Qualifications
Master's Degree and 3 years of cybersecurity and FISMA experience; OR
Bachelor’s Degree in a non-IT field with a total of four (4) years of cybersecurity experience, including FISMA experience;
No degree with a total of 8 years of cybersecurity experience, including FISMA experience.
One of the following certifications (may be obtained within six (6) months of hire):
Certified Information System Security Professional (CISSP)
CompTIA Advanced Security Practitioner (CASP)
Certified Information Systems Auditor (CISA)
Certified Ethical Hacker (CEH)
Systems Security Certified Practitioner (SSCP)
Certified Information Security Manager (CISM)
Knowledge and experience with the implementation of the NIST Special Publication (SP) 800 family of publications (800-53 rev 4/5), particularly those associated with the Risk Management Framework (RMF)
Experience with evaluating system, network, or infrastructure security controls against requirements such as FISMA, FIPS, and NIST guidelines
Knowledge and experience with vulnerability scanning, assessment, and analysis
Knowledge and experience with operating system (Windows and/or Linux) and networking (i.e., Local Area Networks [LAN] and Wide Area Networks [WAN])
Knowledge and experience with information security and assurance principles (e.g., Defense-in-depth) and associated supporting technologies
Knowledge and experience with application security, database security, and operating system security
Ability to assess and weigh current and evolving security threats in an operational environment
Ability to apply basic knowledge of information assurance concepts, practices, and procedures
Ability to interview system stakeholders to properly document security controls
Participated in independent and self-assessments
Ability to perform ISSO duties to at least one system
Preferred Skills
Current experience providing ISSO support to DHS
Knowledge of DHS Information Security Policy Directives and Handbooks is preferred
Familiarity with Jira and Confluence