IS Security Officer 2

Posted Yesterday
Be an Early Applicant
Cambridge, MA, USA
In-Office
82K-220K Annually
Mid level
Aerospace • Information Technology • Software • Biotech • Cybersecurity • Quantum Computing • Defense
Our Mission: Ensure our nations security and prosperity by delivering transformative solutions.
The Role
Supports continuous monitoring and authorization of multiple classified information systems. Responsibilities include maintaining security authorization documentation, managing configuration baselines and system changes, conducting audits and continuous monitoring, handling incidents, assessing vulnerabilities with STIG, SCAP, and Nessus, enforcing access requirements, supporting recovery processes, and coordinating with ISSMs and authorization officials. The role also mentors junior ISSOs and may assume ISSM responsibilities when needed.
Summary Generated by Built In

Overview:

Draper is an independent, nonprofit research and development company headquartered in Cambridge, MA. The 2,000+ employees of Draper tackle important national challenges with a promise of delivering successful and usable solutions. From military defense and space exploration to biomedical engineering, lives often depend on the solutions we provide. Our multidisciplinary teams of engineers and scientists work in a collaborative environment that inspires the cross-fertilization of ideas necessary for true innovation. For more information about Draper, visit www.draper.com.

Job Description Summary:

The Information System Security Officer 2 (ISSO) supports the continuous monitoring and authorization efforts of multiple classified information systems under the direction of the Information System Security Manager (ISSM). Performing a variety of technical, and non-technical Cyber Security functions. Responsibilities also include physical and environmental protection, personnel security, incident handling, and security training and awareness. In close coordination with the ISSM and ISO, the ISSO plays an active role in monitoring a system and its environment of operation to include developing and updating the SSP, managing and controlling changes to the system, and assessing the security impact of those changes.

Job Description:

Duties/Responsibilities
• Assist the ISSM in meeting their duties and responsibilities. The ISSO shall assume ISSM responsibilities in the absence of the ISSM.
• Ensure systems are operated, maintained, and disposed of in accordance with security policies and procedures as outlined in the security authorization package.
• Attend required technical and security training (e.g., operating system, networking, security management) relative to assigned duties.
• Ensure all users have the requisite security clearances, authorization, need-to-know, and are aware of their security responsibilities before granting access to the IS.
• Conduct periodic reviews of information systems to ensure compliance with the security authorization package.
• Coordinate any changes or modifications to hardware, software, or firmware of a system with the ISSM and AO/DAO prior to the change.
• Formally notify the ISSM and AO/DAO when changes occur that might affect system authorization.
• Monitor system recovery processes to ensure security features and procedures are properly restored and functioning correctly.
• Ensure all IS security-related documentation is current and accessible to properly authorized individuals.
• Conduct Audits and Continuous Monitoring (ConMon) activities using available technical and non-technical processes, reports Audit and ConMon findings, Execute incident response and attends and contributes to status meetings.
• Manage configuration baselines of both hardware and software
• Identify system architecture flaws using industry standard tools (e.g. STIG, SCAP, Nessus) that will be flowed to the ISSM for review.
• Mentors and coaches ISSO 1.
• Performs other duties as assigned.
Skills/Abilities
• Fundamental understanding of common auditing techniques
• Understanding of RMF (NIST SP 800-53, JSIG, DAAG, ICD 503), IR, Vulnerability Management, SCAP, STIG, and Security-Relevant Tools.
• Understands Information Technology basics.
• Awareness of network type designations (e.g. WAN, LAN) and associated infrastructure (e.g. Servers, switches, firewalls).
Education
• Requires a bachelor's degree in Information Technology or a related field.
• Equivalent industry experience may be substituted.
• Possesses an IAM I/IAT II Certification, or greater.
Experience:  
• 3-5 years year relevant industry experience is required,
• Preferred experience with auditing systems using native language (PS/BASH), with tools and basic scripts / queries, and experience working with ISSMs to create and manage POA&Ms.

Additional Job Description:

Applicants selected for this position will be required to obtain and maintain a government security clearance.

Current in scope Top Secret security clearance required.

Connect With Draper for Future Opportunities! If you don't find the right posting in our Career Opportunities, you may submit your resume for future consideration.

Job Location - City:

Cambridge

Job Location - State:

Massachusetts

Job Location - Postal Code:

02139-3563

The US base salary range for this full-time position is

$82,300.00 - $220,000.00

Our salary ranges are determined by role, level, and location. The range displayed on each job posting reflects the minimum and maximum target salaries for the position across all US locations. Within the range, individual pay is determined by work location and additional factors, including job-related skills, experience, and relevant education or training. Union ranges will be in compliance with the collective bargaining agreement's approved rates by location and role. Your recruiter can share more about the specific salary range for your preferred location during the hiring process.  Please note that the compensation details listed in US role postings reflect the base salary only, and does not include bonuses or benefits.

Our work is very important to us, but so is our life outside of work. Draper supports many programs to improve work-life balance including workplace flexibility, employee clubs ranging from photography to yoga, health and finance workshops, off site social events and discounts to local museums and cultural activities. If this specific job opportunity and the chance to work at a nationally renowned R&D innovation company appeals to you, apply now www.draper.com/careers.

Draper is committed to creating an inclusive environment. We understand the value of inclusivity and its impact on a high-performance culture. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, disability, age, sexual orientation, national origin, veteran status, or genetic information. Draper is committed to providing access, equal opportunity, and reasonable accommodation for individuals with disabilities in employment, its services, programs, and activities. To request reasonable accommodation, please contact [email protected].

Skills Required

  • Bachelor's degree in Information Technology or a related field
  • Equivalent industry experience may substitute for the bachelor's degree
  • IAM I or IAT II certification, or greater
  • 3-5 years of relevant industry experience
  • Current in-scope Top Secret security clearance
  • Fundamental understanding of common auditing techniques
  • Understanding of RMF, NIST SP 800-53, JSIG, DAAG, ICD 503, incident response, vulnerability management, SCAP, STIG, and security-relevant tools
  • Understanding of information technology fundamentals
  • Awareness of WAN and LAN network designations and related infrastructure, including servers, switches, and firewalls
  • Experience auditing systems using PowerShell or Bash, using tools and basic scripts or queries
  • Experience working with ISSMs to create and manage POA&Ms
Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
HQ: Cambridge, MA
5,000 Employees
Year Founded: 1933

What We Do

We Engineer Solutions for the Nation’s Toughest Problems As an independent nonprofit engineering innovation company, Draper provides engineering services directly to government, industry, and academia. We work on teams as prime contractors or subcontractors and participate as collaborators in consortia. Our strong commitment to delivering working solutions allows us to apply ourselves to a variety of domains from space to undersea — and many areas in between.

Why Work With Us

At Draper, our diverse teams are comprised of engineers, scientists, program managers, and administrative professionals who are dedicated to pioneering solutions that push boundaries.

Gallery

Gallery

Similar Jobs

Klaviyo Logo Klaviyo

Order to Cash Track Lead, Finance Engineering

Consumer Web • eCommerce • Marketing Tech • Retail • Software • Analytics • Generative AI
Easy Apply
Hybrid
Boston, MA, USA
2400 Employees
140K-210K Annually

Imprivata Logo Imprivata

Product Designer

Healthtech • Information Technology • Security • Software • Cybersecurity
Remote or Hybrid
United States
1372 Employees
126K-136K Annually

Sprout Social Logo Sprout Social

Consultant

Marketing Tech • Social Media • Software • Analytics • Business Intelligence
Easy Apply
Remote or Hybrid
US
1400 Employees
68K-112K Annually

Nasuni Logo Nasuni

Solutions Engineer

Artificial Intelligence • Big Data • Cloud • Security • Software • Cybersecurity • Infrastructure as a Service (IaaS)
Easy Apply
Remote or Hybrid
United States
550 Employees

Similar Companies Hiring

Outpost Space Thumbnail
Aerospace • Defense
US
24 Employees
Kepler  Thumbnail
Fintech • Software
New York, New York
6 Employees
Onshore Thumbnail
Artificial Intelligence • Fintech • Software • Financial Services
New York, New York
60 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account