Information Security Specialist III
Listed on 2025-12-16
-
IT/Tech
Cybersecurity, Information Security
Overview
(590) Information Security Specialist III — Silver Spring, MD
Company Summary
Arlo Solutions (Arlo) is an information technology consulting services company that specializes in delivering technology solutions. Our reputation reflects the high quality of the talented Arlo Solutions team and the consultants working in partnership with our customers. Our mission is to understand and meet the needs of both our customers and consultants by delivering quality, value-added solutions. Our solutions are designed and managed to not only reduce costs, but to improve business processes, accelerate response time, improve services to end-users, and give our customers a competitive edge, now and into the future.
Position Description
The Information Security Specialist III supports the National Oceanic and Atmospheric Administration (NOAA) Internal Risk Management Program (IRMP), providing advanced technical, analytical, and programmatic expertise in the prevention, detection, and mitigation of insider threats. This key personnel position executes and advances NOAA’s IRMP objectives in compliance with federal security regulations, most notably Executive Order 13587, National Insider Threat Policy, NIST, FISMA, NSPM-33, and agency-specific guidance.
The Information Security Specialist III collaborates with OCIO leadership, the Internal Risk Office, NOAA research teams, and interagency insider threat task forces to strengthen the security posture of NOAA’s classified and unclassified environments.
Location: Hybrid (Silver Spring, MD)
Clearance: Active TS/SCI
Responsibilities and/or Success Factors- Information Security Program Development and Implementation
- Lead the development and implementation of comprehensive information security policies, procedures, and protocols for insider threat detection and mitigation
- Design and establish security frameworks that integrate physical security, personnel security, cybersecurity, and information assurance functions
- Develop research security protocols in compliance with NSPM-33 to protect sensitive NOAA research activities from internal and external threats
- Create and maintain security guidelines for handling classified national security information (CNSI) and controlled unclassified information (CUI) Risk Assessment and Analysis
- Conduct comprehensive risk assessments of NOAA's information systems, networks, and data repositories
- Analyze security vulnerabilities and develop mitigation strategies for identified risks
- Evaluate and assess compliance with federal security standards including FISMA, NIST frameworks, and DoD cybersecurity requirements
- Perform security impact assessments for new systems, applications, and processes Security Data Integration and Monitoring
- Consolidate and analyze security data from multiple internal and external sources to identify potential insider threats
- Design and implement data integration systems that provide real-time monitoring and actionable insights to leadership
- Develop and maintain insider threat detection systems and behavioral monitoring capabilities
- Ensure ethical data collection and analysis practices that comply with privacy regulations and civil liberties requirements Incident Response and Investigation
- Coordinate incident response activities for suspected insider threat cases and security breaches
- Conduct thorough investigations of security incidents involving classified systems and sensitive information
- Document incident response actions and develop lessons learned for continuous program improvement
- Collaborate with law enforcement agencies and external partners on complex security investigations Compliance and Audit Management
- Ensure compliance with federal security regulations including Executive Order 13587, NSPM-33, FISMA, and NIST standards
- Conduct regular security compliance audits and assessments
- Prepare detailed compliance reports and corrective action plans for identified gaps
- Maintain documentation for security authorization and accreditation processes Training and Awareness Program Support
- Develop technical training materials and awareness programs focused on insider threat identification and mitigation
- Provide expert consultation on…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).