Arlo Solutions logo
Arlo Solutions

Arlo Solutions is an information technology (IT) and services company on a mission to deliver management consulting and cybersecurity-related services primarily

Mid Information Systems Security Officer

Location

United States

Posted

6 days ago

Salary

Not specified

Seniority

Mid Level

Bachelor Degree2 yrs expEnglishCyber Security

Job Description

• Produce all required DOD compliance documentation for RMF, Audit Response and Remediation, Cyber Task Orders, Required Scorecards, Privacy documentation, and other compliance requirements as detailed in the DSCA CYBR Service Catalog. • Draft and coordinate cybersecurity-related documentation to meet required standards, controls, and metrics. • Support all steps of the RMF process (Steps 0-6) required to gain and maintain DOD Information Network (DODIN) and agency commercial network authority to operate. • Assist in categorization, control selection, implementation, and tailoring support, as well as support of assessments from the ISSO role. • Prepare and validate controls in eMASS packages for assessment and review. • Ensure that control requirements are well-defined and that necessary documentation and evidence are gathered for validation and assessment. • Work in the DOD GRC tool Enterprise Mission Assurance Support Service (eMASS) to support control validation. • Conduct continuous monitoring of information systems to detect vulnerabilities, threats, and security incidents. • Utilize security tools and technologies to perform regular scans, assessments, and analysis of system vulnerabilities. • Maintain and update continuous monitoring processes and procedures to ensure they are effective and aligned with organizational requirements. • Assist in the configuration and maintenance of security tools and technologies provided by the CSSP. • Assist in the detection, analysis, and response to cybersecurity incidents. • Participate in incident response activities, including triage, containment, eradication, and recovery. • Document and report on incident response activities, providing detailed analysis and recommendations for improvement. • Provide support to the Watch Officer in monitoring and managing cybersecurity events and incidents. • Maintain situational awareness of the organization's security posture and emerging threats. • Assist with the performance of daily and ad hoc/on-demand vulnerability scans, monthly audit scans, and monthly discovery scans. • Provide weekly vulnerability compliance reporting to ISSMs. • Review and adjust assets, subnets, credentials, and policies to properly manage C5ISR provided Assured Compliance Assessment Solution (ACAS) solutions. • Track and ensure configuration compliance of Enterprise Security Services (ESS) Suite with RMF, ATO, and Inspection requirements. • Assist with the maintenance of completed security waiver forms in coordination with EADSD and ISSM (PMO). • Work with TSD to implement effective scanning, COAMS System Registration, and Continuous Monitoring Scoring (CMRS) Tagging. • Maintain and update Ports, Protocols, and Services Management (PPSM) records, including emergency and exception requests. • Support the maintenance and accuracy of DoD Allow List entries. • Maintain accurate and up-to-date documentation of all RMF, IT, and FISCAM controls validation activities. • Prepare and submit regular reports on the status of security controls, RMF activities, and DevSecOps pipeline security. • Provide detailed documentation and evidence to support security assessments and audits. • Support the maintenance and configuration needed to maintain accurate ingestion of logs from all assets. • Provide summaries of events/incidents, including time of event/incident, anomalous activity identified, asset names and IPs, affected users, and POC for outreach/additional actions. • Complete Cybersecurity Incident Reporting Forms and assist with the detection and analysis of cybersecurity events and incidents. • Support accurate IR POC list, accurate hardware/software and IP inventory, and accurate summary of event/incident. • Document efforts involved in mitigating cybersecurity-related events/incidents that occur within the enterprise. • Support the generation of performance monitoring reports to monitor asset availability. • Support the generation of system health and security posture reports for system owners and ISSMs. • Support accurate hardware and software inventory, accurate ingestion of logs from all assets, and accurate system performance and security posture baselines. • Conduct specified areas of focus/detail for trend analysis. • Support migration information provided by affected system ISSM and report vulnerabilities to appropriate system ISSMs/POCs. • Assist with the reporting to outside agencies, including JFHQ, battle stations, external leadership, and other DOD Agencies. • Support the correlated agency-level POA&Ms with the coordination of POA&Ms from DSCA to outside entities. • Help complete the Cybersecurity Incident Reporting Form, including additional inputs such as personnel logs, system logs, event logs, and accurate software and hardware inventory list.

Job Requirements

  • Must be a US Citizen
  • Active Secret Clearance
  • Bachelor’s degree in computer science, Information Technology, Cybersecurity, or a related field is required OR additional four (4) years of experience
  • Strong understanding of Risk Management Framework (RMF) processes and security control assessments, including experience with categorization, control selection, implementation, and assessment.
  • Minimum of two (2) years of relevant experience in cybersecurity, information assurance, or a related field.
  • Experience in IT controls validation and familiarity with Federal Information System Controls Audit Manual (FISCAM) guidelines.
  • Experience in incident response, continuous monitoring, and vulnerability management.
  • Proficiency in using security assessment tools and platforms such as eMASS (Enterprise Mission Assurance Support Service).
  • Familiarity with continuous monitoring processes and tools.
  • Experience with incident response processes and tools.
  • Knowledge of cybersecurity frameworks and standards, such as NIST, ISO 27001, and CIS Controls.

Benefits

  • Active Secret Clearance

Related Categories

Related Job Pages

More Security Engineer Jobs

Lumen Technologies logo

Sr Engineer - PUB SEC

Lumen Technologies

Lumen connects the world. We are igniting business growth by connecting people, data and applications – quickly, securely, and effortlessly. Together, we are building a culture and company from the people up – committed to teamwork, trust and transparency. People power progress. We’re looking for top-tier talent and offer the flexibility you need to thrive and deliver lasting impact. Join us as we digitally connect the world and shape the future. Background Screening If you are selected for a position, there will be a background screen, which may include checks for criminal records and/or motor vehicle reports and/or drug screening, depending on the position requirements. Equal Employment Opportunities We are committed to providing equal employment opportunities to all persons regardless of race, color, ancestry, citizenship, national origin, religion, veteran status, disability, genetic characteristic or information, age, gender, sexual orientation, gender identity, gender expression, marital status, family status, pregnancy, or other legally protected status (collectively, “protected statuses”). We do not tolerate unlawful discrimination in any employment decisions, including recruiting, hiring, compensation, promotion, benefits, discipline, termination, job assignments or training. Disclaimer The job responsibilities described above indicate the general nature and level of work performed by employees within this classification. It is not intended to include a comprehensive inventory of all duties and responsibilities for this job. Job duties and responsibilities are subject to change based on evolving business needs and conditions.

OtherRemoteTeam 10,001

The Senior Engineer will lead and participate in system integration efforts across design, analysis, review, testing, implementation, and validation for managed security services platforms supporting government and critical infrastructure protection missions. Key duties include recommending optimized solutions, creating compliance reports, participating in operational projects, providing automation recommendations, and managing OS patch deployment.

United States
$83.0K - $121K / year
OtherRemoteTeam 201-500Since 2017

Cybersecurity Subject Matter Expert ensuring compliance and security for DTMO systems

United States
$135K - $163K / year
Sellers Dorsey logo

Development Security Operations Engineer (Healthcare Consulting)

Sellers Dorsey

Sellers Dorsey is an Equal Employment/Affirmative Action employer. We do not discriminate in hiring on the basis of sex, gender identity, sexual orientation, race, color, religious creed, national origin, physical or mental disability, protected Veteran status, or any other characteristic protected by federal, state, or local law. If you need a reasonable accommodation for any part of the employment process, please contact us by email at HumanResources@sellersdorsey.com and let us know the nature of your request and your contact information. Sellers Dorsey maintains a Drug-Free workplace.

OtherRemoteTeam 201-500

The Development Security Operations Engineer will bridge software development and security engineering by designing, building, and maintaining automated systems focused on CI/CD practices, streamlining the software release lifecycle, and ensuring efficient infrastructure development and system performance. Key duties involve implementing application security vulnerability practices, deploying security tools like CNAPP/CSPM, administering GitHub Enterprise, and actively participating in security reviews.

United States
$105K - $140K / year
Coinbase logo

Data Protection Engineer

Coinbase

We're building an open financial system for the world.

OtherRemoteTeam 1,001-5,000Since 2012H1B Sponsor

The engineer will support and expand data loss prevention capabilities to protect the Coinbase ecosystem from security incidents and execute the long-term strategy for the data prevention program. This includes implementing and deploying Data Protection tools, leveraging LLMs and agentic AI for operational efficiency, and collaborating across teams to ensure timely remediation and compliance.

United States
$144K - $170K / year