
Preferred Qualifications
- Experience supporting cloud security initiatives within AWS, Azure, or Microsoft Government Cloud environments.
- Experience supporting Authorization to Operate (ATO) packages and RMF lifecycle activities.
- Experience using Enterprise Mission Assurance Support Service (eMASS).
- Experience with Security Control Assessments (SCAs).
- Knowledge of vulnerability management tools and continuous diagnostics and mitigation (CDM) practices.
Information Assurance Engineer / Information System Security Officer (IA Engineer/ISSO) · Onyx Consulting Services