|
Tharros supports the Department of Homeland Security (DHS) with cybersecurity services across its Intelligence Enterprise. In support of this mission, we have an immediate opportunity for an IT Security Operations Specialist. In this role you will run day-to-day IT security programs inside DHS SCIFs, including SCI incident reporting, privileged user tracking, removable media management, equipment entry/exit and decommissioning, and IT security training and outreach. This position is on-site in a Government SCIF in Washington, DC. Duties include but not limited to:
- Identify, record, and report SCI IT security incidents in the GRC tool and to the DHS Enterprise SOC and IC Security Coordination Center.
- Maintain the privileged user database; issue annual training memos and 30/60/90-day compliance reminders.
- Administer the Removable Media Program in accordance with ICS 500-18, including training, waivers, Rules of Behavior, and tracking.
- Inspect IT equipment entering and exiting SCIFs; review pre-procurement and PED request forms.
- Coordinate sanitization and decommissioning in accordance with DHS 4300C and NSA/CSS Policy Manual 9-12.
- Manage daily operations of the SCIF compliance oversight program (ICOP) and ISCR/ISSO designations.
- Develop and update annual SCI IT security awareness, removable media, and privileged user training; deliver classroom sessions.
- Produce IT security tips, newsletters, surveys, and briefings for non-technical audiences.
- BS degree in Information Technology, Cybersecurity, Information Systems, or Computer Science OR minimum of 6 years' experience in IT or security operations.
- Minimum of 3 years' experience in IT security operations, SCIF compliance, or security program administration.
- Active TS/SCI clearance and U.S. citizenship; willingness to undergo a DHS counterintelligence-scope polygraph.
- Knowledge of ICS 500-18 removable media requirements.
- Knowledge of SCIF IT equipment entry/exit, sanitization, and decommissioning procedures.
- Knowledge of security incident reporting and handling processes.
- Skill in maintaining compliance databases and producing metrics reports.
- Skill in developing training materials and briefing non-technical audiences.
- Ability to manage multiple recurring compliance programs and deadlines.
- Proficient in Microsoft Office Suite to include Teams or similar workplace chat and videoconferencing tools.
- Excellent written and oral communications skills.
Desired
- Experience with NSA/CSS media sanitization procedures.
- LMS administration or instructional design experience.
- COMSEC familiarity to serve as a backup for two-person integrity.
- CompTIA Security+ certification.
|