Information System Security Specialist II

We are seeking an experienced Information System Security Specialist II to support the security authorization, compliance, and continuous monitoring activities of mission-critical information systems. The successful candidate will create and maintain IA artifacts, support Authority to Operate (ATO) efforts using the Risk Management Framework (RMF), perform compliance scanning and patch management activities, and collaborate with system owners, ISSMs, and technical teams to ensure systems remain secure and compliant.


Key Responsibilities:

  • Create, update, and maintain IA artifacts required to obtain and sustain favorable Authority to Operate (ATO) decisions.
  • Apply the Risk Management Framework (RMF) to support system accreditation and continuous monitoring activities.
  • Upload and maintain IA documentation and artifacts within eMASS.
  • Track, apply, test, and report STIG compliance using STIG checklists and Security Content Automation Protocol (SCAP) tools.
  • Document system management procedures, operating procedures, security concerns, and proposed solutions.
  • Support security readiness reviews and preparation of security checklists.
  • Provide software support for patching and compliance scanning activities.
  • Maintain software baselines to ensure IA compliance and perform monthly regressive compliance scanning, including ACAS scans and SCAP reporting.
  • Maintain records of applied patches and update associated documentation with software version information.
  • Anticipate and mitigate potential security risks affecting the software baseline.
  • Monitor and analyze systems and networks to assess risk and recommend policy improvements.
  • Coordinate hardware, software, and firmware changes with the ISSM and verify appropriate installation of security patches.
  • Document security concerns and remediation activities through whitepapers and Plans of Action & Milestones (POA&M).
  • Assist with Annual Security Reviews (ASRs) and Verification & Validation (V&V) activities.
  • Develop detailed test procedures and security configuration documentation in support of security test events.
  • Evaluate security controls, assess their impact on systems, and develop mitigation strategies where necessary.

See also

要針對這個職缺調整履歷嗎?

目前無法檢查您與這個職缺的符合程度;請先將履歷加入個人檔案,下次即可查看。

A new version of freehire is available