Information System Security Specialist - L3 - TO 9
Apply on
Availability Status
This job is expected to be in high demand and may close soon. We’ll remove this job ad once it's closed.
Job Description
Insider Threat Engineering Specialist Information System Security Specialist 3
Work Description: The Insider Threat Engineering Specialist Information System Security Specialists enhance Counter Insider Threat information systems security, policies, procedures, and tools to ensure the
confidentiality, integrity, and availability of systems, networks, and data.
Duties:
Provide guidance, assistance, and coordination to systems developers, systems administrators, and other IT specialists to ensure verified and timely implementation of IT security standards for systems both under development and already deployed.
Document, manage, and control the integrity of changes to all systems security documentation, including standard operating procedures and user guides that provide detailed instructions for implementing IT systems security policies.
Assist in the selection of minimum-security controls to establish a baseline of measures to prevent security breaches of the information system, document the selected security controls in the security plan and initial Risk Assessment Report (RAR), and, document an approved continuous monitoring strategy.
Document the security control implementation, as appropriate, in the security plan, providing a functional description of the control implementation (including planned inputs, expected behavior, and expected outputs).
Conduct security testing and verify which security controls are implemented correctly, operating as intended, and producing the desired outcome in meeting security requirements.
Conduct remedial actions on security controls based on the findings and recommendations of the Security Assessment Report and reassess remediated control(s), as appropriate.
Review vulnerability scans and ensure the accountable parties have responded appropriately to vulnerability findings, troubleshoot security threats and vulnerabilities in response to incident reports, and identify/isolate problem sources; and recommend solutions or corrective actions.
Monitor and analyze systems logs daily to identify systems security trends and assess the security effectiveness of installed systems based on analysis of reported security problems.
Participate in multi-functional teams and manage work through JIRA.
Required Skills and Experience:
Active TS/SCI security clearance.
Certified in a DOD 8570 IAM Level II baseline certification
Possess a minimum of 5 years security engineering experience
Experience in applying the National Institute of Standards and Technology (NIST) Special Publication 800-53 Risk Management Framework.
Desired:
Experience in using JIRA or an alternative Agile Project Management tool
Experience in using Confluence or alternative knowledge management tool
JIRA Certification
Confluence Certification