InfiniSource Consulting SolutionsInfiniSource Consulting Solutions (ICS), a 150+ employee government contractor specializing in Management Consulting, Information Technology, and Professional Services to the federal government. We tailor our services to meet the specific needs of our civilian, defense, and private-industry sponsor. Our corporate support processes are ISO 9001 certified, giving our customers the confidence that we are continually measuring and improving upon the support we provide and are committed to the highest level of customer satisfaction.
SUMMARY
This position is for an experienced Information Systems Security Officer (ISSO) responsible for assuring compliance with all information system (IS) security requirements. The ISSO ensures proper assessment and implementation of security practices and procedures and validation of all security obligations toward meeting the Federal Information Security Modernization Act (FISMA) Risk Management Framework (RMF) requirements.
ESSENTIAL FUNCTIONS
- Ensure that Learning Systems Unit (LSU) adhere to Federal Information Assurance policies and procedures to acquire and maintain an Information System(s) Authorization to Operate (ATO) under the FISMA, by following NIST 800-53 guidelines and NIST 800-53a security controls assessment practices for all current and future systems.
- Ensure the day-to-day implementation, oversight, continuous monitoring, and maintenance of the security configuration, practices, and procedures for each information system.
- Provide liaison support between the LSU system owner and other FBI info system security personnel.
- Guides LSU Operations/system engineering design and development toward a “baked-in” security approach using Information Assurance best practices, as well as FBI-specific policies and guidelines.
- Create and update the Privacy Threshold Analysis (PTA) and Privacy Impact Assessment (PIA), Configuration Management Plan (CMP), Contingency Plan (CP) and Incident Response Plan (IRP), as required for each system
- Responsible for keeping track of all privileged users accessing IS’s.
- Conduct required info system vulnerability scans and log analysis according to risk assessment parameters.
- Ensure that all system security Plan of Actions and Milestones (POA&Ms) are reviewed and updated.
- Ensure all information security audit logs are retained in accordance with DOJ, ODNI or FBI policy
- Report any information system security incidents to the Information Systems Security Manager (ISSM) and/or Chief Security Office (CSO), immediately, and initiate upon approval, any protective and corrective measures, required to be taken.
- Actively participate as a security board member in the Change Management Process
- Ensure all info systems are operated, maintained, and disposed of in accordance with security policies.
- Perform at a level where all information system security assessment documentation delivered to the government is accepted on 1st pass. The government criteria shall be based on administrative (grammar, spelling, punctuation, classifications markings, etc.) and technical review.