Jobs and Careers
NT

Senior ISSO (Top Secret)

NTT DATA
Washington, United Statesfull_timeVerifiedPosted 3 Jan 2024

About the role

Req ID: 265495 

NTT DATA Services strives to hire exceptional, innovative and passionate individuals who want to grow with us. If you want to be part of an inclusive, adaptable, and forward-thinking organization, apply now.

We are currently seeking a Senior ISSO (Top Secret) to join our team in Washington, District of Columbia (US-DC), United States (US).

NTT DATA is seeking qualified Information System Security Officers (ISSO) who will be responsible for performing in part or as a whole the following activities as part of an enterprise service offering.  The primary responsibilities identified are but not limited to:

 

Responsibilities

Ensuring the confidentiality, integrity, and availability systems, networks and data are at an acceptable level of risk throughout the system development life cycle by being a key contributor to a security service offering based on but not limited to the responsibilities detailed below:

Server as an ISSO resource based on level effort required to successfully navigate all seven phases of the security authorization process and systems engineering lifecycle (SELC).  The ISSO will need to be well versed in the application and implementation of effective risk management to support the Team.  Ensure security best practices and standards are built within the design and development of systems.

Provide technical analysis and input into the source code reviews of Government-of-the-shelf (GOTS) applications.

Provide developers and Program Office with methods and recommendations on resolving application-level vulnerabilities.

Perform static code analysis and provide residual risk reports.

Provide technical analysis of supply chain risk and communicate to senior leadership monthly.

Actively participate in external agency meetings for both unclassified and classified networks and facilities.

Support IT system owners on the security control implementation and authorization activities of all systems, in the implementation of the NIST Cybersecurity Framework, NIST RMF, and DHS cybersecurity requirements.

Address all aspects of Systems Management for any IT System (to include but not limited to the following tasks).

  • Document Federal Information Processing Standard (FIPS) Information Types
  • Provide ISSO support to ensure the confidentiality, integrity and availability of DHS IT applications and systems.
  • Implement Risk Management Framework Activities to achieve an Authority to Operate.
  • Develop, update, and maintain the System Security Plan (SSP).
  • Develop, update, and maintain Configuration Management (CM) Plan(s).
  • Provide analysis of system or application configuration changes by assessing the cybersecurity impact of changes to IT systems.
  • Conduct technical vulnerability assessments, prioritize, and track remediation efforts at the application and system level.
  • Assist system owners in managing POA&Ms for designated IT systems.
  • Provide the required system access, information, and documentation to internal and external security assessment and audit teams.
  • Participate in security assessments and audits for systems and facilitate obtaining evidence for data requests.
  • Complete required security authorizations activities for IT systems.
  • Assist federal staff in providing expertise and training to system owners and other key stakeholders within the agency.
  • Respond to cybersecurity data calls.
  • Assess system and application changes and provide detailed technical analysis to determine the security impact to the agency’s risk level and applicable security authorization package.
  • Assist federal staff in interpreting new and existing cybersecurity directives, guidance, and policy to enforce cybersecurity requirements.
  • Provide cybersecurity input into the design and development of applications and systems.
  • Assess the security posture of application(s) / system(s) by identifying applicable NIST SP 800-37 RMF requirements and advising system owners of the process and assist in managing the risk.
  • Review security architecture designs.
  • Develop security requirement traceability matrix.
  • Manage and develop authorization boundary diagrams.
  • Develop and maintain Hardware and Software Inventory Lists.
  • Conduct annual security assessments and provide test reports.
  • Perform system and network auditing requirements.
  • Develop, update, and maintain security products and documentation, at a minimum monthly or whenever significant changes occur.
  • Responsible for all deliverables and system security documentation used to document, define, and maintain the system(s). 
  • Provide daily technical remediation support services by monitoring all systems Remediation Work Plans (RWPs) and POA&

Apply for this role

Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.

Apply Now →Generate Application Kit

Free account required — sign up in 30s

Company

NTT DATA

View company profile →