Loading jobs…
Loading jobs…
Berkadia Commercial Mortgage, LLC — Washington, District of Columbia
Company Summary Arlo Solutions (Arlo) is an information technology consulting services company that specializes in delivering technology solutions. Our reputation reflects the high quality of the talented Arlo Solutions team and the consultants working in partnership with our customers. Our mission is to understand and meet the needs of both our customers and consultants by delivering quality, value-added solutions.
Our solutions are designed and managed to not only reduce costs, but to improve business processes, accelerate response time, improve services to end-users, and give our customers a competitive edge, now and into the future. Position Description: The Mid Information System Security Officer (ISSO) (IAM 2) will support the Defense Security Cooperation Agency (DSCA) Cybersecurity (CYBR) team by providing expertise in Risk Management Framework (RMF) activities, security control assessments, controls validation, and continuous monitoring.
Responsibilities
detailed in the DSCA CYBR Service Catalog. C. S.
and/or Success Factors: Produce all required DOD compliance documentation for RMF, Audit Response and Remediation, Cyber Task Orders, Required Scorecards, Privacy documentation, and other compliance
Requirements
as detailed in the DSCA CYBR Service Catalog. Draft and coordinate cybersecurity-related documentation to meet required standards, controls, and metrics. Support all steps of the RMF process (Steps 0-6) required to gain and maintain DOD Information Network (DODIN) and agency commercial network authority to operate.
Assist in categorization, control selection, implementation, and tailoring support, as well as support of assessments from the ISSO role. Prepare and validate controls in eMASS packages for assessment and review.
are well-defined and that necessary documentation and evidence are gathered for validation and assessment. Work in the DOD GRC tool Enterprise Mission Assurance Support Service (eMASS) to support control validation. Conduct continuous monitoring of information systems to detect vulnerabilities, threats, and security incidents.
Utilize security tools and technologies to perform regular scans, assessments, and analysis of system vulnerabilities.
Assist in the configuration and maintenance of security tools and technologies provided by the CSSP. Assist in the detection, analysis, and response to cybersecurity incidents. Participate in incident response activities, including triage, containment, eradication, and recovery.
Document and report on incident response activities, providing detailed analysis and recommendations for improvement. Provide support to the Watch Officer in monitoring and managing cybersecurity events and incidents. Maintain situational awareness of the organization's security posture and emerging threats.
Assist with the performance of daily and ad hoc/on-demand vulnerability scans, monthly audit scans, and monthly discovery scans. Provide weekly vulnerability compliance reporting to ISSMs. Review and adjust assets, subnets, credentials, and policies to properly manage C5ISR provided Assured Compliance Assessment Solution (ACAS) solutions.
Assist with the maintenance of completed security waiver forms in coordination with EADSD and ISSM (PMO). Work with TSD to implement effective scanning, COAMS System Registration, and Continuous Monitoring Scoring (CMRS) Tagging.