SMC - Information System Security Officer

<strong>Position Summary<br><br></strong><strong> JOB DESCRIPTION <br><br></strong>Ensure the appropriate operational security posture for the Specific Manufacturing Capability (SMC) Information System (IS) is maintained to include ensuring implementation of DoW and SMC Site cybersecurity policies, practices, and procedures. Work with IS owners and the IS Information System Security Manager (ISSM) and serve as advisor on all matters, technical and otherwise, involving security of the IS.<br><br><strong>Essential Job Functions and Responsibilities: (Knowledge, skills, and behaviors required for this position.)<br><br></strong><ul><li> Conduct audits of SMC IS to ensure compliance with Joint Special Access Program (SAP) Implementation Guide (JSIG), DoW Cybersecurity Service Provider (CSSP) requirements. </li><li> Lead and direct the development of IS accreditation packages (i.e., system security plan, security control assessment, risk assessment, etc.) in accordance with federal directives and the Risk Management Framework (RMF). </li><li> Report all security-related incidents to the ISSM. </li><li> Integrate applicable IS requirements, controls, and processes into design specifications in accordance with DoW established standards, policies, procedures, guidelines, directives, and regulations and laws (statutes). </li><li> Act as the subject matter expert (SME) in the security of basic network and telecommunications services/data (e.g., perimeter defense strategies, defense-in-depth strategies, and data encryption techniques). Understand the policies, procedures, and controls required to protect network and telecommunication services and assess technical, operational, and administrative security controls as mandated by RMF standards. </li><li> Coordinate any changes or modifications to hardware, software, or firmware of a system with the ISSM and AO/DAO prior to the change. </li><li> Ensure audit records are collected, reviewed, and documented (to include any anomalies). </li><li> Ensure all IS security-related documentation is current and accessible to properly authorized individuals. </li><li> Lead others in maintaining change control, ensuring configuration management of the IS to protect the system and data in accordance with technical, operational, and administrative security control requirements. </li><li> Perform a variety of data collection, analysis, reporting and briefing activities associated with security operations and maintenance to ensure that the organizational security policies are implemented and maintained on the IS. </li><li> Verify cybersecurity awareness training and requirements are current for IS users based on identified needs and organizational policies and within organizational time frames. Develop IS training material as needed to support end-user training requirements. </li><li> Coordinate with the appropriate management and security offices to ensure IS users have the required security clearances and need-to-know authorizations before accessing information systems. Collect and track required documentation for IS user accounts. </li><li> Identify, categorize, investigate, isolate, assess, and report IS cybersecurity incidents in coordination with other organizations. Coordinate with the appropriate security offices to ensure that physical controls are implemented as required. </li><li> Participate in the creation, review, and assessment of policies and procedures supporting the secure use and operation of SMC information systems that includes, but is not limited to, system security plans, vulnerability management, risk management, configuration management, change management, and others. </li><li> Promote awareness of cyber policy and strategy as appropriate among management and ensure sound principles are reflected in the organization's mission, vision, and goals. </li><li> Assist the ISSM in meeting their duties and responsibilities. The ISSO shall assume ISSM responsibilities in the absence of the ISSM. </li><li> Attend required technical and security training (e.g., operating system, networking, security management) relative to assigned duties </li><li> Maintain required IA certifications. </li><li> Other duties as assigned. <br><br></li></ul><strong>Required<br><br></strong><strong>Education, Credentials, and Work Experience: <br><br></strong><ul><li>Level 4 -Bachelor’s and 9 years of experience. Master’s and 6 years of experience. PhD and 4 years </li><li>of experience.</li><li> Relevant experience commensurate with level. </li><li> DoD 8570/8140 IAM Level II certification. IAM Level II certifications include CISSP, CAP, CISM, and GSLC. CISSP or CISM preferred .If candidate has relevant experience commensurate with level, IAM Level II may be obtained within 6 months of hire. </li><li> Working experience with NIST 800-53, CNSS 1253, FISMA, and/or JSIG Rev 4. </li><li> Strong analytical and problem-solving skills. </li><li> Must be a US Citizen and hold an active DOE “Q” clearance (or DOD/DOJ equivalent) </li><li> Strong analytical and problem-solving skills. <br><br></li></ul><strong>Physical Requirements<br><br></strong>While performing the duties of this classification, the employee is frequently required to stand, walk, sit, stoop, kneel, bend, use hands to handle materials, manipulate tools, keyboard and type, reach with hands and arms, and operate job-related equipment. The employee must occasionally lift and/or move up to 30 pounds. Sufficient visual acuity and hearing capacity to perform the essential functions and interact with people is required. Reasonable accommodations may be made to enable individuals with disabilities to perform the essential functions..<br><br><strong>Working Conditions<br><br></strong>The work environment is an office environment which may include stairs. The noise level is generally moderate; however, may be exposed to loud noises on occasion. Position requires working more than 8 hours/day, irregular hours, and working alone.<br><br><em>The above statements are intended to describe the general nature and levels of work being performed by people assigned to this classification. They are not intended to be construed as an exhaustive list of all responsibilities, duties and skills required of personnel so classified.<br><br></em><strong>Security And Privacy Language<br><br></strong><em> This position includes information security and privacy responsibilities as defined by NIST SP 800 53, OMB Circular A 130, and DOE Order 206.1A. Position must complete initial and annual role-specific training as required. The incumbent must sign and comply with all required access agreements prior to being granted access to organizational systems or data. Comply with all applicable information security and privacy policies and procedures by following established protocols, with an understanding that non-compliance may result in sanctions. <br><br></em><strong>About Us<br><br></strong><strong>Benefits and Relocation<br><br></strong><ul><li>Medical, Dental, Vision, and Flexible Spending Accounts</li><li>401(k) with a 4.2% employer contribution and up to 4.8% match (regular positions) or self-contribute access (postdoctoral positions)</li><li>Paid time off (personal leave)</li><li>Employee Education Program (tuition assistance for eligible positions)</li><li>Comprehensive Relocation Package</li><li>Benefit eligibility subject to multiple factors, including employment status and position classification.<br><br></li></ul><strong>At this time, BEA will not sponsor any H1-B visas obtained outside of the United States of America (U.S.A.), including consular visas.<br><br></strong>INL is a science-based, applied engineering national laboratory dedicated to supporting the U.S. Department of Energy's mission in nuclear energy research, science, and national defense. With more than 6,300 scientists, researchers, and support staff, the laboratory works with national and international governments, universities and industry partners to change the world's energy future and secure our nation's critical infrastructure.<br><br><strong>INL Mission<br><br></strong>Our mission is to discover, demonstrate and secure innovative nuclear energy solutions, other clean energy options and critical infrastructure.<br><br><strong>INL Vision<br><br></strong>Our vision is to change the world's energy future and secure our nation's critical infrastructure.<br><br><strong>Selective Service Requirements<br><br></strong>To be eligible for employment at INL males born after December 31, 1959 must have registered with the Selective Service System (SSS). For more information see .<br><br><strong>Equal Employment Opportunity<br><br></strong>Idaho National Laboratory (INL) is an Equal Employment Opportunity (EEO) employer. It is the policy of INL to provide equal employment opportunities to all qualified applicants without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, age, protected veteran or disabled status, or genetic information.<br><br><strong>Reasonable Accommodation<br><br></strong>We will ensure that individuals with disabilities are provided reasonable accommodation to participate in the job application or interview process, to perform essential job functions, and to receive other benefits and privileges of employment. Please contact us to request accommodation.<br><br><strong>Other Information<br><br></strong>When applying to positions please provide a resume and answer all questions on the following screens. Applicants, who fail to provide a resume or answer the questions, may be deemed ineligible for consideration.<br><br><em>INL does not accept resumes from third party vendors unsolicited.</em>

Back to blog

Other Jobs To Apply

Common Interview Questions And Answers

1. HOW DO YOU PLAN YOUR DAY?

This is what this question poses: When do you focus and start working seriously? What are the hours you work optimally? Are you a night owl? A morning bird? Remote teams can be made up of people working on different shifts and around the world, so you won't necessarily be stuck in the 9-5 schedule if it's not for you...

2. HOW DO YOU USE THE DIFFERENT COMMUNICATION TOOLS IN DIFFERENT SITUATIONS?

When you're working on a remote team, there's no way to chat in the hallway between meetings or catch up on the latest project during an office carpool. Therefore, virtual communication will be absolutely essential to get your work done...

3. WHAT IS "WORKING REMOTE" REALLY FOR YOU?

Many people want to work remotely because of the flexibility it allows. You can work anywhere and at any time of the day...

4. WHAT DO YOU NEED IN YOUR PHYSICAL WORKSPACE TO SUCCEED IN YOUR WORK?

With this question, companies are looking to see what equipment they may need to provide you with and to verify how aware you are of what remote working could mean for you physically and logistically...

5. HOW DO YOU PROCESS INFORMATION?

Several years ago, I was working in a team to plan a big event. My supervisor made us all work as a team before the big day. One of our activities has been to find out how each of us processes information...

6. HOW DO YOU MANAGE THE CALENDAR AND THE PROGRAM? WHICH APPLICATIONS / SYSTEM DO YOU USE?

Or you may receive even more specific questions, such as: What's on your calendar? Do you plan blocks of time to do certain types of work? Do you have an open calendar that everyone can see?...

7. HOW DO YOU ORGANIZE FILES, LINKS, AND TABS ON YOUR COMPUTER?

Just like your schedule, how you track files and other information is very important. After all, everything is digital!...

8. HOW TO PRIORITIZE WORK?

The day I watched Marie Forleo's film separating the important from the urgent, my life changed. Not all remote jobs start fast, but most of them are...

9. HOW DO YOU PREPARE FOR A MEETING AND PREPARE A MEETING? WHAT DO YOU SEE HAPPENING DURING THE MEETING?

Just as communication is essential when working remotely, so is organization. Because you won't have those opportunities in the elevator or a casual conversation in the lunchroom, you should take advantage of the little time you have in a video or phone conference...

10. HOW DO YOU USE TECHNOLOGY ON A DAILY BASIS, IN YOUR WORK AND FOR YOUR PLEASURE?

This is a great question because it shows your comfort level with technology, which is very important for a remote worker because you will be working with technology over time...