5021-Cyber Security SME (ISSE)-TS/SCI w Poly
IronBrickAbout the role
Job Description: Cyber Security SME (ISSE)
Location: Herndon, VA
Clearance-TS/SCI Fullscope Poly
IronBrick was founded in 2006 with the vision to reduce the cost, risk, and effort of managing information. Today that vision is still strong, our innovative services and solutions transform IT environments by solving customer’s complex technology and business challenges.
- Possess multi-tasking skills, as well as be a good communicator/facilitator. Comfortable at all levels from developer to senior staff.
- Knowledge of the complex network environments involving shared networks and multiple security enclaves.
- Possess the ability to bridge the technical implementation (i.e. developer talk), into commonly understood security words. Often this is a skillset and is not an actual language, but frequently translation or a basic understand needs to be conveyed by the ISSE when speaking with others or in writing the documentation in order to ensure it’s easy to understand.
- Document the various security control implementations as well as gather the artifacts that support the Risk Management Framework (RMF) and ICD 503 Security Accreditation for various Assessment and Authorization (A&A) efforts
- Document and obtain a general understanding of the architecture being developed or that was developed for each project in order to write the Systems Security Plans (SSP)/CONOPS in the Xacta application.
- Gather the information by working with various team members in order to write various additional A&A related documents such as Contingency Plan (CP), General User Guide (GUG), Privileged User Guide (PUG), Standard Operating Procedures (SOP’s), etc.
- Support Accreditation and Authorization (A&A) reviews by ISSO/M, as well as the Security Controls Assessor (SCA)
- Document the Plans of Actions and Milestones (POA&Ms) implementation responses or mitigations, as well as provide all required artifacts (i.e. evidence gathering from the teams)
- Coordinating with various contractor and staff personnel to obtain the A&A content, as well as working with various customer security organizations to navigate the customer’s A&A process in order to achieve Authority to Develop (ATD), Interim Authority to Operation (IATT), as well as Authority to Operate (ATO).
- Keep track of where each of the various A&A projects are within the customer’s A&A process in order to know when it’s time to re-submit for accreditation or an accreditation extension.
- Previous ISSE experience directly supporting the customer.
- Previous ISSO experience directly supporting the customer is also helpful.
- Various security tools and reports such as Xacta, RoadRunner, Rapid 7, WebInspect, App Detective, and Splunk
- Public, private and hybrid Cloud experience (AWS, Microsoft Azure, etc.)
- Virtualization experience (VDI & VMWare)
- Basic knowledge is helpful, but not required for the following general topics: Cloud security control implementation, PKI implementation, STIG compliance and vulnerability management, and Security Development and Operations (SecDevOps)
- CISSP, or GSLC
- AWS Certified Security Specialty
- Basic Excel and Microsoft Office365"
IronBrick is an awesome place to work and keep learning! We want our employees to have a good quality of life both inside and outside of the workplace. We offer an environment where employees can achieve success in areas that are most important to them. Our competitive benefits package helps ensure our employees have a healthy work
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s