Draft, propose, and maintain IT security policies, procedures, templates, and checklists for the Tsunami Warning System in accordance with DOC, NOAA, NWS, and NIST guidance.
Perform full security authorization process activities, including developing and updating high-quality security authorization package documentation (System Security Plan, contingency plan, business impact analysis, backup and recovery plans, contingency plan test plans and reports) and supporting reauthorization activities (current ATO valid through 7/31/2026).
Conduct compliance and quality reviews of system security plans, security control implementation descriptions, and contingency planning artifacts; provide written feedback for improvement.
Manage the full Plans of Action and Milestones (POA&M) lifecycle, including reviewing closure evidence, validating completeness of content, tracking remediation timelines, and providing monthly status updates; ISSO holds POA&M closure approval authority alongside the ITSO.
Upload and maintain all security documentation in the Joint Cybersecurity Assessment and Management (JCAM) system (formerly CSAM).
Develop, deliver, and administer role-based IT security training (annual cybersecurity training for ~37 users; specialized training for 6 key security role holders including the Authorizing Official, System Owner, and four system administrators) using PowerPoint presentations, webinars, video conferencing, or instructor-led content.
Support ACIO assessment teams in implementing the NIST Risk Management Framework and managing all NIST SP 800-53 security controls applicable to the system.
Assist in assembling responses to Office of the Inspector General (OIG), DOC, and NOAA inquiries, audits, and data calls as directed by the Federal IT Security Services Branch (ITSSB).
Provide expert advice on IT security solution options for Microsoft Windows and Red Hat Linux environments, including FedRAMP-authorized cloud services in use (ServiceNow, SmartSheet, Google Workspace at Low impact), and assist with risk measurement, migration planning, and implementation of new security tools.
Track and report all required metric data on monthly, quarterly, and annual cadences; produce monthly program status reports detailing completed work, milestones, schedule variances, and projected work for the upcoming month.
Travel to the National Tsunami Warning Center in Alaska approximately twice annually and participate in the contractor's transition activities (minimum two-week overlap) at contract start and end.
Demonstrated prior Federal Government project/contract experience that included (1) advising on IT security requirement solution options and developing supporting documentation/white papers, (2) leading development of solution migration and implementation plans for IT security requirements, and (3) creating IT security policies and procedures.
Working knowledge of U.S. Federal IT security policies and implementation standards (DOC, NOAA, NWS) and comprehensive understanding of NIST guidance, including NIST SP 800-53 Rev. 4/5, NIST SP 800-37 Rev. 2, NIST SP 800-30 Rev. 1, NOAA-IT Security Manual 212-1301, NWS Instruction 60-702, DOC ITSBP, and applicable Federal Information Processing Standards.
Hands-on experience administering security for Microsoft Windows and Red Hat Linux systems, or comparable enterprise environments.
Proficiency with industry-standard IT security tools such as Cyber Security Assessment and Management (CSAM/JCAM) and Tenable Security Center (or equivalent vulnerability management platform).
Demonstrated experience in contingency planning, backup and recovery best practices, and applying NIST guidance in those areas.
Comprehensive understanding of encryption techniques, tools, and best practices for protecting organizational data.
Strong interpersonal skills, including demonstrated proficiency in handling multiple concurrent tasks, project and time management, and the ability to efficiently adjust to changing priorities.
Ability to work on-site full-time during HST core business hours and maintain uninterrupted coverage; flexibility to travel to Alaska approximately twice per year.
Higher-tier industry certifications demonstrating advanced cybersecurity expertise, such as CISSP-ISSEP (Information Systems Security Engineering Professional), CISSP-ISSAP (Information Systems Security Architecture Professional), CISSP-ISSMP (Information Systems Security Management Professional), or PMP (Project Management Professional).
Bachelor's or Master's degree in Computer Science, Cybersecurity, Information Systems, Information Assurance, Engineering, or a related technical field.
Prior ISSO or equivalent FISMA practitioner experience supporting a NOAA, NWS, or Department of Commerce system.
Working knowledge of FedRAMP-authorized cloud services in use on the Tsunami Warning System (ServiceNow, SmartSheet, Google Workspace) and the security implications of inheriting controls from FedRAMP Low boundaries.
About IBSS Corp.
Since 1992, IBSS, a woman-owned small business, has provided transformational consulting services to the Federal defense, civilian, and commercial sectors. Our services include cybersecurity and enterprise information technology, environmental science and engineering (including oceans, coasts, climate, and weather), and professional management services.
Our approach is to serve our employees by investing in their growth and development. As a result, our employees bring greater capabilities and provide exceptional service to our clients. In addition to creating career development opportunities for our employees, IBSS is passionate about giving back to the community and serving the environment. We strive to leave something better behind for the next generation.
We measure our success by the positive impact we have on our employees, clients, partners, and the communities we serve. Our tagline, Powered by Excellence, is a recognition of the employees that make up IBSS and ensures we deliver results with quality, applying industry best practices and certifications.
IBSS offers a competitive benefits package that includes medical, dental, vision, and prescription drug coverage with a company-paid deductible, paid time off, federal holidays, a matching 401K plan, tuition/professional development reimbursement, and Flex-Spending (FSA)/Dependent Care Account (DCA) options.
IBSS is an affirmative action and equal opportunity employer. All qualified applicants will be considered for employment without regard to race, color, religion, sex, disability, age, sexual orientation, gender identity, national origin, veteran status, or genetic information. Click https://www.eeoc.gov/poster to see that the EEO is the law. Please direct any inquiries to the HR Department email at HR@ibsscorp.com.
If you require reasonable accommodation in completing this application, interviewing, completing any pre-employment testing, or otherwise participating in the employee selection process, please direct your inquiries to the Talent Acquisition department at Recruiting@ibsscorp.com