Find Jobs
Find Jobs Near You – Available Work in Your Location
ISSO Specialist
Career Insights for Vulnerability Analyst / Penetration Tester
See where this job fits in the broader career landscape. Knowing your career path helps you see what's possible from here.
Scorecard
Based on Massachusetts data
Review key factors to help you decide if this role fits your goals. How is this calculated?
What they do
A Vulnerability Analyst or Penetration Tester probes for and exploits security vulnerabilities in web-based applications, networks and systems. Penetration Tests are designed to achieve a specific, attacker-simulated goal and should be requested by customers who are already at their desired security posture. A typical goal could be to access the contents of the prized customer database on the internal network, or to modify a record in an HR system. Vulnerability Assessments are designed to yield a prioritized list of vulnerabilities and are generally for clients who already understand they are not where they want to be in terms of security. The customer already knows they have issues and simply need help identifying and prioritizing them.
$119,730 / year median in Massachusetts
+4% projected growth
Job Description
Job Description ISSO Specialist Clearance Level:
A Top Secret clearance with SCI eligibility is required. Candidate may be required to pass a CI polygraph.•MUST BE US
Citizen Location:
Must be within 100 miles from Lexington, MA At Aquila Technology, you will see our team's passion every day, whether we are building a robust, policy-compliant IT system or stress-testing a system to identify gaps and security vulnerabilities. To own the advantage, we ensure our team owns results and gets the work done right the first time by deploying smart, purposeful solutions that work. Aquila is the right people with the right skills driving the right outcomes. We call this the Aquila Advantage. Aquila Technology is seeking a highly skilled ISSO Specialist to join our team in supporting one of the country's premier defense research organizations. The team is seek someone to support the design, development, implementation, and testing of software for a series of large-scale communications system demonstrations. This role supports the Air Force Programs and prefers candidates with mid-level experience. Responsibilities/Day toDay:
Assist and Support necessary compliance activities (e.g., ensure that system security configuration guidelines are followed, compliance monitoring occurs). Continuously validate the organization against policies/guidelines/procedures/regulations/laws to ensure compliance. Ensure that action plans, milestones, or remediation plans are in place for vulnerabilities identified during risk assessments, audits, inspections, etc. Promote awareness of security issues among management and ensure sound security principles are reflected in the organization's vision and goals. Track audit findings and recommendations to ensure that appropriate mitigation actions are taken. Recommend resource allocations required to securely operate and maintain an organization's cybersecurity requirements. Provide technical documents, incident reports, findings from computer examinations, summaries, and other situational awareness information to key stake holders. Recognize a possible security violation and take appropriate action to report the incident, as required. Assist the Program Managers and the Information System Security Manager (ISSM) in the development and maintenance of System Security Plans (SSP) and associated artifacts such as the Plan of Action & Milestones (POA&M), Risk Assessment Report, and Continuous Monitoring Strategy. Ensure systems are operated, maintained, and disposed of in accordance with organization security policies and procedures. Conduct network, system, and application vulnerability scanning, configuration assessment, and remediation. Lead and align information technology (IT) security priorities with the security strategy. Prepare for and participate in periodic organization compliance assessments. Interpret patterns of noncompliance to determine their impact on levels of risk and/or overall effectiveness of the enterprise's cybersecurity program. Must Have 4 yearsSystem Auditing Certification:
Current DoD 8570 IAT Level II Certification (GSEC, Security+ CE, SSCP, CCNA-Security) 4 years- Regulatory & Compliance 4 years
- Government Policy/Regulations 4 years
- STIGs/SCAP 4 years
- Assessing Security Controls (CS105.16) 4 years
- Assessment and Authorization 4 years
- Authorizing Systems (CS106.16) 4 years
- Categorization of the System (CS102.16) 4 years
- Continuous Monitoring (CS200.16) 4 years
- Implementation of Controls (CS104.16) 4 years
- Monitoring Security Controls (CS107.16) 4 years
NIST 800-53 4
yearsNIST SP 800-37 4
years- Risk Management Framework (RMF) 4 years
- Selecting Security Controls (CS103.
Have Degree Level:
Bachelor's Degree SecurityHBSS NIST 800-171
Education and Certifications:
BS degree is preferred but not required Security Plus is the minimum 8570 certification requirement.Our Perks Include:
PTO- 15 days (vacation/sick) 10 paid holidays
- 6 standard (New Year's, Memorial Day, Independence Day, Labor Day, Thanksgiving, and Christmas)
- 4 floating holidays prorated based on your day of hire: 1.5 paid days, or 12 hours, for approved volunteer work 1 week of paid maternity/paternity LOA after 1 year of Full-time employment Tuition & Training Reimbursement
- 5K annually for pre-approved, Eligible full-time team members who have completed a minimum of six (6) months of employment may apply for tuition reimbursement for approved, job-related courses taken through an accredited college or university.
Aquila will reimburse up to $5,000 per fiscal year for tuition expenses only. Expenses related to training programs, certifications, books, materials, meals, transportation, or other non-tuition costs are not eligible under the Tuition Reimbursement Program. All tuition reimbursement requests must be submitted to and approved by the team member's Manager prior to course registration. Reimbursement will be issued upon successful course completion and submission of final grades and proof of payment. 401K with Fidelity
- Eligible to participate following 90 days of employment.
Company match on employee contribution:
$1/$1 up to 3%, then .50 cents / $1 for 4th and 5th %s Fully vested from day one Company match does not apply to catch-up contribution Cell Phone & Internet Reimbursed up to $150 monthly to cover cell phone, data, and home internet expenses. Aquila Technology will reimburse team members who work from home ONLY for cell phone/mobile device fees for work-related communications and/or operations each month. Employees eligible for this benefit must work remote 2 days a week or more to qualify. Buy Your Own Device (BYOD)- Team members are eligible for reimbursement of up to $1,500 every three (3) years for the purchase of electronic equipment used to access corporate services.
- A Top Secret clearance with SCI eligibility is required. Candidate may be required to pass a CI polygraph.
MUST BE US
Citizen Interview process- will consist of a phone screen followed by an extensive zoom interview with the team members. Location/Work Schedule
- This position is 100% onsite due to the nature of the work.