|
Tharros supports the Department of Homeland Security (DHS) with cybersecurity services across its Intelligence Enterprise. In support of this mission, we have an immediate opportunity for a Junior Information System Security Officer (ISSO). In this role you will support the security posture of assigned systems within a portfolio of more than 130 classified and unclassified systems, in accordance with ICD 503 and DHS 4300C. Working with senior ISSOs, you will maintain authorization artifacts, track POA&Ms, review audit logs, and serve as a SCIF Information Security Compliance Representative (ISCR). This position is on-site in a Government SCIF in Washington, DC. Duties include but not limited to:
- Maintain security artifacts (SSP, POA&Ms, risk exceptions, contingency plans, privileged user guides, PTAs) in the GRC tool.
- Track POA&Ms on 30/60/90/120/180-day review intervals and provide weekly or bi-weekly activity reports.
- Perform audit log reviews at least weekly and respond to NOSC alerts.
- Ensure periodic vulnerability scans are performed and review scan results.
- Submit IATT requests and notify the ISSM, SCA, and AO of changes affecting authorization.
- Support annual contingency plan tests and quarterly CPEM reporting.
- As SCIF ISCR, maintain hardware inventory, process entry/exit paperwork, submit monthly checklists, and report SCI security incidents.
- BS degree in Information Technology, Cybersecurity, Information Systems, or Computer Science OR minimum of 4 years' experience in IT or cybersecurity.
- Minimum of 1 year of experience in ISSO, RMF, or security compliance support.
- Active TS/SCI clearance and U.S. citizenship; willingness to undergo a DHS counterintelligence-scope polygraph.
- Knowledge of the Risk Management Framework (RMF), NIST SP 800-37, and NIST SP 800-53.
- Knowledge of hybrid classified/unclassified, on-premise and cloud environments.
- Knowledge of DevSecOps and agile methodologies.
- Skill in securing Linux and Windows operating systems.
- Skill in POA&M tracking and audit log review.
- Ability to maintain accurate documentation across multiple systems.
- Proficient in Microsoft Office Suite to include Teams or similar workplace chat and videoconferencing tools.
- Excellent written and oral communications skills.
Desired
- CompTIA Security+ or CySA+ certification.
- Experience with RSA Archer, eMASS, or a similar GRC tool.
- Exposure to Cross Domain Solutions.
.
|