Hiring.Camp

Senior ISSO / ISSE (eMASS and ACAS)

Empowerai

·

Sep 30, 2024

Location
Quantico, VA, US
Workplace
Onsite
Type
Full-time
Department
Security
Seniority
Senior
Experience
5+ years
Education
Master
Visa
Not sponsored
Clearance
Required
Closing date
Today
Source
iCIMS

Description

Overview

Empower AI is AI for government. Empower AI gives federal agency leaders the tools to elevate the potential of their workforce with a direct path for meaningful transformation. Headquartered in Reston, Va., Empower AI leverages three decades of experience solving complex challenges in Health, Defense, and Civilian missions. Our proven Empower AI Platform® provides a practical, sustainable path for clients to achieve transformation that is true to who they are, what they do, how they work, with the resources they have. The result is a government workforce that is exponentially more creative and productive. For more information, visit www.Empower.ai.

 

Empower AI is proud to be recognized as a 2024 Military Friendly Employer by Viqtory, the publisher of G.I. Jobs. This designation reflects the company’s commitment to hiring and supporting active-duty and veteran employees.

Responsibilities

Empower AI is seeking a Senior ISSO / ISSE to combine information systems security officer and security engineering responsibilities for the systems managed by an enterprise IT Customer Support Services program supporting a Department of War agency across NIPRNet, SIPRNet, and JWICS enclaves. The role owns the eMASS RMF packages and continuous monitoring for assigned systems as ISSO, and as ISSE engineers and validates STIG/SRG baselines, designs control implementations, leads ACAS vulnerability remediation engineering, and ensures new solutions (endpoint, ITSM/dashboards, collaboration, communications, automation and AI) are designed to achieve and maintain ATO. The Senior ISSO/ISSE produces the weekly Vulnerability Scan Analysis Report and monthly STIG Compliance Report, prepares systems for assessments, and serves as the go-to security engineering expert for engineers and the Risk Management Support Lead. This is a salaried, FLSA-exempt position in which you will independently analyze situations, determine the appropriate course of action, and exercise discretion and independent judgment on matters of significance to the program and its customers. 

 

THIS IS AN ONSITE ROLE IN QUANTICO, VA (RKB) WITH UP TO 10% OF TRAVEL INVOLVED. 

 

JOB DUTIES: 

  • Own the eMASS RMF packages and continuous monitoring for assigned systems as ISSO: SSP, SAR inputs, POA&M management, control implementation statements, artifact collection, ATO expiration tracking and reaccreditation, and assessment preparation and liaison with assessors. 
  • Lead ACAS/Nessus vulnerability management engineering: analyze weekly scan results, determine root causes and remediation or mitigation, drive resolver groups to closure within policy timeframes, and produce the weekly Vulnerability Scan Analysis Report. 
  • Engineer and validate STIG/SRG-compliant baselines and security control implementations for endpoint, ITSM/dashboard, collaboration, and communications systems using STIG Viewer and SCAP tooling, and produce the monthly STIG Compliance Report. 
  • Perform security impact analysis for changes and new capabilities (including automation and AI), integrate secure development (NIST SP 800-218) requirements, and align designs to DoD Zero Trust and ICAM strategies. 
  • Lead security engineering for in-scope systems: define security architectures, select and tailor NIST SP 800-53 controls, and design control implementations for endpoint infrastructure, ITSM/dashboard platforms, collaboration and web platforms, and VoIP/VTC/mobile communications. 
  • Engineer, validate, and maintain STIG/SRG-compliant baseline configurations for Windows, Linux (RHEL), VMware, Active Directory, network printers, communications equipment, and cloud/SaaS components, using STIG Viewer, SCAP, and automated compliance tooling. 
  • Lead vulnerability remediation engineering: analyze ACAS/Nessus results, determine root causes, design and validate remediation or mitigations, and provide technical inputs to POA&Ms and the weekly Vulnerability Scan Analysis Report. 
  • Develop and review RMF technical artifacts in eMASS, including control implementation statements, architecture and data flow diagrams, hardware/software lists, ports/protocols/services, and evidence packages, and prepare systems for security control assessments. 

Qualifications

REQUIREMENTS: 

  • Bachelor's degree and a minimum of 10 years of related experience (a Master's degree with 8 years of related experience, or an additional 4 years of related experience in lieu of a degree, may be substituted). 
  • Must be a U.S. Citizen. 
  • Must have an Active Top Secret Clearance with SCI eligibility (favorably adjudicated T5/T5R) to start. 
  • Must be within investigation scope and/or currently enrolled in Continuous Evaluation / Continuous Vetting. 
  • Must possess and maintain a current DoD 8570/8140 IASAE Level II baseline certification (e.g., CISSP or Associate, CASP+ CE, or CSSLP). 
  • Demonstrated ability to work independently, analyze problems, determine the appropriate course of action, and exercise discretion and independent judgment with limited day-to-day supervision. 
  • Minimum of 10 years of cybersecurity experience, including at least 5 years performing information systems security engineering for DoD or Federal systems. 
  • Expert knowledge of NIST SP 800-37, NIST SP 800-53, CNSSI 1253, DoDI 8510.01, DoDI 8500.01, and DISA STIGs/SRGs. 
  • Hands-on experience engineering and validating STIG-compliant configurations for Windows Server, Active Directory, VMware, Linux (RHEL), and network/communications devices, using STIG Viewer, SCAP, and ACAS/Nessus. 
  • Experience leading RMF technical package development in eMASS and successfully achieving ATOs. 
  • Experience performing security impact analysis and integrating secure development practices (NIST SP 800-218 SSDF) into application and automation delivery. 
  • Working knowledge of DoD Zero Trust Strategy/Reference Architecture, DoD ICAM Strategy, and supply chain risk management controls. 
  • Excellent technical writing and communication skills; ability to explain security requirements to engineers, developers, and Government stakeholders. 

 

DESIRED SKILLS: 

  • CISSP-ISSEP or CISSP-ISSAP, CASP+ CE, CSSLP, or GIAC security engineering certifications. 
  • Experience supporting Department of War (DoW), DoD, or Intelligence Community systems across NIPRNet, SIPRNet, and JWICS enclaves. 
  • Experience securing ServiceNow, Microsoft 365 GCC High/Power Platform, Power BI, and Cisco unified communications environments. 
  • Experience with cloud security (DISA CCSRG, FedRAMP, IL4/IL5) and automated compliance/Infrastructure-as-Code security tooling. 
  • Experience with security engineering for AI/ML and automation capabilities. 
  • Familiarity with DoDAF 2.02 architecture views and DoD Cyber Workforce Framework role qualification requirements. 

About Empower AI

All hiring and promotion decisions at Empower AI are based on merit to bring the best talent available to contribute to our firm’s overall success. It is the policy of Empower AI not to discriminate against any applicant for employment, or employee because of age, color, sex, disability, national origin, race, religion, or veteran status. Empower AI is a VEVRAA Federal Contractor.

Pay Band Min

USD $147,000.00/Yr.

Pay Band Max

USD $227,520.00/Yr.

Skills

LinuxVMwarePower BIServiceNowCybersecurityRisk ManagementComplianceTechnical WritingCISSP

Similar Jobs

30

Sr. ISSO

Fuse Engineering Llc·Annapolis Junction, MD

1y+ ago

Senior Cybersecurity Engineer / ISSO

Agil3 Technology Solutions (A3T)·Quantico, VA

1d ago

Senior Information System Security Officer (ISSO) - Tewksbury, MA

RTX·US-MA-TEWKSBURY-TB3 ~ 50 Apple Hill Dr ~ CONCORD BLDG, Tewksbury Tb3 300 Concord·Onsite

2d ago

Senior Information Systems Security Officer (ISSO) II - Tucson, AZ

RTX·US-AZ-TUCSON-M05 ~ 1151 E Hermans Rd ~ BLDG M05, US·Onsite

1w ago

Senior Systems Engineer - Cybersecurity / ISSO

Integral Federal·Tysons Corner, VA

1w ago

Senior Information System Security Officer (ISSO) – WSMR, New Mexico

ASRC Federal·White Sands Missile Range, NM

2w ago

Senior Information System Security Officer (ISSO) - El Segundo, CA (Sponsor Clearance)

RTX·US-CA-EL SEGUNDO-E01 ~ 2000 E El Segundo Blvd ~ BLDG E01, US·Onsite

2w ago

Senior Information System Security Officer (ISSO)

ShorePoint·Albuquerque, New Mexico

2w ago

Senior Information Systems Security Officer (ISSO)

Agecareers·Alexandria, VA +1·Remote

2w ago

Senior Systems Engineer / Information Systems Security Officer (ISSO)

Caci·0IW FORT MEADE MD, US·Onsite

2w ago

Senior Information Systems Security Officer (ISSO)

Toyon Research Corporation·Arlington, VA

2w ago

Senior Information System Security Officer (ISSO) - Tucson, AZ

RTX·US-AZ-TUCSON-M05 ~ 1151 E Hermans Rd ~ BLDG M05, US·Onsite

2w ago

Sr Information Systems Security Officer (ISSO) - Cloud, Advisor - TS/SCI w/poly

Peraton·Washington, DC

3w ago

Sr Information Systems Security Officer (ISSO), Advisor - TS/SCI w/poly

Peraton·Winchester, VA

3w ago

Sr Information Systems Security Officer (ISSO), Advisor - TS/SCI w/poly

Peraton·Huntsville, AL

3w ago

Sr Information Systems Security Officer (ISSO) - Cloud, Advisor - TS/SCI w/poly

Peraton·Huntsville, AL

3w ago

Senior Information System Security Officer (ISSO) - Aurora, CO

RTX·US-CO-AURORA-S75 ~ 16800 E Centretech Pkwy ~ BLDG S75, US·Onsite

3w ago

Senior Information System Security Officer (ISSO) - Tucson, AZ

RTX·US-AZ-TUCSON-842 ~ 1151 E Hermans Rd ~ BLDG 842, US·Onsite

3w ago

Senior Information System Security Officer (ISSO) - Goleta, CA

RTX·US-CA-GOLETA-H02 ~ 6380 Hollister Ave ~ BLDG H02, US·Onsite

3w ago

Senior Information Systems Security Officer (ISSO)

Parsons Corporation·USA CO Colorado Springs, US·Onsite

3w ago

Information System Security Officer (ISSO) – Senior

ASRC Federal·Aberdeen Proving Ground, MD 21005

3w ago

Sr Information Systems Security Officer (ISSO), Advisor - TS/SCI w/poly

Peraton·Washington, DC

4w ago

Senior Information System Security Officer (ISSO)

C3El·Washington, D.C.·Onsite

1mo ago

Senior Information System Security Officer (ISSO) - Tucson, AZ

RTX·US-AZ-TUCSON-M05 ~ 1151 E Hermans Rd ~ BLDG M05, US·Onsite

1mo ago

Senior Information System Security Officer (ISSO) - El Segundo, CA

RTX·US-CA-EL SEGUNDO-E07 ~ 2012 E El Segundo Blvd ~ BLDG E07, US·Onsite

1mo ago

Senior Information Systems Security Officer (ISSO) II - El Segundo, CA

RTX·US-CA-EL SEGUNDO-E07 ~ 2012 E El Segundo Blvd ~ BLDG E07, US·Onsite

1mo ago

Senior Information System Security Officer (ISSO) - Dulles, VA

RTX·US-VA-DULLES-710 ~ 22110 Pacific Blvd ~ BLDG 10, US·Onsite

1mo ago

Senior Information System Security Officer (ISSO)

C3El·Washington, D.C.·Onsite

1mo ago

Information System Security Officers (ISSO), Senior Security Engineers & Security Engineering Leads (CBP)

Agile Defense·Ashburn, VA·Hybrid

1mo ago

Information Systems Security Officer (ISSO), Senior Advisor - TS/SCI w/poly

Peraton·Linthicum Heights, MD

1mo ago