Information Systems Security Officer
CurrentAssist with developing, reviewing, and maintaining information SSPs and supporting documents in accordance with VA polices; Perform manual and system level audit reviews of systems to track security events including any signs of inappropriate or unusual activity, data transfers, etc.; Perform recurring self-assessments on all systems under the local area purview to ensure compliance with documented security requirements and to detect any system level vulnerabilities; Prepare a summary report of any findings of security violations and/or vulnerabilities and ensure proper protection and/or corrective measures are taken; Provide incident handling and security training and awareness; Play an active role in monitoring a system and its environment of operation to include developing and updating the SSP, managing and controlling changes to the system, and assessing the security impact of those changes; Implement and enforce information security policies and procedures; Perform the steps involved in the execution of the RMF, including generation of documentation, controls compliance testing, and continuous monitoring activities for stand-alone systems; Work with IT in performing an initial system assessment to ensure that required security controls are implemented and operating correctly before a system is authorized for production; Ensure IT staff and users follow established information security policies and procedures to protect, operate, maintain, and dispose of systems and data in accordance with security policies and practices as outlined in the assessment and authorization packages; Notify IT Staff when a user account is to be created, modified, disabled, or removed from a system; Evaluate proposed changes against VA security requirements and recommend approval or denial based on a security impact analysis; Participate in inspections and incident response; Verify user training prior to initial system access and periodically after.