Overview
On Site
Depends on Experience
Full Time
Skills
Information Assurance
Impact Analysis
Information Architecture
Policies and Procedures
System Security
SSP
RAR
Traceability Matrix
SCTM
Authorization
Information System Security
Configuration Management
Computer Hardware
Firmware
NIST SP 800 Series
Publications
Regulatory Compliance
Threat Analysis
Risk Assessment
Security Engineering
Testing
Product Requirements
Reporting
Security Architecture
Design Review
Management
DoD
Security+
Customer Engagement
Cyber Security
Security Controls
Risk Management Framework
RMF
IT Infrastructure
Virtualization
Cloud Computing
Forms
Security Clearance
SAP
eMASS
XACTA
Microsoft Windows
Red Hat Enterprise Linux
Amazon Web Services
Auditing
Log Analysis
Splunk
Patch Management
Vulnerability Assessment
STIG
Aerospace
Communication
Insurance
Job Details
Job Description
Readiness Delivered. At Kratos, we encourage an entrepreneurial spirit balanced with discipline. We work hard, and take care of our customers, employees, and families. Recognized as thought leaders in our industry, we are motivated by creating and delivering innovative solutions to our nation and global customers. Kratos has an exciting opportunity for an ISSO to support the Information Assurance (IA) development and sustainment of assigned systems and to serve as a security support element for technical teams. This is accomplished in compliance with CMMC and Risk Management Framework (RMF) policies and procedures, including the development of System Security Plans (SSP), Risk Assessment Reports (RAR), Plans of Action and Milestones (POA&M), and Security Control Traceability Matrices (SCTM). The ISSO maintains the operational security posture to ensure that security policies, standards, and procedures are followed throughout the system lifecycle. Additionally, the ISSO supports vulnerability and risk assessment analysis to achieve and sustain Authorization to Operate (ATO) and ensures information system security requirements are integrated into configuration management for software, hardware, and firmware.
This position is based on multiple DoD Directives; including DoD 5205.07 volumes 1-4; DoDD 5205.02E; DoDI 5025.01, 5205.11, 5200.39, 5220.22, DoDM 3305.13; DoD 8140 series; Intelligence Community Directive Series 500/600/700; NIST 800 series special publications; Executive Orders 13556 and 13636, the Joint Special Access Program Implementation Guide Rev 4, and DISA Security Technical Implementation Guides.
Applicants selected will be subject to a government security investigation and must meet eligibility requirements for access to classified information. U.S. citizenship is required. Travel to customer sites and other program locations may be required.
Primary Responsibilities:
Experience and Skills
Preferred Skills and Experience
#LI-Onsite
The grade-based pay range for this job is listed below. Individual salaries within that range are determined through a wide variety of factors including but not limited to education, experience, knowledge, and skills.
Competitive salary based on experience and education
Salary Range: $89,000-$125,000
Kratos is valued for our ability to design and deliver leading edge, resilient solutions for aerospace communication, control, awareness and mission success across a continuum of offerings-from commercial to tailored custom solutions and integrated programs. Customers trust us to stay relevant and know we are in it for the long-haul. We bring both the capability and confidence that our customers value and depend on. And we always deliver.
This posting will close within 90 days from the Posting Date.
Job Benefits
Readiness Delivered. At Kratos, we encourage an entrepreneurial spirit balanced with discipline. We work hard, and take care of our customers, employees, and families. Recognized as thought leaders in our industry, we are motivated by creating and delivering innovative solutions to our nation and global customers. Kratos has an exciting opportunity for an ISSO to support the Information Assurance (IA) development and sustainment of assigned systems and to serve as a security support element for technical teams. This is accomplished in compliance with CMMC and Risk Management Framework (RMF) policies and procedures, including the development of System Security Plans (SSP), Risk Assessment Reports (RAR), Plans of Action and Milestones (POA&M), and Security Control Traceability Matrices (SCTM). The ISSO maintains the operational security posture to ensure that security policies, standards, and procedures are followed throughout the system lifecycle. Additionally, the ISSO supports vulnerability and risk assessment analysis to achieve and sustain Authorization to Operate (ATO) and ensures information system security requirements are integrated into configuration management for software, hardware, and firmware.
This position is based on multiple DoD Directives; including DoD 5205.07 volumes 1-4; DoDD 5205.02E; DoDI 5025.01, 5205.11, 5200.39, 5220.22, DoDM 3305.13; DoD 8140 series; Intelligence Community Directive Series 500/600/700; NIST 800 series special publications; Executive Orders 13556 and 13636, the Joint Special Access Program Implementation Guide Rev 4, and DISA Security Technical Implementation Guides.
Applicants selected will be subject to a government security investigation and must meet eligibility requirements for access to classified information. U.S. citizenship is required. Travel to customer sites and other program locations may be required.
Primary Responsibilities:
- Perform security assessments such as vulnerability and compliance assessments, threat analysis, security code reviews, and risk assessments to identify potential design and implementation vulnerabilities.
- Participate in regular security self-inspections and audits.
- Assist with the selection and implementation of security controls and features for systems and applications.
- Identify new security features and recommend updates to existing products to ensure security is maintained throughout the product lifecycle.
- Perform security assessments on new and proposed products and technologies to ensure secure integration into the approved baseline.
- Provide product security engineering support and recommendations used to resolve integration and testing issues.
- Maintain a standardized set of security product requirements and produce metrics to report performance against those requirements.
- Review and define security diagnostics and tools to facilitate the analysis and reporting of security events.
- Assist other teams with mitigating security risks, responding to product security incidents, and product security related issues.
- Participate in security architecture and design review meetings.
- Manage system access and revocation requests. Track and verify DoD certification requirements in accordance with DoD 8140 guidance.
Experience and Skills
- A solid knowledge of the DISA/DoD Risk Management Framework.
- CompTIA Security+ CE, CASP+, or equivalent cybersecurity certification.
- Experience with security controls, RMF, and STIGs.
- Familiarity with modern IT infrastructure capabilities to include virtualization, cloud deployment, and containerization.
- Self-motivated and comfortable with supporting multiple groups of developers, engineers, test, and deployment.
- Able to clearly communicate technical concepts orally and in written forms to internal and external audiences with technical and non-technical backgrounds.
- Capable of working in a fast-paced team environment.
- Excellent organizational and communication skills and able to effectively interact with managers and technical staff.
- Top Secret clearance with SCI eligibility required. Candidates with Special Access Program (SAP) experience are highly valued.
Preferred Skills and Experience
- 2 years as an ISSO or equivalent duties.
- Familiarity with eMASS, XACTA, or similar government systems of record.
- Familiarity with Zero Trust Architecture (ZTA) requirements.
- Experience with Windows and RHEL environments.
- Experience with AWS.
- Experience with security tools such in the following areas: Malicious code prevention and analysis (i.e., Trellix), Audit log analysis (Splunk, Greylog, etc.), Patch Management and Vulnerability Analysis (Tenable Security Suite & ACAS), and security tools which support the implementation of DISA STIGs (SCC, Evaluate STIG, STIG Viewer, etc.).
#LI-Onsite
The grade-based pay range for this job is listed below. Individual salaries within that range are determined through a wide variety of factors including but not limited to education, experience, knowledge, and skills.
Competitive salary based on experience and education
Salary Range: $89,000-$125,000
Kratos is valued for our ability to design and deliver leading edge, resilient solutions for aerospace communication, control, awareness and mission success across a continuum of offerings-from commercial to tailored custom solutions and integrated programs. Customers trust us to stay relevant and know we are in it for the long-haul. We bring both the capability and confidence that our customers value and depend on. And we always deliver.
This posting will close within 90 days from the Posting Date.
Job Benefits
- Medical, Dental & Vision Insurance Coverage
- Life/ADD & Short/Long Term Disability Insurance
- 401(k) Savings Plan
- Employee Stock Purchase Plan (ESPP)
- Paid Time-Off (PTO)
- Holidays
- Education Reimbursement
Employers have access to artificial intelligence language tools (“AI”) that help generate and enhance job descriptions and AI may have been used to create this description. The position description has been reviewed for accuracy and Dice believes it to correctly reflect the job opportunity.