Consulting
Listed on 2026-09-12
-
IT/Tech
Cybersecurity, Information Security & Data Protection, IT Consultant, Network Security
Department of Homeland Security (DHS), Customs and Border Protection (CBP) Security Operations Center (SOC) is a US Government program responsible to prevent, identify, contain and eradicate cyber threats to CBP networks through monitoring, intrusion detection and protective security services to CBP information systems including local area networks/wide area networks (LAN/WAN), commercial Internet connection, public facing websites, wireless, mobile/cellular, cloud, security devices, servers and workstations.
The CBP SOC is responsible for the overall security of CBP Enterprise-wide information systems, and collects, investigates, and reports any suspected and confirmed security violations.
If you're looking for comfort, keep scrolling.
The contractor shall provide a qualified individual(s) to serve as an Information Systems Security Officer (ISSO) with the ability to implement, assess, and maintain NIST SP 800-53 security controls across CBP applications, including systems hosted in FedRAMP authorized cloud service providers (AWS, Azure, GCP) as assigned by the Government Information Systems Security Manager (ISSM). The contractor ISSO must be skilled in supporting ATO packages, continuous monitoring activities, POA&M management, vulnerability remediation, and audit readiness for CBP assessments.
The contractor ISSO must be knowledgeable in Federal, National, DHS and CBP standards, policies, requirements and procedures and shall provide technical security expertise in planning, coordinating, preparing and authoring security authorization documentation necessary to ensure OPR meets all Federal Information Systems Modernization Act (FISMA) regulatory requirements and DHS 4300A Sensitive Systems Policy and CBP 1400-05D Information Security Policy.
The ISSO ensures that the information system complies with applicable security policies, procedures, laws and regulations; create, documents and implements security plans and compliance documentation to enforce Information Assurance principles. In attaining this goal, the contractor shall support the Government Information Systems Security Manager by performing the following duties:
Develop, draft, review and endorse all information systems security plans and other security authorization artifacts and documents such as:
Standards for Security Categorization of Federal Information and Information Systems (FIPS 199) Assessment E-Authentication Determination Privacy Threshold Analysis (PTA) Privacy Impact Assessment (PIA) Risk Assessment Plan System Security Plan (SSP) Configuration Management Plan Contingency Plan Contingency Plan Test and Test Results Section 508 of the Rehabilitation Act Plan Plan of Action & Milestones (POA&Ms) Policy Waiver and Risk Acceptance request Ensure that assigned systems are operated, maintained, and disposed of in accordance with applicable policies and procedures NIST SP 800-37 Rev.
2, Risk Management Framework for Information Systems and Organizations: A System Life Cycle Approach for Security and Privacy, DHS 4300A Policy and Handbook, CBP Information Systems Security Policies and Procedures Handbook (HB 1400-05D), and internal CBP (i.e., Office of Information Technology, Security Operations Division, etc.) security policies and practices. Complete all activities required by the DHS Ongoing Authorization (OA) Program to transition assigned systems into the DHS OA Program and perform all required actions to maintain system authorization under OA once the system is admitted to the Program Assist the Government with the reporting and management of system level security violations and incidents.
Assist the Government with the technical security evaluation of threats and vulnerabilities involving new/enhanced…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).