Information System Security Officer
CurrentEnsure assigned systems maintain an ATO• Develop the Privacy documents (PTA, PIA)• Obtain knowledge of secure use of controls within systems• Support management on security-related issues• Ensure system security controls are documented in accordance with-in NIST 800-53A requirements.• Ensure systems comply with security policies and mandates Federal Government (Memos, Directives) and FSA Guidelines (compliance)• Ensure the existence of protective measures against threats• Ensure system boundary is accurately identified• Ensure the SSP and other security documents exist, follow templates and accurately reflect the controls in place• Track system SDLC changes and determine impact (SIA)• Review system and privileged user accounts• Monitor system deviations and vulnerabilities• Worked on implementation of information technology (IT) security controls and security authorization documents; and assures the system is compliant with mandated security policies and requirements.• Provides recommendations for all Risk Assessments and Vulnerability Assessments conducted for the system.• Assist in the developing of security documentation including System Security Plans, Contingency Plans, Incident Response Plans, System Inventory documentation etc.• Provides security analysis of IT activities to ensure that appropriate security measures are in place and being enforced.• Ensures that plans of actions and milestones (POA&Ms) or remediation plans are in place for vulnerabilities identified during risk assessments, audits, inspections, etc. Manages timely processing of POA&Ms.• Identifies any possible security violation and takes appropriate action to report the incident as required. Supervises or manages protective or corrective measures when a cybersecurity incident or vulnerability is discovered.• Ensures that all Systems security controls, address information security requirements consistent with Agency’s security goals.