Information Systems Security Officer (ISSO) in Bedford
Information Systems Security Officer (ISSO)

Information Systems Security Officer (ISSO) in Bedford

Bedford Full-Time 91415 - 146264 £ / year (est.) No home office possible
Go Premium
I

At a Glance

  • Tasks: Ensure security for networks and systems while monitoring incidents and compliance.
  • Company: Join a leading organisation focused on information security and innovation.
  • Benefits: Competitive salary, professional development, and a supportive work environment.
  • Why this job: Make a real difference in cybersecurity and protect vital information.
  • Qualifications: Degree in Cyber Security or related field; experience in security roles preferred.
  • Other info: Exciting career growth opportunities in a dynamic and collaborative team.

The predicted salary is between 91415 - 146264 £ per year.

IDA has an excellent opportunity for an Information Systems Security Officer (ISSO). The ISSO works closely with the Information System Security Manager (ISSM) to support the daily operations of the information security program. In this role, you will ensure appropriate operational security posture is maintained for local area networks (LAN), wide area networks (WAN) and multi-user stand-alone systems. The ISSO monitors these systems and their operational environment and must have the technical knowledge and expertise required to manage the security aspects of these systems. The ISSO must understand requirements for physical and environmental protection of the computer systems, personnel security rules that pertain to systems, incident handling (such as classified spills or malware), and security training and awareness. The ISSO plays an active role in monitoring a system and its environment of operation to include developing and updating the system security plan (SSP), managing and controlling changes to the system, and assessing the security impact of those changes.

Responsibilities

  • Serves as the Information Systems Security Officer (ISSO) under the Information Systems Security Manager (ISSM) for IDA classified and unclassified systems.
  • Manages and coordinates information security monitoring, inspections and incident response.
  • Manages a formal information security / information systems security program with assistance from the ISSM.
  • Reviews and maintains information systems security plans (SSPs) and Assessment and Authorization (A&A) in accordance with DoW mandated policies.
  • Performs audit reviews of systems comprised of multiple operating systems using security information and event management (SIEM) products to track multiple events including any signs of inappropriate or unusual activity, intrusion events, data transfers, etc. Reports any findings to the ISSM.
  • Performs recurring self-assessments on all systems under their purview to ensure compliance with documented security requirements and to detect any system level vulnerabilities.
  • Prepares a detailed report of the findings and ensures proper protection and/or corrective measures are taken immediately, or develops a Plan of Action and Milestones (POA&M) to document planned actions.
  • Supports the ISSM during on-site assessments of US Government Security Control Assessors (SCAs) to demonstrate compliance with technical configuration requirements and implementation and enforcement of written security policy.
  • Continuously updates all required system documentation, including the SSP, POA&M, Risk Assessment Report, and system component inventories.
  • Develops procedures for responding to security incidents and investigating and reporting security violations and incidents as appropriate.
  • Develops, implements and enforces information security policies and procedures.
  • Assists ISSM to perform the steps involved in the execution of the Risk Management Framework (RMF), including generation of documentation, controls compliance testing, and continuous monitoring activities for systems.
  • Develops and periodically reviews training materials and standard operating procedures covering all technical and administrative aspects of system operations.
  • Works with IT to perform an initial system assessment to ensure that required security controls are implemented and operating correctly before a system is authorized for production.
  • Works with IT to develop automated processes to assist in maintaining system compliance and documentation updates.
  • Collaborates with IT to oversee an effective change management policy and procedures for authorizing use of hardware/software on an information system.
  • Evaluates proposed changes against Government security requirements and recommends approval or denial based on a security impact analysis.
  • Reviews and ensures implementation of bulletins and advisories that impact the security posture of information systems covered by SSPs.
  • Reviews systems for compliance to Government requirements, and provides recommendations for improvements.
  • Develops an information systems security, education, training, and awareness program.
  • Clearly communicates to all users including security personnel, IT staff, and managers the proper procedures for protecting classified information and the systems that process that information. Training prior to initial system access and periodically after includes proper system usage, physical security, data transfers, media protection etc.
  • Performs other duties as assigned.

Qualifications

  • Bachelor’s degree in Information Assurance/Cyber Security or similar relevant field or equivalent experience.
  • Minimum three years’ experience in a similar systems security manager or officer role.
  • Must have the following Information Assurance certifications or security training or obtain the certificates within 6 months of hire: DSS NISPOM Risk Management Framework Courses, DOD -M certification at IAT level 2, such as Security +, Certified Authorization Professional (CAP) through (ISC)2. Higher-level certifications such as CISM or CISSP strongly desired.
  • Must understand the technical configurations of Windows or Linux Operating Systems (as appropriate to location) in physical and virtual environments; both preferred.
  • Knowledge of NIST security publications is highly preferred.
  • Must have the ability to read and understand event logs from Windows and/or Linux.
  • Knowledge of tools to parse logs, scan operating systems for vulnerabilities and compliance checking preferred, and required within 6 months of hire.
  • Customer service skills, including good interpersonal skills and the ability to communicate effectively with all levels of employees.
  • Candidate must possess a Top Secret clearance with SCI eligibility is preferred.
  • Successful completion of a criminal background check is required.

We support transparency, equity, and fairness in our compensation program and provide a reasonable estimate of the salary range based on data-driven market analysis for each position. While it is not typical for an individual to be hired at or near the top of the range, a reasonable estimate of the salary range for this role is $91,415 - $146,264. Individual salary within this range will be commensurate with the incumbent’s experience, unique skills and qualifications, and other relevant factors.

Information Systems Security Officer (ISSO) in Bedford employer: Institute for Defense Analyses

At IDA, we pride ourselves on being an exceptional employer that fosters a collaborative and innovative work culture. As an Information Systems Security Officer, you will benefit from comprehensive training opportunities, a commitment to professional growth, and a supportive environment that values transparency and equity in compensation. Located in a dynamic area, our team is dedicated to maintaining the highest standards of information security while ensuring a rewarding and meaningful career path for all employees.
I

Contact Detail:

Institute for Defense Analyses Recruiting Team

StudySmarter Expert Advice 🤫

We think this is how you could land Information Systems Security Officer (ISSO) in Bedford

✨Tip Number 1

Network like a pro! Attend industry events, webinars, and meetups to connect with professionals in the information security field. Don't be shy—introduce yourself and share your passion for security; you never know who might have a lead on your dream job!

✨Tip Number 2

Get your online presence sorted! Update your LinkedIn profile to reflect your skills and experiences relevant to the ISSO role. Join groups related to information security and engage in discussions to showcase your expertise and enthusiasm.

✨Tip Number 3

Prepare for interviews by brushing up on common security scenarios and incident response strategies. Practice articulating your experience with security plans and compliance testing, as these are key topics for an ISSO position. We recommend doing mock interviews with friends or mentors!

✨Tip Number 4

Apply through our website! It’s the best way to ensure your application gets noticed. Tailor your application to highlight your relevant experience in managing security programs and understanding technical configurations, so we can see how you fit into our team!

We think you need these skills to ace Information Systems Security Officer (ISSO) in Bedford

Information Assurance
Cyber Security
Incident Handling
Security Information and Event Management (SIEM)
Risk Management Framework (RMF)
System Security Plans (SSP)
Assessment and Authorization (A&A)
Vulnerability Assessment
Change Management
NIST Security Publications
Windows Operating Systems
Linux Operating Systems
Communication Skills
Interpersonal Skills
Top Secret Clearance

Some tips for your application 🫡

Tailor Your CV: Make sure your CV is tailored to the Information Systems Security Officer role. Highlight your relevant experience, especially in managing security programs and incident response. We want to see how your skills align with what we're looking for!

Craft a Compelling Cover Letter: Your cover letter is your chance to shine! Use it to explain why you're passionate about information security and how your background makes you a great fit for the ISSO position. Don’t forget to mention any specific projects or achievements that relate to the job.

Show Off Your Certifications: If you've got any relevant certifications like Security+ or CAP, make sure they’re front and centre in your application. We love seeing candidates who are committed to their professional development and understand the importance of staying current in the field.

Apply Through Our Website: We encourage you to apply directly through our website. It’s the best way to ensure your application gets into the right hands. Plus, it shows us you’re serious about joining our team at StudySmarter!

How to prepare for a job interview at Institute for Defense Analyses

✨Know Your Stuff

Make sure you brush up on your knowledge of information security principles, especially those related to the Risk Management Framework (RMF) and NIST publications. Be ready to discuss your experience with Windows and Linux operating systems, as well as any tools you've used for log parsing and vulnerability scanning.

✨Showcase Your Experience

Prepare specific examples from your past roles that demonstrate your ability to manage security incidents, conduct audits, and develop security plans. Highlight any experience you have with incident handling or compliance assessments, as these are crucial for the ISSO role.

✨Communicate Clearly

Since you'll be working with various teams, practice explaining complex security concepts in simple terms. Be prepared to discuss how you would train staff on security policies and procedures, ensuring everyone understands their role in maintaining security.

✨Ask Insightful Questions

At the end of the interview, don’t hesitate to ask questions about the company's security culture, ongoing projects, or challenges they face. This shows your genuine interest in the role and helps you gauge if it's the right fit for you.

Information Systems Security Officer (ISSO) in Bedford
Institute for Defense Analyses
Location: Bedford
Go Premium

Land your dream job quicker with Premium

You’re marked as a top applicant with our partner companies
Individual CV and cover letter feedback including tailoring to specific job roles
Be among the first applications for new jobs with our AI application
1:1 support and career advice from our career coaches
Go Premium

Money-back if you don't land a job in 6-months

>