CCS Global Tech is a rapidly growing Information Technology company with a diverse portfolio of technology products and services and a large network of industry partnerships. With over 22 years of being a successful business with a global talent pool and presence, CCS is a certified Microsoft Gold Partner and specializes in delivering expert Microsoft based solutions for technical and business needs. We have been recognized by Inc. 500 Magazine as one of the fastest growing small companies in the Unites States.
we are a Tier 1 vendor for the City and County of San Francisco for Cloud Services, Staffing Services and Training Services. For this multi-year opportunity with a diverse set of needs to address, we are currently focusing on establishing partnerships with individuals as well as companies who can help us enhance our overall service portfolio, cut lead times, and ultimately help us deliver successfully. We currently hold sizable Government accounts in the San Francisco bay area including City and County of San Francisco, San Mateo County, and Santa Clara County.
We take great pride in our global reach and local influence. Your experience alongside our highly skilled and talented internal team who guide you along the way, offers key insights into what helps you stand out in a competitive job market.
If you are a partner company, please submit resumes with contact information of your own W2 Consultants only. Submitted consultants are expected to have excellent communication skills.
Position Title: Information System Security Officer (ISSO)
LCAT: Computer Security System Specialist - Level II
Clearance: Public Trust
Work Location: Vienna, VA
Salary Range: $ 110,000- $125,000
Job Description Essential Duties & Responsibilities
Role Overview: The Information Systems Security Officer (ISSO) conducts research, develops, implements, tests, and reviews an organization's information security to protect information and prevent unauthorized access. Emphasis on general knowledge of infrastructure devices (i.e. firewalls, routers, switches).
Responsibilities: o Conduct initial Security Assessment and obtain system Authorization to Operate (ATO), in line with NIST SP 800-37 Rev. 2.
o Maintain the Security Authorization or ATO of assigned system(s)
o Continuously update all Security Authorization documentation to maintain assigned system's ATO or system go-live dates.
o Select the baseline security controls for the IT system, using the CSAM Governance, Risk, and Compliance (GRC) Tool, and tailor controls where appropriate.
o Document all relevant NIST 800-53 Security Controls for assigned IT systems in the System Security Plan (SSP).
o Perform and document initial and annual risk self-assessments of all systems assigned
o Develop and document all supporting Security A&A artifacts (i.e., PTA, SSP, ITCP, BIA, CMP, MOU, ISA).
o Produce Security Authorization package for Authorizing Official (AO) signature including ATO
o Track the deployment of software to the environment that is not part of the base image.
o Conduct security impact analyses of proposed changes, provide recommendations.
o Ability to analyze configuration settings, implementation of STIGs, and conducting manual checklists.
o Generate and manage Plan of Action & Milestones (POA&Ms), with meaningful milestones, and clear/concise implementation statements for each non-compliant control for assigned IT Systems.
Required Skills & Experience 3-5 years Cybersecurity experience
Working knowledge and experience with CSAM and the NIST RMF
Solid knowledge of the process to obtain a system ATO and requirements to maintain the ATO
Experience working with system stakeholders to assess and manage system cybersecurity risk
Ability to synthesize complex IT system information and communicate system status and requirements in written products and verbal presentations
Ability to write clear, concise and effective security control implementation statements
Familiarity with configuration settings and vulnerability management analysis of infrastructure devices
Ability to draft a complete ATO package, to include the SSP
Ability to work independently, and efficiently, with minimal direct supervision, and within given timelines
Required -
Professional Certification(s): Security+
Formal Education: HS Diploma
Years of Professional Experience: Minimum 3-5
Desired Skills & Experience
BS in Computer Science, Information Technology, or related field
CISSP, Security+, CGRC (formerly CAP), CISM
Required Technical/Business Tools Experience
CSAM GRC Tool
DHS experience
Physical Requirements
Ability to work onsite at customer HQ 1-2 times per week