Arlo Solutions (Arlo) is an information technology consulting services company that specializes in delivering technology solutions. Our reputation reflects the high quality of the talented Arlo Solutions team and the consultants working in partnership with our customers. Our mission is to understand and meet the needs of both our customers and consultants by delivering quality, value-added solutions. The Department of Defense’s (DoD) Chief Digital and Artificial Intelligence Office (CDAO) is at the forefront of supporting the DoD with the adoption of innovative technologies such as data, analytics, and artificial intelligence to help accelerate predictions, forecasts, and interpretations for both strategic and tactical decisions across the enterprise.
(655) Mid Information Systems Security Officer
Location
United States
Posted
89 days ago
Salary
0
Seniority
Mid Level
No structured requirement data.
Job Description
(655) Mid Information Systems Security Officer
Arlo Solutions LLC
Company Summary Arlo Solutions (Arlo) is an information technology consulting services company that specializes in delivering technology solutions. Our reputation reflects the high quality of the talented Arlo Solutions team and the consultants working in partnership with our customers. Our mission is to understand and meet the needs of both our customers and consultants by delivering quality, value-added solutions. Our solutions are designed and managed to not only reduce costs, but to improve business processes, accelerate response time, improve services to end-users, and give our customers a competitive edge, now and into the future. Position Overview The Mid Information System Security Officer (ISSO) (IAM 2) will support the Defense Security Cooperation Agency (DSCA) Cybersecurity (CYBR) team by providing expertise in Risk Management Framework (RMF) activities, security control assessments, controls validation, and continuous monitoring. The role involves ensuring compliance with RMF, IT, and Federal Information System Controls Audit Manual (FISCAM) guidelines, and supporting the cybersecurity responsibilities detailed in the DSCA CYBR Service Catalog. Work Location: Fully Remote Clearance: Active Secret Clearance Job Responsibilities and/or Success Factors - Produce all required DOD compliance documentation for RMF, Audit Response and Remediation, Cyber Task Orders, Required Scorecards, Privacy documentation, and other compliance requirements as detailed in the DSCA CYBR Service Catalog. - Draft and coordinate cybersecurity-related documentation to meet required standards, controls, and metrics. - Support all steps of the RMF process (Steps 0-6) required to gain and maintain DOD Information Network (DODIN) and agency commercial network authority to operate. - Assist in categorization, control selection, implementation, and tailoring support, as well as support of assessments from the ISSO role. - Prepare and validate controls in eMASS packages for assessment and review. - Ensure that control requirements are well-defined and that necessary documentation and evidence are gathered for validation and assessment. - Work in the DOD GRC tool Enterprise Mission Assurance Support Service (eMASS) to support control validation. - Conduct continuous monitoring of information systems to detect vulnerabilities, threats, and security incidents. - Utilize security tools and technologies to perform regular scans, assessments, and analysis of system vulnerabilities. - Maintain and update continuous monitoring processes and procedures to ensure they are effective and aligned with organizational requirements. - Assist in the configuration and maintenance of security tools and technologies provided by the CSSP. - Assist in the detection, analysis, and response to cybersecurity incidents. - Participate in incident response activities, including triage, containment, eradication, and recovery. - Document and report on incident response activities, providing detailed analysis and recommendations for improvement. - Provide support to the Watch Officer in monitoring and managing cybersecurity events and incidents. - Maintain situational awareness of the organization's security posture and emerging threats. - Assist with the performance of daily and ad hoc/on-demand vulnerability scans, monthly audit scans, and monthly discovery scans. - Provide weekly vulnerability compliance reporting to ISSMs. - Review and adjust assets, subnets, credentials, and policies to properly manage C5ISR provided Assured Compliance Assessment Solution (ACAS) solutions. - Track and ensure configuration compliance of Enterprise Security Services (ESS) Suite with RMF, ATO, and Inspection requirements. - Assist with the maintenance of completed security waiver forms in coordination with EADSD and ISSM (PMO). - Work with TSD to implement effective scanning, COAMS System Registration, and Continuous Monitoring Scoring (CMRS) Tagging. - Maintain and update Ports, Protocols, and Services Management (PPSM) records, including emergency and exception requests. - Support the maintenance and accuracy of DoD Allow List entries. - Maintain accurate and up-to-date documentation of all RMF, IT, and FISCAM controls validation activities. - Prepare and submit regular reports on the status of security controls, RMF activities, and DevSecOps pipeline security. - Provide detailed documentation and evidence to support security assessments and audits. - Support the maintenance and configuration needed to maintain accurate ingestion of logs from all assets. - Provide summaries of events/incidents, including time of event/incident, anomalous activity identified, asset names and IPs, affected users, and POC for outreach/additional actions. - Complete Cybersecurity Incident Reporting Forms and assist with the detection and analysis of cybersecurity events and incidents. - Support accurate IR POC list, accurate hardware/software and IP inventory, and accurate summary of event/incident. - Document efforts involved in mitigating cybersecurity-related events/incidents that occur within the enterprise. - Support the generation of performance monitoring reports to monitor asset availability. - Support the generation of system health and security posture reports for system owners and ISSMs. - Support accurate hardware and software inventory, accurate ingestion of logs from all assets, and accurate system performance and security posture baselines. - Conduct specified areas of focus/detail for trend analysis. - Support migration information provided by affected system ISSM and report vulnerabilities to appropriate system ISSMs/POCs. - Assist with the reporting to outside agencies, including JFHQ, battle stations, external leadership, and other DOD Agencies. - Support the correlated agency-level POA&Ms with the coordination of POA&Ms from DSCA to outside entities. - Help complete the Cybersecurity Incident Reporting Form, including additional inputs such as personnel logs, system logs, event logs, and accurate software and hardware inventory list. Education and Minimum Qualifications - Must be a US Citizen - Active Secret Clearance - Bachelor’s degree in computer science, Information Technology, Cybersecurity, or a related field is required OR additional four (4) years of experience - Strong understanding of Risk Management Framework (RMF) processes and security control assessments, including experience with categorization, control selection, implementation, and assessment. - Minimum of two (2) years of relevant experience in cybersecurity, information assurance, or a related field. - Experience in IT controls validation and familiarity with Federal Information System Controls Audit Manual (FISCAM) guidelines. - Experience in incident response, continuous monitoring, and vulnerability management. - Proficiency in using security assessment tools and platforms such as eMASS (Enterprise Mission Assurance Support Service). - Familiarity with continuous monitoring processes and tools. - Experience with incident response processes and tools. - Knowledge of cybersecurity frameworks and standards, such as NIST, ISO 27001, and CIS Controls. Desired Qualifications: - Certifications such as CSSP, CISM, CISA, CAP, Security+, or equivalent is highly desirable. - Experience with OKTA - Experience as an ISSO or otherwise prior experience with IT Risk Management Framework Support. AAP Statement We are proud to be an Affirmative Action and Equal Opportunity Employer and as such, we evaluate qualified candidates in full consideration without regard to race, color, religion, sex, sexual orientation, gender identity, marital status, national origin, age, disability status, protected veteran status, and any other protected status.
Job Requirements
- Must be a US Citizen
- Active Secret Clearance
- Bachelor’s degree in computer science, Information Technology, Cybersecurity, or a related field is required OR additional four (4) years of experience
- Strong understanding of Risk Management Framework (RMF) processes and security control assessments, including experience with categorization, control selection, implementation, and assessment.
- Minimum of two (2) years of relevant experience in cybersecurity, information assurance, or a related field.
- Experience in IT controls validation and familiarity with Federal Information System Controls Audit Manual (FISCAM) guidelines.
- Experience in incident response, continuous monitoring, and vulnerability management.
- Proficiency in using security assessment tools and platforms such as eMASS (Enterprise Mission Assurance Support Service).
- Familiarity with continuous monitoring processes and tools.
- Experience with incident response processes and tools.
- Knowledge of cybersecurity frameworks and standards, such as NIST, ISO 27001, and CIS Controls.
- Desired Qualifications
- Certifications such as CSSP, CISM, CISA, CAP, Security+, or equivalent is highly desirable.
- Experience with OKTA
- Experience as an ISSO or otherwise prior experience with IT Risk Management Framework Support.
- AAP Statement
- We are proud to be an Affirmative Action and Equal Opportunity Employer and as such, we evaluate qualified candidates in full consideration without regard to race, color, religion, sex, sexual orientation, gender identity, marital status, national origin, age, disability status, protected veteran status, and any other protected status.
Related Guides
Related Categories
Related Job Pages
More Security Analyst Jobs
• Lead large-scale, highly complex cybersecurity, infrastructure and governance, risk and compliance (GRC) initiatives • Translate complex technical and security and compliance challenges into structured, actionable project plans • Drive execution with rigor and attention to detail • Communicate with executive presence • Develop and execute organizational change management plans
Cybersecurity Risk Assessment Specialist
MercorCincinnatus is an enterprise staffing company that partners with leading technology companies to source and employ highly skilled professionals for full-time and long-term contingent roles. Cincinnatus serves as the employer of record for these engagements, providing W-2 employment, payroll, benefits, and compliance, while placing employees directly within client teams to work on high-impact initiatives. Roles hired through Cincinnatus are not project-based or freelance engagements. They are structured, role-based positions that typically involve full-time or fixed-term commitments, close collaboration with a client's internal teams, and integration into standard enterprise workflows. Cincinnatus is a legal entity separate from Mercor. While opportunities may be discovered through Mercor's platform, employment, onboarding, payroll, and benefits for these roles are administered by Cincinnatus. Equal Employment Opportunity Cincinnatus is proud to be an Equal Employment Opportunity employer. We do not discriminate based upon race, religion, color, national origin, sex (including pregnancy, childbirth, reproductive health decisions, or related medical conditions), sexual orientation, gender identity, gender expression, age, status as a protected veteran, status as an individual with a disability, genetic information, political views or activity, or any other legally protected characteristic. Cincinnatus is committed to providing reasonable accommodations for qualified individuals with disabilities and disabled veterans throughout the job application process.
Role Description - Red team conversational AI models and agents by conducting jailbreaks, prompt injections, misuse cases, and bias exploitation. - Generate high-quality human data by annotating failures, classifying vulnerabilities, and flagging systemic risks. - Apply structure by following taxonomies, benchmarks, and playbooks to maintain consistent testing. - Document reproducibly by producing reports, datasets, and attack cases that customers can act on. - Work independently and asynchronously to meet deadlines while improving AI model performance. Qualifications - Must-Have: - Native-level fluency in English & Arabic. - Prior red teaming experience in AI adversarial work, cybersecurity, or socio-technical probing. - Strong communication skills to explain risks clearly to technical and non-technical stakeholders. - Preferred: - Experience in Adversarial ML, Cybersecurity, or Socio-technical risk. - Skills in Creative probing such as psychology, acting, or writing for unconventional adversarial thinking. Requirements - Hourly contractor, Paid weekly. Application Process - Upload resume - AI interview based on your resume - Submit form Resources & Support - For details about the interview process and platform information, please check: https://talent.docs.mercor.com/welcome/welcome - For any help or support, reach out to: support@mercor.com - PS: Our team reviews applications daily. Please complete your AI interview and application steps to be considered for this opportunity.
Surveillance Investigator - Full Time
CoventBridge GroupCoventBridge Group offers a full range of investigative services for clients around the world. The company provides surveillance, counter-fraud services, and cl
Overview Surveillance Investigator - Full Time Minneapolis, MN Area CoventBridge Group is growing—and we’re looking for experienced investigators to join our elite surveillance team. In this role, you’ll conduct discreet, vehicle-based field investigations to help uncover insurance fraud and deliver trusted results to our clients. As a leader in the fraud investigation industry, CoventBridge offers the opportunity to work remotely with flexible scheduling, advanced tools, and the support of a nationwide team. Responsibilities/ Requirements Key Responsibilities: - Case Prep: Use social media and database tools to conduct initial research and gather intel on subjects. - Surveillance in the Field: Carry out discreet, mobile and stationary surveillance—track movements and capture high-quality video evidence. - Reporting: Write thorough, court-ready reports that clearly document key activities and findings. - Evidence Submission: Wrap up each day by uploading reports and video footage from your personal laptop. - Team Collaboration: Stay connected with your field supervisor for ongoing support, guidance, and mentorship. Essentials for this Role: - PI License: Must currently hold—or be eligible to obtain—Private Investigator license in Minnesota. - Driver's License: Active driver's license that is not currently suspended or revoked. - Personal Vehicle: A well-maintained vehicle that is always reliable (preferably with tinted windows). Proof of auto insurance coverage is required. - Travel Expectations: While we aim to keep assignments within a reasonable drive of your residence, occasional further travel and overnight stays (covered by the company) may be required. - Technology: A reliable laptop, cell phone, and internet service are needed for communication and administrative tasks. - Required Skills: Strong computer & internet proficiency. Excellent communication, verbal & writing skills. Possess or is willing to purchase covert camera, digital video camera with uploading capabilities, and laptop computer with Windows Operating System with access to Microsoft Word Additional Responsibilities: Duties and responsibilities include essential functions of positions assigned to this classification. Depending on assignment, the employee may perform a combination of some or all the following duties: - Conduct Fixed and Mobile Video Surveillance: Capture high-quality video footage of subjects to assist in case investigations. - Gather Evidence: Obtain videotaped documentation, photos, and audio recordings as part of thorough surveillance. - Background and Activity Checks: Perform courthouse research, background checks, and monitor subject activities to build robust case reports. - Investigative Reporting: Draft clear, concise, and detailed investigative reports summarizing findings and evidence. - Evidence Management: Upload all video, photographic, and audio evidence into the case management system in a timely and organized manner. - Drive Safely and Responsibly: Remain alert and practice safe driving while traveling to and from investigation sites. Working Conditions: - Most surveillance cases start at 6:00AM. End time can vary depending on activity. - Weekends/holidays are common workdays as claimants are more likely to be active. - This is an independent role often requiring long hours alone in your vehicle, regardless of weather conditions. - Must remain alert with no external distractions, ready to use videography equipment to document subjects. Benefits Compensation & Perks That Work For You: We believe great work deserves great rewards. Here’s what you can expect when you join our team: Competitive Pay: - Earn $25-$30 per hour, based on experience. On-the-Road Support: - Monthly vehicle allowance - Company fuel card - Company-issued cell phone - Monthly internet stipend - Travel & report writing compensation - Fast, hassle-free expense reimbursements (minimal out-of-pocket costs) Full Coverage Benefits: - Medical, dental, and vision insurance - Employer-paid life insurance, short-term & long-term disability Future-Focused Perks: - Company-matching 401(k) to help you build for the future - Paid time off to recharge and reset - Company-paid investigator licensing fees Career Growth: - Ongoing paid training and advancement opportunities to help you grow your skills and your career The salary range for this role is $25-$30 per hour. This is the lowest to highest salary we in good faith believe we would pay for this role at the time of this posting. We may ultimately pay more or less than the posted range, and the range may be modified in the future. An employee’s pay position within the salary range will be based on several factors including, but not limited to, relevant education, qualifications, certifications, experience, skills, geographic location, performance, and business or organizational needs. About Us: CoventBridge Group is the global leader in full-service investigations providing: Surveillance, SIU and Compliance, Claims Investigation, Counter-Fraud Programs, Desktop Investigations, Social Media, Record Retrieval, Canvasses and Vendor Management programs. The company provides top tier data privacy and security practices, deploys robust case management technology customized to clients’ needs and delivers worldwide coverage via its 1000 employees and affiliates worldwide. CoventBridge Group is an equal opportunity employer. We evaluate qualified applicants without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, caste, disability, veteran status, and other legally protected characteristics and maintains a drug-free workplace. CoventBridge Group is committed to the full inclusion of all qualified individuals. As part of this commitment, CoventBridge will ensure that persons with disabilities are provided reasonable accommodations. If reasonable accommodation is needed to participate in the job application or interview process, to perform essential job functions, and/or to receive other benefits and privileges of employment, please contact: Human Resources; 888-932-7364; humanresources@coventbridge.com. CoventBridge (USA) Inc. Minnesota License # 1047
About the Internship Program: Our internship program is designed to provide hands-on experience and professional development opportunities for students or recent graduates. Interns will work on meaningful projects, gain exposure to our organization, and develop skills that align with their career goals. About the Role: We are seeking a highly motivated Information Security Intern to join our Information Security team. This internship provides hands-on experience supporting enterprise security initiatives in a fast paced, regulated environment. You’ll gain real world cybersecurity experience including vulnerability management, threat monitoring, compliance documentation, identity management and devsecops projects. Specific responsibilities: - Assist in monitoring security alerts and analyzing potential threats - Support vulnerability scanning and remediation tracking - Help review access controls and user permissions - Contribute to documentation of security policies and training procedures - Support incident response documentation - Help mature devsecops - Support automation of processes such as identity management and incident response What you’ll need: - Currently pursuing a Bachelor’s or Master’s degree in Cybersecurity, Computer Science, Information Technology, or related field - At least beginner level skill in scripting, Python preferred - Familiarity with operating systems (Windows, macOS) - Basic understanding of information security concepts - Strong analytical and problem-solving skills - Ability to handle sensitive information with confidentiality and discretion - Strong communicator who can translate technical issues clearly and concisely Additional Details: At Health-E Commerce, our goal is to provide an offer that supports growth potential within the role and allows for future salary progression. Final compensation is evaluated on various factors which include but aren’t limited to experience, skills, internal equity among peers, and geographic location. - Compensation: $15-20/hr - 100% remote within the United States - Must be able to work EST hours Candidate Privacy Notice

