Jobs and Careers
KB

Information Systems Security Officer

KBR, Inc.
Lexington Park, United Statesfull_timeVerifiedPosted 21 Dec 2023

About the role

Title:

Information Systems Security Officer

KBR has an opening for an Information Systems Security Officer to join our team of qualified, diverse individuals onsite at KBR, Lexington Park, MD. This position requires on site presence.

Note: Remote or Tele-Work is not available.

Duties and Responsibilities:

  • Serves as an Information Systems Security Officer (ISSO) for Government information systems in support of a Program Management Activity (PMA).

  • Performs extensive assessments of systems and networks within the networking environment or enclave and identify where those systems/networks deviate from acceptable configurations, enclave policy, or local policy; Candidate will achieve this through passive evaluations (compliance audits) and active evaluations (vulnerability assessments). 

  • Establishes strict program control processes to ensure mitigation of risks and supports obtaining certification and accreditation of systems; This includes process support, analysis support, coordination support, security certification test support, security documentation support, investigations, software research, hardware introduction and release, emerging technology research inspections and periodic audits.

  • Assists in the implementation of the required government policy (i.e., RMF, NISPOM, JSIG) and makes recommendations on process tailoring. 

  • Performs extensive analyses to validate established security requirements and to recommends additional security requirements and safeguards.

  • Supports the formal Security Test and Evaluation (ST&E) required by each government accrediting authority through pre-test preparations, participation in the tests, analysis of the results, and preparation of required reports. 

  • Periodically, conducts of a review of each system's audits and monitors corrective actions until all actions are closed. Manages / tasks junior level Information Assurance or System Administrator personnel.


Required Qualifications:

  • Bachelor’s degree in computer and architecture information systems management or related field from an accredited college or university or equivalent experience is required OR an additional four (4) years of relevant experience may be substituted for a Bachelor’s Degree.

  • Two (2) years of experience with mid-sized client/server systems in systems analysis, software design, software development, and system administration are required.

  • Experience with DoD NIST SP 800-53 or Risk Management Framework (RMF) and Joint SAP Implementation Guide (JSIG) requirements is required.

  • Knowledge of quality assurance, quality control, and independent verification and validation techniques is required.

  • Experience working independently and as part of a team in researching data, developing analytical techniques and methodologies is required.

  • Experience with managing secure Information Systems (IS) and databases while implementing and maintaining cross-domain solutions is required.

  • Experience creating custom filters within comprehensive auditing software / environments such as SPLUNK or GFI Events Manager.

  • Experience with Data Loss Prevention (DLP) tools.

  • Experience with Linux, Power-shell scripts used for automation.

  • Experience with VMware / Virtual Cloud Foundation (VCF)

  • Experience with COMSEC Policy / Procedures, OTAT & reconciling COMSEC Inventories

  • A current Information Assurance Manager (IAM) Level I certification in accordance with DoD 8570.01-M, or the ability to gain the IAM Level I certification within six months is required.

  • Applicant selected may be subject to a government security investigation and must meet eligibility requirements for access to classified information. A current Top-Secret Clearance with a Single Scope Background Investigation (SSBI) completed within the last 5 years is required.

Preferred Qualifications:

  • Participates in the development and maintenance of system security plans and contingency plans for all systems under their responsibility.

  • Draft, maintain, Planned, System Security Checklists, Security Impact Assessments, POA&M, and Authority to Operate (ATO) artifacts.

  • Maintain inventory of all information Security System assigned.

  • Develop a variety of Assessment & Authorization deliverables to include System Security Plan (SSP), Security Assessment Report (SAR), Configuration Management Plan (CMP), Contingency Plan (CP) and POA&M for review and approval for Authorization Official

  • Effectively communicate Technical Information to non-technical personnel

  • Coordinate with Leadership across the o

Apply for this role

Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.

Apply Now →Generate Application Kit

Free account required — sign up in 30s

Company

KBR, Inc.

View company profile →