Senior Information System Security OfficerAs the Senior Information System Security Officer, you will provide strategic cybersecurity leadership, ensuring the security, compliance and operational integrity of mission-critical DoD systems.Key responsibilities include:Leading the development, implementation, and enforcement of cybersecurity policies, standards, and methodologies.Directing vulnerability management activities using ACAS, DISA STIGs, and SCAP Compliance Checker.Overseeing secure configuration of operating systems and network devices in accordance with DISA STIG requirements.Managing continuous monitoring efforts, conducting security audits, and driving risk mitigation strategies.Providing subject matter expertise on NIAP/Common Criteria certifications and DISA Approved Products List (APL) compliance.Preparing and reviewing authorization documentation, certification letters, and MOAs for system interconnections.Advising program leadership, system owners, and engineers on RMF compliance and cybersecurity best practices.This description outlines the general nature and scope of the role. Additional duties may be assigned as necessary.Requirements include:CompTIA Security + is required. Master's degree in Information Technology, Cybersecurity, Computer Science, or related area of study is required.
Without a degree, one of the following certifications is required: CISM, CISSP, FITSP-M, or GCIH. Please upload copies of any relevant IT certifications you hold.10 years of engineering experience, including at least 5 years in Information Assurance/Cybersecurity (IA/CS).Demonstrated experience implementing the Risk Management Framework (RMF) in accordance with DoDI .Extensive experience applying security controls outlined in CNSSI 1253, NIST SP 800-53, and JSIG.Able to conduct vulnerability assessments using ACAS, DISA STIGs, and SCAP Compliance Checker with automated benchmarks.Proven experience implementing DISA STIG configurations across operating systems and network devices.In-depth knowledge of continuous monitoring, security audits, risk assessments, and mitigation planning for DoD systems.Experience evaluating NIAP/Common Criteria technologies and the DISA Approved Products List (APL).Background preparing certification letters, MOAs, and authorization documentation for system interconnections.Experience developing IA-related acquisition documentation.Familiarity with Intelligence Community Directive (ICD) 705, DoDD , and DOD -M Volumes 1-4.Comfortable mentoring and guiding more junior teammates.Equally important are:Ability to build positive, collaborative relationships across teams and with external partners.Effective communicator with strong verbal and written skills.Proactive, self-directed work style with the ability to operate independently.Analytical thinker with proven problem-solving capabilities.Highly organized, with the ability to balance competing priorities in a fast-paced environment.This position requires U.S. citizenship and an active DoD Top Secret clearance.
Selected candidate will be subject to a government security investigation and must meet eligibility requirements for access to classified information.The anticipated annual salary range for this position is $135,000 - $155,000, commensurate with an individual's experience, qualifications, and skill set.ASEC offers meaningful, mission-driven work within a culture that supports your professional and personal growth. We partner with our government customers to deliver innovative solutions across engineering, information technology, training, and logistics. Above all, we are committed to doing what's right for the Warfighter—plain and simple.Why work at ASEC?100% employee-owned company.
Learn more about our Employee Stock Ownership Plan (ESOP) here!Comprehensive benefits package, including 11 paid holidays, medical/dental/vision coverage, HSA/FSA options, disability insurance, and more!401(k) with company matchTuition assistance for undergraduate and graduate educationVeteran-friendly employerThriving employee cultureASEC is an Equal Opportunity Employer. We recruit, hire, train, compensate, and promote employees based on qualifications, merit, and business needs, without regard to race, color, religion, sex, national origin, ancestry, age, marital status, sexual orientation, gender identity or expression, disability, veteran status, genetic information, pregnancy or related conditions (including breastfeeding), or any other status protected by law.ASEC also complies with all applicable pay transparency laws and will not discriminate against employees or applicants for inquiring about, discussing, or disclosing compensation.