Massachusetts Jobs

MassHire JobQuest Logo

Job Information

MIT Lincoln Laboratory Information System Security Officer in Lexington, Massachusetts

The Security Services Department’s overall mission is to identify and counter security threats to the MIT Lincoln Laboratory’s mission of development of game-changing technology in support of National Security, including guarding against compromise by foreign intelligence agencies and insider threats. To accomplish this mission, this department formulates and implements policies, plans, and actions designed to protect facilities against threats of vandalism, accidental destruction, and sabotage; and safeguards personnel, classified and unclassified information systems, personal identifiable information, property, and other assets from exploitation and recruitment by foreign intelligence agencies.

We foster a diverse and inclusive culture where security professionals from a wide range of backgrounds are empowered to solve complex security problems in close collaboration with Laboratory research teams and Government counterparts. Our people are our most important resource, and we encourage a casual and flexible opportunity-filled working environment that is technology-focused. Where mission needs can be met, the Security Services Department encourages flexible schedules and hybrid remote work arrangements.

Who are we?

MIT Lincoln Laboratory is a Federally Funded Research and Development Center (FFRDC) whose mission is research in support of National Security. * Mission - The Security Services Department’s (SSD) overall mission is to identify and counter security threats to the MIT Lincoln Laboratory’s mission of development of game-changing technology in support of national security, including guarding against compromise by foreign intelligence agencies and insider threats. * Culture – We foster an inclusive, opportunity-filled environment of empowered team members from diverse backgrounds.

What will you do?

You will provide cybersecurity support to several independent MIT Lincoln Laboratory’s Special Programs. Core responsibilities include:

⦁ Assist and Support necessary compliance activities (e.g., ensure that cyber system security configurations guidelines are followed, compliance monitoring occurs). ⦁ Continuously validate the organization against cybersecurity policies/guidelines/procedures/regulations/laws to ensure compliance. ⦁ Ensure that plans of actions and milestones or remediation plans are in place for vulnerabilities identified during risk assessments, audits, inspections, etc. ⦁ Promote awareness of security issues among management and ensure sound security principles are reflected in the organization's vision and goals. ⦁ Conduct continuous monitoring and track audit findings and provide countermeasure and mitigation recommendations to ensure that appropriate actions are taken to secure critical R & D data. ⦁ Recommend resource allocations required to securely operate and maintain an organization's cybersecurity requirements. ⦁ Provide technical documents, incident reports, findings from computer examinations, summaries, and other situational awareness information to key stake holders. ⦁ Recognize a possible security violation and take appropriate action to report the incident, as required. ⦁ Assist the Program Managers and the Information System Security Manager (ISSM) in the development and maintenance of System Security Plans (SSP) and associated artifacts such as the Plan of Action & Milestones (POA&M), Risk Assessment Report, and Continuous Monitoring Strategy. ⦁ Ensure systems are operated, maintained, and disposed of in accordance with organization security policies and procedures. ⦁ Provide periodic cybersecurity reviews of network, system, and application vulnerability scanning, configuration assessment, and remediation. ⦁ Lead and align information technology (IT) security priorities with the security strategy. ⦁ Prepare for and participate in periodic organization compliance assessments. ⦁ Interpret patterns of noncompliance to determine their impact on levels of risk and/or overall effectiveness of the enterprise's cybersecurity program.

How will you grow?

You will find significant opportunities to do meaningful work in an environment intentionally designed to be one where you will learn, thrive and belong. * Leadership: Room to advance on your team or to lead cross-functional projects. * Growth Opportunities: Potential for lateral and vertical movement. * Education/Training: Management training, mentorship, in-house and external courses. * Exposure: Engagement with sponsors, stakeholders, Laboratory leadership and other Departments and Divisions. * Community: Participation is encouraged for Laboratory social events, Employee Resource Groups (ERGs), clubs and study groups, volunteering and community service projects.

What you need/Requirements:

To work with MITLL, all employees must meet certain basic requirements.

  • Top-Secret clearance with SCI.

  • Must be a U.S. Citizen.

  • Successfully pass a background check and consent to undergoing a government polygraph examination.

  • Possess a DoD 8570.01-M IAM I baseline certification (e.g. CompTIA Security+), or be able to obtain one within 6 months of hire

  • Demonstrated experience with vulnerability scanning and auditing tools and processes is required

  • Excellent written and verbal communication skills are required

  • Technical experience, skills, and course work completed towards an undergraduate degree, or industry IT certifications may be considered in lieu of education or DoD security experience requirements

  • Demonstrated understanding of the following security frameworks is required:

  • NIST 800-53 / Risk Management Framework (RMF)

  • Intelligence Community Directive (ICD) 503

  • National Industrial Security Program Operating Manual (NISPOM) Chapter 8

  • DoD Manual 5205.07 Volumes 1- 4

    Ideally you will have:

    The Laboratory values experiences from diverse backgrounds and occupations. The most successful candidates will have the following skills and qualifications.

⦁ A minimum of 4 years of IT security experience in DoD cybersecurity is preferred ⦁ Experienced in auditing, configuration and vulnerability management ⦁ Experience and familiarity with multiple operating systems such as Windows Server 2012, 2016, 2019, and 2022 Windows 10 and 11, Red Hat Enterprise Linux, Ubuntu, Mac, etc. ⦁ Experience with virtualization and Cloud technologies is preferred ⦁ Ability to integrate information security requirements into the acquisition process; using applicable baseline security controls as one of the sources for security requirements; ensuring a robust software quality control process; and establishing multiple sources (e.g., delivery routes, for critical system elements). ⦁ Technical experience securing networks and systems utilizing DISA STIGs and/or SRGs is highly desired

At MIT Lincoln Laboratory, our exceptional career opportunities include many outstanding benefits to help you stay healthy, feel supported, and enjoy a fulfilling work-life balance. Benefits offered to employees include:

  • Comprehensive health, dental, and vision plans

  • MIT-funded pension

  • Matching 401K

  • Paid leave (including vacation, sick, parental, military, etc.)

  • Tuition reimbursement and continuing education programs

  • Mentorship programs

  • A range of work-life balance options

  • ... and much more!

Please visit our Benefits page (https://hr.mit.edu/benefits) for more information. As an employee of MIT, you can also take advantage of other voluntary benefits, discounts, and perks (https://hr.mit.edu/benefits/additional) .

Selected candidate will be subject to a pre-employment background investigation and must be able to obtain and maintain a Secret-level DoD security clearance.

MIT Lincoln Laboratory is an Equal Employment Opportunity (EEO) employer. All qualified applicants will receive consideration for employment and will not be discriminated against on the basis of race, color, religion, sex, sexual orientation, gender identity, national origin, age, veteran status, disability status, or genetic information; U.S. citizenship is required.

Requisition ID: [[id]]

#ISSO #Cybersecurity #RMF, #SCI, #TS, #Poly

DirectEmployers