Information System Security Engineer
Fairfax, Va, Us
•Currently performing ISSO work (holding a signed ISSO letter) as an ISSE.•Maintain Information Assurance compliance/management on Windows, Linux and CISCO assets.•Develop, implement, and enforce DoD cyber security and A&A information systems security policies ensuring system security requirements are addressed during all phases of the RMF lifecycle. •Maintain and manage eMASS records for 7 packages of 600+ Systems Assess and Authorize, and Application Assess Only.•Self-assess and maintain Security Controls for packages have been met and are in date of the ATO’s. •Identify Weakness in the organizations systems and implement new security measures as necessary. •Prepare, develop, and document program security and technical publications such as: POA&M, System Security Planning, Analyses, Authorization Boundary Diagrams, Hardware/Software List, Data flow Diagrams, E-Authentication, ESAM, SLCM, PIA, PPS.•Ensure POA&M reports are maintained and that security vulnerabilities are tracked and remediated.•Perform Step 6 Continuous Monitoring of Authorized systems in the RMF lifecycle including: Tenable ACAS/Nessus Vulnerability scan results, SCAP, DISA Security Technical Implementation Guides, VRAM and IAVM reviews.•Supporting national security focused customer providing system security engineering services and/or products to ensure secure, reliable, and uninterrupted availability of customer-developed and deployed systems and networks.•Perform analysis and evaluation to design, implement, test and secure systems, networks and architectures. •Ability to identify risk areas of non-compliance and propose solutions or mitigate to fulfill operational requirements and meet cybersecurity requirements simultaneously. •Follow best practices instructed by the ISSO/ISSM are met and ensuring that system administrators follow proper protocols of security measures.