Caci

Information System Security Officer - Jr.

Washington, Washington, United StatesFull timeJunior$72,700 / yearPosted 1 day ago
Apply on Caci →

Sign in to see who you know at Caci.

Job Title: Information System Security Officer - Jr.Job Category: Information TechnologyTime Type: Full timeMinimum Clearance Required to Start: NoneEmployee Type: RegularPercentage of Travel Required: Up to 10%Type of Travel: Local* * *The Opportunity:CACI is searching for a Junior Information System Security Officer to support the FEMA Office of the Chief Information Security Officer (OCISO) in Washington, D.C. As a Junior ISSO, you will play a crucial role in ensuring the security and compliance of FEMA's information systems. You will work in a dynamic environment, collaborating with Lead ISSOs, IT system owners, stakeholders, and cybersecurity professionals to implement and maintain robust security controls. Your efforts will directly contribute to safeguarding FEMA's mission-critical systems and data. The Junior ISSO will be responsible for technical cybersecurity efforts in coordination with Senior ISSOs and ISSMs and system owners, providing support to the Compliance Branch Lead. Serving as a point of contact for technical cybersecurity matters related to quantifying technical risk, the Junior ISSO will execute Risk Management Framework activities for ATO decisions, ensure confidentiality, integrity, and availability of FEMA Information Systems, and implement security controls throughout the system lifecycle. This position requires maintaining a security posture in compliance with FISMA, DHS 4300 Series, NIST, and DHS and Component Directives.Responsibilities:The Junior ISSO will execute Risk Management Framework activities for ATO decisions and ensure systems meet compliance requirements while ensuring confidentiality, integrity, and availability of FEMA Information Systems through proper security control implementation. This position requires implementing security controls and conducting system assessments to identify vulnerabilities and gaps, as well as developing and maintaining various system-related artifacts (System Security Plans, Configuration Management Plans, and Contingency Plans, etc). The Junior ISSO will conduct Security Impact Analyses and test configuration changes pre- and post-deployment, support continuous monitoring of IT systems, and develop and track POA&Ms for identified vulnerabilities. Responsibilities include developing security requirement traceability matrices and managing hardware and software inventory lists, supporting cloud security initiatives, and participating in Change Advisory Board (CAB) reviews. The position involves conducting technical vulnerability assessments, providing audit support documentation, and responding to cybersecurity data calls with timely information to leadership. Critical deliverables include generating and tracking POA&Ms within 0 to 15 days after vulnerability identification, and updating System Security Plans, Configuration Management Plans, and Contingency Plans annually or when changes occur. The Junior ISSO will conduct Security Impact Analysis Reports within 5 bu...