Founded in 2009, RSC2, Inc. is a Small Business Administration (SBA) Certified HUBZone Professional Services company headquartered in Baltimore, Maryland. RSC2 provides breakthrough expertise, support services, and technologies to make operations, programs and systems of record perform better. Our professional staff is trained to provide world-class services to all types of customers. We uphold the integrity and quality of our work so you can expect only the best from us. We are looking for a RMF Lead/ISSO to join our growing company! This role is located at Aberdeen Proving Ground, MD. Information Systems Security Officer (ISSO) candidate to support Government customer in the APG, Maryland area. The candidate will be responsible for ensuring compliance with the ISSO Roles and Responsibilities as laid out in agency directives, instructions, and memos. Duties and responsibilities include:
Perform tasks delegated by the ISSM in support of various information assurance /cybersecurity programs such as security authorization activities in compliance with Risk Management Framework (RMF) policies and procedures including System Security Plans (SSPs), Risk Assessment Reports, A&A packages, and Security Controls Traceability Matrix (SCTM)
Maintains operational security posture to ensure information systems (IS), security policies, standards, and procedures are established and followed
Performs vulnerability/risk assessment analysis to support Assessment & Authorization (A&A)
Review and analyze system audit logs to identify anomalous activity and potential threats to network resources
Conducting vulnerability scans and recognizing vulnerabilities in security systems
Ensure that cybersecurity-enabled products or other compensating security control technologies reduce identified risk to acceptable security levels
Apply a full range of Cybersecurity policies, principles, and techniques to maintain the security integrity of information systems processing classified information
Perform security reviews and identify security gaps in security architecture resulting in recommendations for inclusion in the risk
Work with government customers to support computer security incidents and vulnerability compliance
Input and maintain system documentation into government record-keeping systems like Xacta and eMASS
Provide Configuration Management for security-relevant information system software, hardware, and firmware
Perform risk analysis whenever an application or system undergoes a major change
Provide input to the Risk Management Framework process activities and related documentation
Required Qualifications:
Must be a US Citizen
Active security clearance
Experience considered in lieu of degree
A minimum of 5 years of experience as an IA/Security Specialist and OMB Information Security directives/policy compliance
Must hold active Security , CISSP, CISA, or equivalent certifications (DoD 8570 IAM 2 equivalent)
At least 5 years of direct experience and in-depth working knowledge of FISMA and NIST Information Security Guides
Advanced written and verbal communication skills
Desired Qualifications:
Experience with effective policy, instruction, and development for Federal or DoD Information Security Programs
Experience with performing Security Control Assessment in compliance with NIST SP 800- 37, NIST SP 800-53, NIST SP 800-53A, and other NIST 800 guides
Experience with risk analysis and assessment determinations