HimalayasHimalayas logo
Arlo SolutionsAS

(655) Mid Information Systems Security Officer

Arlo Solutions is a Washington, DC-based professional services firm offering cybersecurity, program management, and strategic communications solutions, primarily to U.S. government agencies in the defense, intelligence, and civil markets.

Arlo Solutions

Employee count: 51-200

United States only

Stay safe on Himalayas

Never send money to companies. Jobs on Himalayas will never require payment from applicants.

Company Summary

Arlo Solutions (Arlo) is an information technology consulting services company that specializes in delivering technology solutions. Our reputation reflects the high quality of the talented Arlo Solutions team and the consultants working in partnership with our customers. Our mission is to understand and meet the needs of both our customers and consultants by delivering quality, value-added solutions. Our solutions are designed and managed to not only reduce costs, but to improve business processes, accelerate response time, improve services to end-users, and give our customers a competitive edge, now and into the future.

Position Overview

The Mid Information System Security Officer (ISSO) (IAM 2) will support the Defense Security Cooperation Agency (DSCA) Cybersecurity (CYBR) team by providing expertise in Risk Management Framework (RMF) activities, security control assessments, controls validation, and continuous monitoring. The role involves ensuring compliance with RMF, IT, and Federal Information System Controls Audit Manual (FISCAM) guidelines, and supporting the cybersecurity responsibilities detailed in the DSCA CYBR Service Catalog.

Work Location: Fully Remote

Clearance:
Active Secret Clearance

Job Responsibilities and/or Success Factors

  • Produce all required DOD compliance documentation for RMF, Audit Response and Remediation, Cyber Task Orders, Required Scorecards, Privacy documentation, and other compliance requirements as detailed in the DSCA CYBR Service Catalog.
  • Draft and coordinate cybersecurity-related documentation to meet required standards, controls, and metrics.
  • Support all steps of the RMF process (Steps 0-6) required to gain and maintain DOD Information Network (DODIN) and agency commercial network authority to operate.
  • Assist in categorization, control selection, implementation, and tailoring support, as well as support of assessments from the ISSO role.
  • Prepare and validate controls in eMASS packages for assessment and review.
  • Ensure that control requirements are well-defined and that necessary documentation and evidence are gathered for validation and assessment.
  • Work in the DOD GRC tool Enterprise Mission Assurance Support Service (eMASS) to support control validation.
  • Conduct continuous monitoring of information systems to detect vulnerabilities, threats, and security incidents.
  • Utilize security tools and technologies to perform regular scans, assessments, and analysis of system vulnerabilities.
  • Maintain and update continuous monitoring processes and procedures to ensure they are effective and aligned with organizational requirements.
  • Assist in the configuration and maintenance of security tools and technologies provided by the CSSP.
  • Assist in the detection, analysis, and response to cybersecurity incidents.
  • Participate in incident response activities, including triage, containment, eradication, and recovery.
  • Document and report on incident response activities, providing detailed analysis and recommendations for improvement.
  • Provide support to the Watch Officer in monitoring and managing cybersecurity events and incidents.
  • Maintain situational awareness of the organization's security posture and emerging threats.
  • Assist with the performance of daily and ad hoc/on-demand vulnerability scans, monthly audit scans, and monthly discovery scans.
  • Provide weekly vulnerability compliance reporting to ISSMs.
  • Review and adjust assets, subnets, credentials, and policies to properly manage C5ISR provided Assured Compliance Assessment Solution (ACAS) solutions.
  • Track and ensure configuration compliance of Enterprise Security Services (ESS) Suite with RMF, ATO, and Inspection requirements.
  • Assist with the maintenance of completed security waiver forms in coordination with EADSD and ISSM (PMO).
  • Work with TSD to implement effective scanning, COAMS System Registration, and Continuous Monitoring Scoring (CMRS) Tagging.
  • Maintain and update Ports, Protocols, and Services Management (PPSM) records, including emergency and exception requests.
  • Support the maintenance and accuracy of DoD Allow List entries.
  • Maintain accurate and up-to-date documentation of all RMF, IT, and FISCAM controls validation activities.
  • Prepare and submit regular reports on the status of security controls, RMF activities, and DevSecOps pipeline security.
  • Provide detailed documentation and evidence to support security assessments and audits.
  • Support the maintenance and configuration needed to maintain accurate ingestion of logs from all assets.
  • Provide summaries of events/incidents, including time of event/incident, anomalous activity identified, asset names and IPs, affected users, and POC for outreach/additional actions.
  • Complete Cybersecurity Incident Reporting Forms and assist with the detection and analysis of cybersecurity events and incidents.
  • Support accurate IR POC list, accurate hardware/software and IP inventory, and accurate summary of event/incident.
  • Document efforts involved in mitigating cybersecurity-related events/incidents that occur within the enterprise.
  • Support the generation of performance monitoring reports to monitor asset availability.
  • Support the generation of system health and security posture reports for system owners and ISSMs.
  • Support accurate hardware and software inventory, accurate ingestion of logs from all assets, and accurate system performance and security posture baselines.
  • Conduct specified areas of focus/detail for trend analysis.
  • Support migration information provided by affected system ISSM and report vulnerabilities to appropriate system ISSMs/POCs.
  • Assist with the reporting to outside agencies, including JFHQ, battle stations, external leadership, and other DOD Agencies.
  • Support the correlated agency-level POA&Ms with the coordination of POA&Ms from DSCA to outside entities.
  • Help complete the Cybersecurity Incident Reporting Form, including additional inputs such as personnel logs, system logs, event logs, and accurate software and hardware inventory list.

Education and Minimum Qualifications

  • Must be a US Citizen
  • Active Secret Clearance
  • Bachelor’s degree in computer science, Information Technology, Cybersecurity, or a related field is required OR additional four (4) years of experience
  • Strong understanding of Risk Management Framework (RMF) processes and security control assessments, including experience with categorization, control selection, implementation, and assessment.
  • Minimum of two (2) years of relevant experience in cybersecurity, information assurance, or a related field.
  • Experience in IT controls validation and familiarity with Federal Information System Controls Audit Manual (FISCAM) guidelines.
  • Experience in incident response, continuous monitoring, and vulnerability management.
  • Proficiency in using security assessment tools and platforms such as eMASS (Enterprise Mission Assurance Support Service).
  • Familiarity with continuous monitoring processes and tools.
  • Experience with incident response processes and tools.
  • Knowledge of cybersecurity frameworks and standards, such as NIST, ISO 27001, and CIS Controls.


Desired Qualifications
:

  • Certifications such as CSSP, CISM, CISA, CAP, Security+, or equivalent is highly desirable.
  • Experience with OKTA
  • Experience as an ISSO or otherwise prior experience with IT Risk Management Framework Support.

AAP Statement

We are proud to be an Affirmative Action and Equal Opportunity Employer and as such, we evaluate qualified candidates in full consideration without regard to race, color, religion, sex, sexual orientation, gender identity, marital status, national origin, age, disability status, protected veteran status, and any other protected status.

About the job

Apply before

Posted on

Job type

Full Time

Experience level

Education

Bachelor degree

Experience

2 years minimum

Experience accepted in place of education

Location requirements

Hiring timezones

United States +/- 0 hours

About Arlo Solutions

Learn more about Arlo Solutions and their company culture.

View company profile

At Arlo Solutions, the core of their operations is a steadfast commitment to bolstering national security through innovative and tailored solutions. Founded in 2014 by Lonye Ford and Arlene Wube, the company's culture is deeply rooted in values of excellence, passion, and a people-first approach. This isn't just about corporate jargon; it's a lived reality where every team member is empowered to contribute to a mission larger than themselves. The company thrives on a collaborative and open environment, fostering innovation and allowing individuals to grow both professionally and personally. They believe in being distinct, detail-oriented, and daring in their pursuit of simplifying complex technological challenges for their clients, primarily within the Department of Defense and other federal government agencies. This dedication has not only fueled their rapid growth but has also garnered national recognition for their impactful work in cybersecurity and intelligence support.

The journey of Arlo Solutions is a testament to resilience and a forward-thinking mindset. From its bootstrapped beginnings, the company has cultivated a unique perspective, viewing industry peers not as competitors but as potential partners. This collaborative spirit has been instrumental in their success, allowing them to partner with larger organizations and deliver comprehensive solutions. The leadership emphasizes the importance of a strong foundational structure, robust processes, and, most importantly, the right people. As Arlo Solutions continues to expand its team and take on increasingly complex projects, the focus remains on maintaining the core values that have defined their success: a passion for the mission, a commitment to excellence, and an unwavering dedication to the people they serve and the team they've built. Their vision extends beyond just delivering services; it's about making a tangible impact on national security and creating an environment where innovation and personal growth go hand in hand.

Employee benefits

Learn about the employee benefits and perks provided at Arlo Solutions.

View benefits

Voluntary Benefits

Voluntary Benefits

Career development

Career development

Paid volunteer time

Paid volunteer time

Flexible/Unlimited PTO

Flexible/Unlimited PTO

View Arlo Solutions's employee benefits
Claim this profileArlo Solutions logoAS

Arlo Solutions

View company profile

Similar remote jobs

Here are other jobs you might want to apply for.

View all remote jobs

4 remote jobs at Arlo Solutions

Explore the variety of open remote roles at Arlo Solutions, offering flexible work options across multiple disciplines and skill levels.

View all jobs at Arlo Solutions

Remote companies like Arlo Solutions

Find your next opportunity by exploring profiles of companies that are similar to Arlo Solutions. Compare culture, benefits, and job openings on Himalayas.

View all companies

Find your dream job

Sign up now and join over 100,000 remote workers who receive personalized job alerts, curated job matches, and more for free!

Sign up
Himalayas profile for an example user named Frankie Sullivan