Information Security Analyst
Duties include but are not limited to: Track and manage POAMs throughout the remediation cycle from creation to closure.
Review and approve Technical Requirement Model (TRM) for software products
Lead Authority to Operate efforts for assigned Air and Marine Operations systems
Ensure technical team is adhering to laid down policy and procedures to meet DHS and CBP compliance requirements.
Ensuring audit logs are reviewed periodically in accordance with departmental policy and the Security Authorization documentation (e.g. weekly or daily)
Develop, analyze and update System Security Plan (SSP), Risk Assessment (RA), Privacy Threshold Analysis (PTA), Privacy Impact Assessment (PIA), System Security test and Evaluation (ST&E) and the Plan of Actions and Milestones (POA&M)
Document risks and appropriate compensation controls for the Authorizing Official to make a risk-based decision on identified vulnerabilities.
Designate systems and categorize its C.I.A using FIPS 199 and NIST SP 800-60
Create update Standard Operating Procedure (SOP) for process flows and quality enhancements
Develop Information Security Continuous Monitoring Strategy to help maintain an ongoing awareness of information security (Ensure continued effectiveness of all security controls), vulnerabilities, and threats to support organizational risk management decisions
Create security impact analysis document to accompany required changes for Change Control Board approval before changes are made to assigned systems
Required Education, Experience and Qualifications: Significant ISSO experience required, in lieu of degree. (2 years)
A minimum of 7 years of experience in the following:
Developing System Security Plan
Managing and tracking POAMs
Continuing monitoring activities
Developing Standard Operating Procedures (SOP)
Understanding of NIST 800-Series
Proficiency with Microsoft Office software, including Word, Excel, PowerPoint, Outlook, and SharePoint.
Positive adjudication from a CBP Background Investigation.