Information Systems Security Officer
Current• Developed Security Control Assessment Plan to conduct security assessment and coordinated meetings with control owners and other stakeholders.• Coordinated documents System Security Plans (SSPs), reviews and uploads supporting security artifacts and evidence, generates risk reports, and facilitates continuous monitoring process for authorized systems.• Review System Security Plan (SSP), Configuration Management Plan (CMP), Contingency Plan (CP) and other security policy documentation.• Using eMASS, maintain up-to-date status of all security controls, enhancements, and control correlation identifiers (CCIs).• Assess security controls, Security Technical Implementation Guides (STIGs), and Assured Compliance Assessment Solution (ACAS) scans.• Compiling and submitting A&A packages for IA security control assessor (SCA) review and assessment• Worked on both classified and unclassified networks, including transferring files from unclassified to classified networks. • Supports the System Information System Owner (ISO), with establishing, maintaining, and tracking the security plans from eMASS in accordance with the RMF process as documented at the RMF Knowledge Service, and produce the five artifacts described in the system owners guide at all classification levels. • Ensure security policies, procedures; recommendations comply with FISMA, NIST, Organizational guidelines and technical best practices.• Participates in the development and maintenance of system security plans and contingency plans for all systems under their responsibility.• Develop a variety of Assessment & Authorization deliverables including System Security Plan (SSP), Security Assessment Report (SAR), Contingency Plan (CP) and POA&M for review and approval for Authorization Official. • Monitor and conduct Security Control Assessment to ensure all controls meet security requirements as stipulated in the SSP and NIST SP 800-53 Rev4.