Information Systems Security Officer - (TS/SCI Required)
Paragone Solutions is seeking an Information Systems Security Officer, responsible for evaluating cybersecurity risks including external and internal threats, platform and application vulnerabilities, and data protection weaknesses. Conducts testing and assessment of security controls designed to mitigate risks, communicates findings and recommendations to management, and proposes practical solutions to strengthen business operations. Oversees and follows up on corrective actions to ensure effective remediation. May participate in or lead professional teams to execute technical audit projects aimed at assessing the effectiveness of cybersecurity governance, tools, and operations. Evaluates the design, efficiency, and effectiveness of information technology and security processes, procedures, and technical controls, including solution implementations. Identifies and addresses systemic gaps in cybersecurity risk management to enhance the organization's overall security posture.
This is a full-time, on-site position located at Aberdeen Proving Ground, MD. Experience with classified authorizations required, NSA or other is desired. Knowledgeable in eMASS, continuous monitoring requirements, RMF 2.0, DISA STIGs, etc.
This position requires an Active DOD Top Secret (TS) Clearance with SCI and Poly. If a candidate does not have a polygraph, they must be willing to undergo a polygraph investigation.
Responsibilities:
- Perform all ISSO duties and responsibilities in DODI 8500.01, DODI 8510.01, and AR 25–2.
- Responsible for ensuring the appropriate operational security posture is maintained for the information system (IS) on multiple security domains and classification to met Intelligence Community (IC), DoD and Army cybersecurity/information assurance regulations and policies.
- Direct experience with implementation of DOD-I-8500, DOD-I-8510, ICD 503, NIST 800-53, CNSSI 1253, Army AR 25-2, and RMF security control requirements and able to provide technical direction, interpretation and alternatives for security control compliant.
- Develops, reviews, evaluates and verifies self-testing results to validate enclave security requirements in accordance with applicable Intelligence Community, DoD and Army cybersecurity and Information Assurance (IA) regulations, policies and organizational security policies) in Information Systems (ISs) are met. ISs includes Cross Domain Solution Suites (CDSS), Cloud, On-Prem, Tactical, etc., within the program’s portfolio.
- Ensure the appropriate organizational operational security posture is maintained for the assigned Army IS.
- Maintain organizational situational awareness and initiate actions to improve or restore cybersecurity posture of assigned IS.
- Implement and enforce assigned Army IS cybersecurity policies and procedures, as defined by cybersecurity-related documentation.
- Ensure Army IS cybersecurity-related documentation is current and accessible to properly authorized individuals. Prepare, distribute, and maintain plans, instructions, and SOPs concerning system security.
- Prepare and maintain Risk Management Framework (RMF) system accreditation Body of Evidence (BOE) packages using the eMASS, XACTA or other approved A&A tool to include, System Security Plans, Risk Assessment Reports, System Requirements Traceability Matrices (SCTM), and other documentation as required by ICD 503, NIST 800-53, CNSSI 1254 and any additional documentation as determined by the Authorizing Official (AO). Direct experience with eMASS, XACTA or other other A&A repositories required.
- Relevant experience must be in computer or information systems design/development and with information assurance and accreditation processes (e.g., System Security Plans, Risk Assessment Reports, Certification and Accreditation Packages, and System Requirements Traceability Matrices).
- Review unit or product vendor RMF BOE and provides guidance and oversight.
- Fully understand DISA Port Protocol, and Services Management (PPSM) requirement and able to obtain PPSM account for management of PPSM for supporting systems.
- Must be willing to travel, as needed, 25% and more.
Additional Requirements:
- MS degree plus 5 or more years directly related experience; or BS degree plus 7 or more years of directly related experience.
- Degree: Computer Science or a related field (e.g., General Engineering, Computer Engineering, Electrical Engineering, Systems Engineering, Cyber Security, Information Technology, Information Security, and Information Systems) degree required.
- Active TS/SCI (SI/TK) w/CI poly.
- Primary Certifications - one or more of the following required: CISM, CISSP, CSSLP, CCSP, or CASP+ CE (must also have Linux Cert).
- Additional Certifications - one or more of the following is a plus: Linux+, RHEL, or other Linux type certification or training.
In accordance with the Maryland Wage Transparency Law, the expected salary range for this position is $177,000- $200,000 annually. This range reflects the base pay for candidates with qualifications and experience relevant to the position requirements. The final offer within this range will be determined based on a candidate's experience, skills, and alignment with the job’s specific responsibilities. Additional factors such as internal equity and company budget may also be considered when determining the offer within this range.
Full time employees are eligible to participate in Paragone's comprehensive benefits package that includes individual and family medical, dental and vision coverage, paid time off (PTO), and participation in a 401(k)-retirement savings plan.
Paragone Solutions, Inc. is a boutique provider of services to the Department of Defense. We are a process-oriented (i.e. ISO 9001 certified) services company that provides cybersecurity, IT training, and industrial health/occupational safety support services. Founded in 2008, we are a certified woman-owned small business and a SBA certified 8(a) firm. Paragone offers competitive salaries and a relaxed, life-friendly work environment.
All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability, or status as a protected veteran.
#ZR