General Dynamics Information Technology Sr. ISSO Specialist with TS/SCI clearance in Springfield, Virginia
Performs all procedures necessary to ensure the safety of information systems assets and to protect systems from intentional or inadvertent access or destruction.
Performs Computer Security Incident Response activities for a large organization, coordinates with other government agencies to record and report incidents.
Monitor and analyze Intrusion Detection Systems (IDS) to identify security issues for remediation.
Recognizes potential, successful, and unsuccessful intrusion attempts and compromises thorough reviews and analyses of relevant event detail and summary information.
Evaluate firewall change requests and assess organizational risk.
Communicates alerts to agencies regarding intrusions and compromises to their network infrastructure, applications and operating systems.
Assists with implementation of counter-measures or mitigating controls.
Ensures the integrity and protection of networks, systems, and applications by technical enforcement of organizational security policies, through monitoring of vulnerability scanning devices.
Performs periodic and on-demand system audits and vulnerability assessments, including user accounts, application access, file system and external Web integrity scans to determine compliance.
Prepares incident reports of analysis methodology and results.
Serves as a technical team or task leader.
Maintains current knowledge of relevant technology as assigned.
Participates in special projects as required.
Responsible for the management of A&A process for both existing and new systems.Manage inventory and track the location and disposition of equipment Validate the configuration and security status of systems Recommend security requirements based on appropriate guidance, including controls and measures may be appropriate to mitigate these system vulnerabilities.Develop, review and evaluate A&A documentation including the System Security Authorization Agreement (SSAA), System Security Plan (SSP), Risk Assessment, Security Test and Evaluation (ST&E) plan Prepare the A&A Evaluation Report and Plan of Action and Milestones (POA&M).Escalate security concerns or forward the A&A Evaluation Report and supporting A&A documentation package to the certifier.Manage POA&M to ensure necessary security controls and processes are implemented.Familiar with DoDI 8510.01 and DoDI 8500.2.
Bachelors Degree in Computer Science or a related technical discipline, or the equivalent combination of education, professional training or work experience.
10-15 years of related experience in data security administration.
Experience performing certification and accreditation activities in support of DoD, Intelligence Community or Federal Government sites, systems, and networks.Experience using XACTA workflows and modules desired.Experience following NIST Risk Management Framework processes.Experience reviewing and writing C&A / A&A documentation (SSP, SSAA, POA&M, Test Plans ) Knowledge of validating IA controls found in DODI 8500.2 and NIST SP 800-53rev4.Experience conducting IA vulnerability assessment as required for the Security Test & Evaluation for validation of secure configuration as evidence to request IATO, IATT, or ATO.Excellent written and verbal communication skills.Excellent customer service skills.Understanding of the A&A processes and experience with the following A&A programs:o Director of Central Intelligence Directive (DCID) 6/3 or JFAN 6/3
o Intelligence Community Directive (ICD) 503 or DoD Risk Management Framework
o National Institute of Standards and Technology (NIST) Special Publication (SP) 800-53
o Security Control Selection, Implementation, and Testing
Experience using security scanning software ACAS/Nessus, eEye Retina, DISA Gold Disk/ STIG Tools
Knowledge and understanding of the IC community or DoD vulnerability assessment and remediation process
Develop and maintain documentation including policies and standard operating procedures (SOP)* Provide Cyber Security policy support for a broad range of needs, including Assessment & Authorization, system risk analyses, and cyber security best practices* Generate review, and comment as directed on Cyber Security policies and instructions- Certification & Accreditation experience with DIACAP, DCID 6/3, ICD-503, and/or NIST Risk Management Framework- DOD 8570.01-M IAT LEVEL III certification
For more than 50 years, General Dynamics Information Technology has served as a trusted provider of information technology, systems engineering, training and professional services to customers across federal, state, and local governments, and in the commercial sector. Over 40,000 GDIT professionals deliver enterprise solutions, manage mission-critical IT programs and provide mission support services worldwide. GDIT is an Equal Opportunity/Affirmative Action employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability, or veteran status, or any other protected class. #ISDCJ #DPOST
Number of Positions1
Job FunctionInformation Technology
Security Clearance LevelTop Secret/SCI
Full/Part TimeFull Time