Information System Security Officer
DeloitteAbout the role
Information System Security Officer
Risk Management and Governance | Cyber RiskColorado Springs, Colorado, United States
Position Summary
Are you looking to elevate your cyber career? Your technical skills? Your opportunity for growth? Deloitte’s Government and Public Services Cyber Practice (GPS Cyber Practice) is the place for you! Our GPS Cyber Practice helps organizations create a cyber minded culture and become stronger, faster, and more innovative. You will become part of a team that advises, implements, and manages solutions across five verticals: Strategy, Defense and Response; Identity; Infrastructure; Data; and Application Security. Our dynamic team offers opportunities to work with cutting-edge cyber security tools, and grow both vertically and horizontally at an accelerated rate. Join our cyber team and elevate your career.
Recruiting for this position will end on Dec 9, 2024
Work you'll do:
- Assist ISSM gaining and maintaining RMF accreditation packages for current and future DCO-S tool suites, sites and networks, perform assessments of systems and networks within the networking environment or enclave and identify where those systems and networks deviate from acceptable configurations, enclave policy, or local policy.
- Perform passive evaluations such as compliance audits and active evaluations such as vulnerability assessments, establishing strict program control processes to ensure mitigation of risks and support obtaining certification and accreditation of systems.
- Lead support of process, analysis, coordination, security certification test, security documentation, as well as investigations, software research, hardware introduction and release, emerging technology research inspections and periodic audits.
- Assist in the implementation of the required government policy (i.e., NISPOM, NIST 800, JSIG), make recommendations on process tailoring, participate in and document process activities.
The team
Deloitte’s Government and Public Services (GPS) practice – our people, ideas, technology and outcomes—is designed for impact. Serving federal, state, & local government clients as well as public higher education institutions, our team of more than 15,000 professionals brings fresh perspective to help clients anticipate disruption, reimagine the possible, and fulfill their mission promise.
At Deloitte, we believe cyber is about starting things—not stopping them—and enabling the freedom to create a more secure future. Our Cyber Application Security team advises federal clients on integrating security activities throughout the software development lifecycle to enable the design, build, and deployment of secure applications. Our team focuses on concept and requirements, design and development, verification, production and maintenance, and retirement. If you’re seeking a career in vulnerability management, quality assurance, or GRC tools, then Application Security at Deloitte is the offering for you.
Qualifications
Required :
- MA/MS degree and 10 years of experience, or BA/BS and 18 years of experience
- Must be legally authorized to work in the United States without the need for employer sponsorship, now or at any time in the future
- Active Secret security clearance required
- 10+ years of experience with implementation of the required government policy (i.e., NISPOM, NIST 800, JSIG)
- Detailed understanding of how to prepare and review Security test and Evaluation (ST&E) plans and test reports, analytical evaluation of systems’ applicable RMF controls and mitigations, system hardening procedures, and development of Cyber requirements.
- 5+ years experience (4 years of experience may be used in lieu of degree) with Cybersecurity, The Risk Management Framework, Program Security, and Controlling, labeling, virus scanning, and appropriately transferring data (upload/download) between information systems at varying classification levels
- 10+ years of experience with DoD cybersecurity policies, manuals, and standards and developing and maintaining RMF assessment and authorization documentation through the system life-cycle including experience with DISA STIGS, eMASS and Xacta
- Competency in Microsoft Windows Server, Active Directory, VMWare, Microsoft Office, video teleconferencing/VOIP, and Microsoft Azure
For individuals assigned and/or hired to work in Colorado, Deloitte is required by law to include a reasonable estimate of the compensation range for this role. This compensation rang
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s
Similar roles
Assistant Professor of Management Information Systems - Tenure Track
University of Oklahoma
Information Specialist Medical Laboratory Scientist (Hybrid)
Geisinger
Chair of Computer and Information Science (CIS)
University of Michigan-Dearborn