Gunnison Consulting Group

Gunnison Consulting Group is an IT company that offers both commercial and government customers high-quality consulting services. Since 1994, the firm’s goal

Information System Security Officer (ISSO)

Location

United States

Posted

74 days ago

Salary

$70K - $75K / year

Seniority

Mid Level

No structured requirement data.

Job Description

Information System Security Officer (ISSO)

Gunnison Consulting Group

Description Salary: $70,000 - $75,000/year The ISSO provides system-level security expertise and serves as the principal advisor to system owners on cybersecurity compliance, risk, and operations. This role ensures systems maintain Authorization to Operate (ATO) and adhere to Department and federal requirements. Duties and responsibilities include: - Implement and document security controls in accordance with NIST SP 800-53 and RMF. - Manage the full RMF lifecycle, including security categorization, control selection, implementation, testing, and continuous monitoring. - Develop, maintain, and submit security documentation including SSPs, SARs, and POA&Ms. - Conduct security scans, vulnerability assessments, and compliance testing. - Support internal and external audits by providing documentation and evidence. - Identify, document, and track vulnerabilities and remediation plans. - Serve as the central point of contact for system-level cybersecurity matters. Requirements - 5+ years of ISSO or equivalent cybersecurity role experience. - In-depth knowledge of NIST RMF, FISMA, and CISA directives. - Proficiency with vulnerability management and risk assessment tools. - Strong documentation and reporting skills. Clearance Requirement: Active Secret clearance required. The salary range for this position depends upon multiple factors including location, the individual's knowledge, skills, competencies, and experience, and contract-specific budget constraints and organizational requirements. Gunnison Consulting Group's total compensation package also includes bonus and profit-sharing opportunities, depending on company and employee performance. Available employee benefits include: - 3 weeks of Personal Leave your first year - 11 paid Holidays each year - 5 days of Flexible Time Off each year - 401(k) company match at 50% up to 10% of your salary - Medical, Dental and Vision Insurance - Life and Disability Insurance - Public Transportation Subsidies - Certifications and Training Allowance - $2,500/year! Why Join Gunnison? - Gunnison takes on ambitious projects. We target fun, challenging work that requires creative thinking and innovation. - Quality is our top priority. - Gunnison employee benefits meet or exceed what other companies in the Washington, D.C. metropolitan area offer. - There is a great sense of camaraderie at Gunnison. This is an atmosphere we will maintain as we continue to grow. - We are growing rapidly and the opportunity for individual professional growth with Gunnison is outstanding. - We hire for careers at Gunnison, not to fill a position. Equal Opportunity/Affirmative Action Employer. Must be eligible for employment in the United States. We are unable to sponsor candidates at this time. In 1994 Gunnison began serving the greater Washington, D.C. metro area, focused on tackling our customers' most ambitious technology projects. By creating a culture dedicated to enabling our customers and employees to achieve more than they ever thought they could, the company has thrived for over 25 years.

Related Job Pages

More Security Analyst Jobs

Full TimeRemoteTeam 10,001+Since 2017H1B Sponsor

Through our dedicated associates, Conduent delivers mission-critical services and solutions on behalf of Fortune 100 companies and over 500 governments - creating exceptional outcomes for our clients and the millions of people who count on them. You have an opportunity to personally thrive, make a difference and be part of a culture where individuality is noticed and valued every day. Information Security Engineer III About the Role The Information Security Engineer III serves as a member of the NIST CISO Audit & Assurance team and will assist in the performance of internal audits, ensuring they comply with applicable Conduent and ISO security standards, regulations, and policies. The internal auditor will be professional, independent, impartial, and fair in all interactions. - The NIST security resource is accountable for procedures and processes that ensure the integrity, confidentiality, and availability of assigned Business units’ information, applications, and infrastructure. - The resource will perform routine risk assessments, security audits, and vulnerability scans to identify, evaluate, document, and remediate organization risk, control gaps and vulnerabilities. - This position will be responsible for developing security reports, security recommendations, and security policies and procedures that are meaningful, defensible, and actionable for a variety of audiences as pertained to assigned business units. - Perform log collection, correlation, reviews, archival, retention, and monitoring of automated alerts for items such as, and not limited to: - IPS/IDS alerts; change detection (FIM) alerts - application firewall alerts; malware alerts - rogue wireless network alerts - security system health alerts; exploit attempt alerts - Participate and be an integral component of audit, compliance, and regulatory functions, including and not limited to: - audits of system security to ensure compliance with Corporate security framework - NIST 800-53, ISO 27001/2, PCI-DSS - emerging country, state, and Federal privacy laws - Primary POC in a vulnerability management program of the account that includes: - external and internal vulnerability scans of applications and systems - external and internal penetration tests of applications and systems - documentation and remediation of identified vulnerabilities and exploits - routinely monitoring various communication avenues for security vulnerabilities and security patches - taking a risk-based approach comparing those security vulnerabilities and security patches across the operating environments - making recommendations to various IT teams on the mitigation process for those identified security vulnerabilities - Coordinate with business units, operations, and technology teams for incident response, remediation, and improvement - Acts as the initial point of contact to facilitate the handling of security audits and client requests - Supports the creation of business continuity/disaster recovery plans, to include conducting disaster recovery tests, publishing test results, and making changes necessary to address deficiencies - Maintain documentation that supports the annual Security compliance attestation as it is relevant to the assigned Business units Qualifications and Education Requirements - CIPP, CRISC, CISA, CISSP, CISM, ISO or any security/IT audit certification is a plus. - Minimum of Five (4 to 5) Years of experience in IT Security, or Security Auditing is required. - Knowledge and understanding of security controls across all security domains, such as access management, encryption, vulnerability management, authentication, authorization, network security, physical security, etc. - Ability to identify security risks in application, system, and network architecture, data flow, and processes or procedures - Ability to assess the organizational impact of identified security risks and recommend solutions or mitigating controls. - Knowledge of security technologies, devices, and countermeasures, as well as the threats they are designed to counter. - Experience with developing security reports, recommendations, policies, and procedures that are meaningful, defensible, and actionable for a variety of audiences. - Familiarity with more than one framework (NIST 800-series, ISO 27000-series, PCI DSS and ISO, HIPAA, HITRUST, FISMA, FedRAMP other common security control frameworks). - Experience in PowerPoint, Word, Excel; experience with Visio and MS Project. - Communication skills (interpersonal, verbal, presentation written, email). Experience to write report segments and to participate in presentations. - Familiarity with security, workflow, and collaboration tools such Nessus Tenable, Splunk, SharePoint and ServiceNow (Snow) is a plus - Positive attitude, team player, self-starter; takes initiative, ability to work independently and effectively with all levels of staff and management both internally and externally Preferred Skills - Creating and Maintaining NIST 800-53-rev5 based SSP and POAM - Familiarity with more than one framework (NIST 800-series, ISO 27000-series, PCI DSS and ISO, HIPAA, HITRUST, FISMA, FedRAMP other common security control frameworks). Flexible Working At Conduent, we want you to be yourself. We recognize that everyone is different and that how people want to work and deliver at their best is different for everyone too. In this role, you can expect the following working conditions: Remote work: Enjoy the convenience of working from home and maximize your time by unplugging at the end of your workday. Working For You Perks and rewards designed for you: - Health and Welfare Benefits: Our health and welfare benefits can be tailored to fit you and your family's needs and start on the first day of employment. - Retirement Savings: We will support you as you save for your future. - Career Growth Opportunities: We help you thrive, so together, we can grow. We provide opportunities to advance your career with a vast portfolio of businesses and a global footprint. - Paid time off: We provide attractive paid time off packages designed for you to enjoy your life away from work. - Great Work Environment: We are proud of our award-winning culture and the recognition we’ve received for our diversity efforts. Join Us At Conduent, we are one team, one mission. We understand that our success is directly related to the success of our associates. We strive to create a culture where you can: Bring your authentic self to work Grow and thrive, both personally and professionally Make a difference with our clients, in our communities, and with the millions of people we support When you join Conduent, you are engaged in creating the future - both our company’s and your own. With more than 60,000 associates across 24 countries, we will provide you the opportunity to grow with a team of people who will challenge and inspire you to be the best! Pay Transparency Laws in some locations require disclosure of compensation and/or benefits-related information. For this position, actual salaries will vary and may be above or below the range based on various factors including but not limited to location, experience, and performance. In addition to base pay, this position, based on business need, may be eligible for a bonus or incentive. In addition, Conduent provides a variety of benefits to employees including health insurance coverage, voluntary dental and vision programs, life and disability insurance, a retirement savings plan, paid holidays, and paid time off (PTO) or vacation and/or sick time. The estimated salary range for this role is $96,250 - $125,000. Conduent is an Equal Opportunity Employer and considers applicants for all positions without regard to race, color, creed, religion, ancestry, national origin, age, gender identity, gender expression, sex/gender, marital status, sexual orientation, physical or mental disability, medical condition, use of a guide dog or service animal, military/veteran status, citizenship status, basis of genetic information, or any other group protected by law. For US applicants: People with disabilities who need a reasonable accommodation to apply for or compete for employment with Conduent may request such accommodation(s) by submitting their request through this form that must be downloaded: click here to access or download the form. Complete the form and then email it as an attachment to FTADAAA@conduent.com. You may also click here to access Conduent's ADAAA Accommodation Policy.

United States
$96.3K - $125K / year
Diebold Nixdorf logo

Associate Service Operations Security Technician

Diebold Nixdorf

We automate, digitize, and transform the way people bank and shop.

Security Analyst74 days ago
Full TimeRemoteTeam 10,001+Since 1859H1B Sponsor

Expect more. Connect more. Be more at Diebold Nixdorf. Our teams automate, digitize, and transform the way more than 75 million peoplearound the globebank and shop in thishyper-connected, consumer-centric world. Join us inconnecting people to commerce in this vital, rewardingrole. Installs, debugs and provides technical maintenance for product and component hardware and software, mainly on customer premises. Provides scheduled inspection, cleaning and other services and performs minor product repairs within an assigned territory. Inspects products for correct operation and resolves noted issues and / or escalates according to established procedure. Schedules services, completes all required paperwork and works with customers to ensure satisfaction with service delivery and understanding of product functionality. Why should you join Diebold Nixdorf? Brightest minds + technology and innovation + business transformation The people of Diebold Nixdorf are 23,000+ teammates of diverse talents and expertise in more than 130 countries, harnessing future technologies to deliver personalized, secure consumer experiences that connect people to commerce. Our culture is fueled by our values of collaboration, decisiveness, urgency, willingness to change, and accountability. –Diebold Nixdorf is an equal opportunity employer and we value diversity at our company. We do not discriminate on the basis of race, religion, color, national origin, gender, sexual orientation, gender identity, age, marital status, veteran status, or disability status. ** To all recruitment agencies: Diebold Nixdorf does not accept agency resumes. Please do not forward resumes to our jobs alias, Diebold Nixdorf employees or any other organization location. Diebold Nixdorf is not responsible for any fees related to unsolicited resumes** We are a global Company operating in multiple Locations and Entities. As we are keen to find the best solution for our candidates several legal entities might be applicable for a Job offer. A List of our operating entities can be found here - https://www.dieboldnixdorf.com/en-us/about-us/global-locations

United States
Securitas Security Services logo

Cybersecurity Awareness Specialist

Securitas Security Services

Securitas’ mission is to protect homes, workplaces, and communities by providing the security services they need to protect their assets, safeguard their people, and maintain their ability to generate profits. Core values - Integrity, Vigilance, and Helpfulness Employees come from diverse backgrounds, bringing distinctive skills and perspectives.

Security Analyst74 days ago
Full TimeRemoteTeam 10,001

Cyber Security Awareness Specialist JOB SUMMARY The Cybersecurity Awareness Specialist supports the execution of Securitas North America’s cybersecurity culture and human risk management initiatives. This role is primarily responsible for administering phishing and social engineering simulations, analyzing results, and supporting cybersecurity awareness training efforts across the division. Working under the direction of the Manager, Cybersecurity Culture & Human Risk Management, this position plays a key role in identifying human risk trends and reinforcing secure behaviors through targeted testing, reporting, and training support. This is a remote position. ESSENTIAL FUNCTIONS: - The functions listed describe the business purpose of this job or position. Specific duties or tasks may vary and be documented separately. An associate might or might not be required to perform all functions listed. Additional duties may be assigned, and functions may be modified, according to business necessity. - All assigned duties or tasks are deemed to be part of the essential functions, unless such duties or tasks are unrelated to the functions listed, in which case they are deemed to be other (non-essential) functions. - Associates are held accountable for successful job performance. Job performance standards may be documented separately, and may include functions, objectives, duties or tasks not specifically listed herein. - In performing functions, duties or tasks, associates are required to know and follow safe work practices, and to be aware of company policies and procedures related to job safety, including safety rules and regulations. Associates are required to notify superiors upon becoming aware of unsafe working conditions. - All functions, duties or tasks are to be carried out in an honest, ethical and professional manner, and to be performed in conformance with applicable company policies and procedures. In the event of uncertainty or lack of knowledge of company policies and procedures, associates are required to request clarification or explanations from superiors or authorized company representatives. Social Engineering & Phishing Simulations • Coordinate and execute phishing simulations and other social engineering exercises (e.g., smishing, vishing) across North America. • Utilize approved platforms (e.g., KnowBe4, Microsoft Defender) to deploy campaigns. • Manage campaign scheduling, targeting, and assignment of follow-up training. • Monitor and track key campaign metrics, including: • Click-through rates • Reporting rates • Repeat click behavior • Remedial training completion • Escalate findings and trends to the Manager for program refinement. • Maintain documentation of campaign execution and results. Data Tracking & Reporting (Excel-Based) • Compile, organize, and analyze phishing and training data using Microsoft Excel. • Create pivot tables, charts, and summary reports to support leadership updates. • Assist in tracking key performance indicators related to phishing performance and training completion. • Support preparation of monthly and quarterly reporting materials. Training & Awareness Support • Assist in the development and distribution of cybersecurity awareness materials. • Support onboarding and annual mandatory training administration. • Help create and coordinate awareness campaigns, webinars, and internal communications. • Provide logistical and administrative support for awareness initiatives. Incident & Awareness Support • Assist in reviewing reported phishing emails and awareness-related inquiries. • Help identify trends and training gaps based on campaign outcomes. • Maintain accurate records to support audit and compliance requirements. Collaboration • Work closely with the Manager, Cybersecurity Culture & Human Risk Management. • Partner with IT, Digital Security, HR, and Communications teams as needed. • Support divisional initiatives across the United States, Canada, and Mexico. MINIMUM QUALIFICATIONS AT ENTRY: Additional qualifications may be specified and receive preference, depending upon the nature of the position. Education/Experience: - Bachelor’s degree in communications, information security, or information technology, OR High School diploma with equivalent work experience. - 1-3 years’ experience in cybersecurity, compliance, or related field preferred - Experience administering phishing simulations preferred - Strong written and verbal communication skills preferred - Preferred certifications: SANS Security Awareness Professional (SSAP), CompTIA Security, or other relevant cybersecurity certifications Competencies (as demonstrated through experience, training, and/or testing): - Strong analytical and problem-solving skills - Ability to work independently and as part of a team - Strong attention to detail and organizational skills - Effective written and verbal communication skills - Ability to manage multiple tasks and meet deadlines Technical Skills - Microsoft 365 (Excel, PowerPoint, Outlook, Teams) - Proficiency in MS Excel (pivot tables, formulas, basic data analysis) - Phishing simulation platforms (e.g., KnowBe4) preferred - Smartsheet (preferred) - Microsoft Defender (preferred) WORKING CONDITIONS AND PHYSICAL/MENTAL DEMANDS: With or without reasonable accommodation, requires the physical and mental capacity to perform effectively all essential functions. In addition to other demands, the demands of the job include: - Maintaining composure in dealing with executives, clients, prospects, and staff, in group settings and in situations requiring high performance and results. - Must undergo and meet company standards for controlled substance testing, and behavioral selection survey. - Handling and being exposed to sensitive and confidential information. - Required ability to handle multiple tasks concurrently. - Up to 25% travel - Occasional lifting and/or moving up to 10 pounds. - Duties are performed in an office, hybrid or remote work setting. Securitas is committed to equal employment opportunity. All qualified applicants will receive consideration for employment without regard to race, color, religion, age, sex, sexual orientation, gender identity, national origin, pregnancy, genetic information, disability, status as a protected veteran, or any other applicable legally protected characteristic. Securitas employees come from all walks of life, bringing with them a variety of distinctive skills and perspectives. United through our common purpose, we provide the security needed to safeguard our clients' assets and people. Our core values - Integrity, Vigilance and Helpfulness - are represented by the three red dots in the Securitas logo. If you live by these values, we’re looking for you to join the Securitas team. Benefits include: - Retirement plan - Employer-provided medical and dental coverage - Company-paid life insurance - Voluntary life and disability insurance - Employee assistance plan - Securitas Saves discount program - Paid holidays - Paid time away from work Additionally, some populations may have the availability of accessing earned wages on a daily basis, prior to payday. Restrictions and fees may apply. Certain waiting periods may also apply. Paid time away from work may be available either through a combination of vacation and sick time or under a PTO policy, depending on local requirements. Benefits may be different for union members. Our Company Mission: Securitas’ mission is to protect homes, workplaces, and communities by providing the security services they need to protect their assets, safeguard their people, and maintain their ability to generate profits. Our Values: Securitas’ core values - Integrity, Vigilance and Helpfulness - are the foundation for our employees to build trust with customers, colleagues, and the surrounding community. Integrity: Securitas employees are honest and trusted by customers to safeguard their premises and valuables. We don’t compromise on integrity and create an open forum for our employees and customers to voice opinions, report improprieties, and share information. Vigilance: Seeing, hearing, and evaluating. A Securitas employee is always attentive and often notices things that others don’t. Their vigilance is necessary in order to be aware of potential risks or incidents that may take place on our customers’ premises. Helpfulness: As part of an on-going effort to ensure safety, Securitas employees are always ready to help if an incident occurs that requires intervention regardless of whether or not it is directly related to their job.

United States
$113K - $115K / year
Job Closed
Mayo Clinic logo

Intern - Info Security

Mayo Clinic

Headquartered in Rochester, Minnesota, Mayo Clinic is a nonprofit medical institution ranked first in more specialties than all other hospitals in America. The company employs arou

Security Analyst74 days ago

The Application Protection Team within the Mayo Clinic Office of Information Security (OIS) seeks interns to support our enterprise Vulnerability Management Program and Secure-SDLC. In return, interns will acquire valuable knowledge and real-world experience in cybersecurity that will complement their studies. Application Protection identifies and reports vulnerabilities, including CVEs, while also providing remediation advice to technical, clinical, and business stakeholders. We assess risk levels based on factors such as the number of affected assets, network exposure, and exploit maturity. These operational tasks are performed through the following services offered by our team to Mayo Clinic: • Threat and Exposure Management o External attack surface discovery o Vulnerability Threat Monitoring and Triage • Continuous Vulnerability Scanning o Dynamic Application Security Testing o Enterprise Asset Scanning (Servers, Endpoints, Containers, IoT, etc) • Secure Software Development Lifecycle o Static Application Code Scanning o Container lifecycle and vulnerability management o Risk & Exception management Our interns provide essential support to maintain these services and work on tasks to enhance efficiency through automation. This temporary position requires applicants to be available for a duration of 6-12 months, working a minimum of 20 hours per week and a maximum of 40 hours per week. This is a remote position within the United States. Mayo Clinic will not sponsor or transfer visas for this position including F1 OPT STEM. Why Mayo Clinic Mayo Clinic is top-ranked in more specialties than any other care provider according to U.S. News & World Report. As we work together to put the needs of the patient first, we are also dedicated to our employees, investing in competitive compensation and comprehensive benefit plans – to take care of you and your family, now and in the future. And with continuing education and advancement opportunities at every turn, you can build a long, successful career with Mayo Clinic. Benefits Highlights - Medical: Multiple plan options. - Dental: Delta Dental or reimbursement account for flexible coverage. - Vision: Affordable plan with national network. - Pre-Tax Savings: HSA and FSAs for eligible expenses. - Retirement: Competitive retirement package to secure your future. Just as our reputation has spread beyond our Minnesota roots, so have our locations. Today, our employees are located at our three major campuses in Phoenix/Scottsdale, Arizona, Jacksonville, Florida, Rochester, Minnesota, and at Mayo Clinic Health System campuses throughout Midwestern communities, and at our international locations. Each Mayo Clinic location is a special place where our employees thrive in both their work and personal lives. Learn more about what each unique Mayo Clinic campus has to offer, and where your best fit is. Equal Opportunity All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, gender identity, sexual orientation, national origin, protected veteran status or disability status. Learn more about the "EOE is the Law". Mayo Clinic participates in E-Verify and may provide the Social Security Administration and, if necessary, the Department of Homeland Security with information from each new employee's Form I-9 to confirm work authorization.

United States
Job Closed