Marathon TS · 1 day ago
ISSO
Marathon TS is seeking an Information System Security Officer who will conduct assessments of threats and vulnerabilities and develop appropriate mitigation strategies. The role involves managing security assessments across various applications, ensuring compliance with NIST RMF and ISO standards, and supporting the development of security blueprints and guidelines.
Information ServicesProfessional NetworkingProfessional ServicesTechnical Support
Responsibilities
Ability to manage responsibility for security assessments of a variety of applications or domains, to include cloud computing, and to manage several project/initiatives of large size, complexity, and risk
Demonstrated proficiency in implementing security controls, conducting risk assessments, and documenting compliance measures based on NIST RMF and ISO standards to meet organizational and regulatory requirements
Demonstrated proficiency in successfully evaluating and supporting documentation, validation, and accreditation processes necessary to assure that new and existing information technology (IT) systems meet the organization's information assurance (IA) and security requirements
Demonstrated proficiency in ensuring appropriate treatment of risk, compliance, and assurance from internal and external perspectives
Demonstrated ability to support development of actionable security blueprints, principles, models, designs, standards, and guidelines to ensure enterprise IT architecture and support is consistent, usable, secure and adds value to the business
Experience with network and vulnerability scanning tools and technologies to interrogate systems for configuration and status
In-depth understanding of security architecture principles and best practices to design, implement, and maintain secure IT infrastructures in alignment with A&A policies
Demonstrated proficiency in utilizing Governance, Risk, and Compliance (GRC) tools for managing Assessment & Authorization (A&A) processes
Ability to serve as subject matter expert (SME) for the US Government Client A&A process, including providing guidance to stakeholders, business units, and new A&A resources as necessary
Strong organizational skills and ability to build and maintain schedules and step-by-step action plans
Effective communication and collaboration skills to work with cross-functional teams, business units, stakeholders, and IT professionals, and to brief executives
Qualification
Required
Ability to manage responsibility for security assessments of a variety of applications or domains, to include cloud computing, and to manage several project/initiatives of large size, complexity, and risk
Demonstrated proficiency in implementing security controls, conducting risk assessments, and documenting compliance measures based on NIST RMF and ISO standards to meet organizational and regulatory requirements
Demonstrated proficiency in successfully evaluating and supporting documentation, validation, and accreditation processes necessary to assure that new and existing information technology (IT) systems meet the organization's information assurance (IA) and security requirements
Demonstrated proficiency in ensuring appropriate treatment of risk, compliance, and assurance from internal and external perspectives
Demonstrated ability to support development of actionable security blueprints, principles, models, designs, standards, and guidelines to ensure enterprise IT architecture and support is consistent, usable, secure and adds value to the business
Experience with network and vulnerability scanning tools and technologies to interrogate systems for configuration and status
In-depth understanding of security architecture principles and best practices to design, implement, and maintain secure IT infrastructures in alignment with A&A policies
Demonstrated proficiency in utilizing Governance, Risk, and Compliance (GRC) tools for managing Assessment & Authorization (A&A) processes
Ability to serve as subject matter expert (SME) for the US Government Client A&A process, including providing guidance to stakeholders, business units, and new A&A resources as necessary
Strong organizational skills and ability to build and maintain schedules and step-by-step action plans
Effective communication and collaboration skills to work with cross-functional teams, business units, stakeholders, and IT professionals, and to brief executives
A minimum of eight (8) to twelve (12) years' relevant experience
A degree from an accredited College/University in the applicable field of services is required. If the individual's degree is not in the applicable field then four additional years of related experience is required
Typically performs all functional duties independently
Note: Special credentials (licenses and/or certifications) may be required at the Task Order level on a case-specific basis