Five (5) to ten (10) years of IA experience is required; three (3) of which must be FISMA-related
Bachelor's Degree in related IT Field or Bachelor's Degree may be substituted with four (4) additional years of FISMA- related experience, for a total of 9 to 14 years of experience
One of the following:
Certified Information Systems Security Professional (CISSP)
CompTIA Advanced Security Practitioner (CASP)
Certified Information Systems Auditor (CISA)
Certified Ethical Hacker (CEH)
Certified Information Security Manager (CISM)
Ability to hold and maintain DHS Public Trust
Specialized knowledge of financial audit standards, classified system IA requirements and Privacy Act requirements
Specialized knowledge and experience with the implementation of the NIST Special Publication (SP) 800 family of publications (800-53 rev 4/5), particularly those associated with the Risk Management Framework (RMF)
Knowledge and experience with vulnerability scanning execution, assessment, and analysis
Knowledge and experience with the operating system and network (i.e., Local Area Networks [LAN] and Wide Area Networks [WAN])
Knowledge and experience with information security and assurance principles (e.g., Defense-in-depth) and associated supporting technologies
Knowledge and experience with application security, database security, and network security
Experience with evaluating system, network, or infrastructure security controls against requirements such as FISMA, FIPS, and NIST guidelines
Ability to assess and weigh current and evolving security threats in an operational environment
Preferred Skills
Current experience providing ISSO support to DHS
Experience supporting systems hosted in Cloud environments
Experience supporting systems in Agile and DevSecOps environments