What are the responsibilities and job description for the HPE Information System Security Officer position at Command Cyber Solutions, LLC?
Essential Duties & Responsibilities
Education, Certification & Experience Requirements:
- Lead cybersecurity planning and security architecture integration for the HPE GreenLake implementation.
- Assess all hosted systems for RMF compliance, authorization to operate (ATO) status, security-control implementation, and cloud-migration readiness.
- Validate system categorization, impact levels, data classifications, and applicable regulatory requirements.
- Identify cybersecurity risks, vulnerabilities, and compliance gaps that could affect migration sequencing and operational readiness.
- Develop cybersecurity requirements for integration with Zero Trust architecture, identity and access management, logging, continuous monitoring, and security information and event management (SIEM) capabilities.
- Ensure migration strategies incorporate security-by-design principles and applicable Department of War and Department of the Air Force cybersecurity policies.
- Support development of security implementation roadmaps, risk-mitigation strategies, and authorization packages necessary for cloud operations.
- Advise Government personnel on cybersecurity implications of modernization decisions and provide recommendations to maintain mission assurance throughout implementation and migration activities.
- Perform cybersecurity analysis and develop system topologies, data-flow mappings, and security architecture documentation supporting HPE GreenLake migration planning and implementation.
- Perform and assist in vulnerability-management activities, including executing ACAS scans; evaluating scan results; prioritizing findings; mapping remediation actions to affected systems; and supporting reduction of the overall vulnerability posture.
- Evaluate Security Technical Implementation Guides (STIGs) and complete required STIG checklists.
- Manage systems through the complete process of achieving and maintaining ATO in a Department of War/Department of the Air Force environment.
- Perform and support security patching, configuration-compliance validation, and remediation tracking.
- Develop, manage, and update the program risk register in coordination with project management and Government stakeholders.
- Support continuous-monitoring activities, cybersecurity reporting, incident-response coordination, and audit readiness.
- Perform other duties as assigned based on customer requirements.
Education, Certification & Experience Requirements:
- Bachelor's Degree in Business, Information Technology, Cybersecurity, or a related field with five (5) or more years of experience in information security, RMF, vulnerability management, cloud security, or a related field. A Master's Degree and two (2) or more years of relevant experience may be substituted.
- Security CE or IAM/IAT I equivalent
- Active Secret clearance
- Must have relevant Department of the Air Force RMF experience.
- RMF assessment and authorization activities, including development and maintenance of authorization-package artifacts.
- Vulnerability management, including conducting scans and evaluating and prioritizing scan outputs.
- Evaluating STIGs and completing STIG checklists.
- Successfully obtaining or maintaining systems through the complete ATO process.
- Cloud security architecture and migration support, preferably in an HPE GreenLake, hybrid-cloud, or comparable environment.
- Identity, credential, and access management; Zero Trust architecture; logging; continuous monitoring; and SIEM integration.
- Security patching and configuration management.
- Experience using eMASS or other related cybersecurity governance, risk, and compliance tools.
- Strong organizational, analytical, problem-solving, written communication, and interpersonal skills.
- Cybersecurity expertise
- RMF ATO, and continuous-monitoring experience
- Cloud-migration and cloud-security experience
- HPE GreenLake or comparable hybrid-cloud environment familiarity
- Zero Trust architecture integration
- Identity and access management
- Security logging, monitoring, and SIEM integration
- Data-center security
- Security policies and procedures
- Security frameworks and standards
- Vulnerability management and compliance auditing
- Security monitoring and incident response
- Risk management
- Cybersecurity training and awareness
- Vendor security assessment
- Security incident investigation
- Project-management coordination
- Effective communication with Government, technical, and program-management stakeholders