Information Systems Security Officer

Summary

An Information Systems Security Officer supporting a government customer's security program: driving system accreditation/ATO lifecycle under NIST RMF, maintaining security documentation, tracking POA&Ms, running vulnerability remediation, audits, incident response exercises, and compliance training. Core tech: NIST 800-53, RMF, DISA STIGs, security governance tools like Xacta.

The Opportunity

The ISSO, working closely with the customer’s ISSO, directly supports efforts to plan, coordinate and implement the information security program and system accreditation lifecycle. Responsible for enterprise and system-level cybersecurity engineering tasks. Identifies security risks and integrates required security controls as set forth by policy. Ensures security compliance of information technology applications. Responsible for monitoring security policies and procedures, coordinating internal security audits and security exercises, delivering required security training and participating in coordination meetings.

Key Responsibilities (Principal Duties and Accountabilities *Essential Functions)

  • Primary liaison to customer ISSO to support the system accreditation process and Authorization to Operate (ATO) efforts, audits, and reaccreditation cycles; Utilizes customer’s security governance tool for the system authorization and ATO lifecycle
  • Working closely with engineers, utilizes vulnerability scanning tools and reports to track and remediate findings
  • Evaluates and validates physical security to ensure support of systems security requirements
  • Tracks and manages Plans of Action and Milestones (POA&M’s) that are out of compliance
  • Supports NIST RMF implementation and documentation including annual security control review
  • Coordinates and assists with internal security audits
  • Develops and maintains security documentation such as the System Security Plan, system boundary diagram, inventory of hardware and software, ports and protocols, etc.
  • Develops, coordinates and tests incident response plans, contingency plans and security tabletops/exercises
  • Documents system parameters and ensure all security documents are kept current
  • Asses proposed changes to information systems; identifies risks and impacts; Performs Security Impact Analysis (SIA) and submits change control requests for system enhancements to the ATO package
  • Participates in new technology enhancements and implementations and its implication on the system boundary
  • Assists in testing system function pre and post security control implementations
  • Delivers annual compliance training as mandated by policy and regulatory standard
  • Oversees user account provisioning, permission review, and access enforcement for system integrity
  • Develops and maintains Memorandum of Understanding (MOUs) and Interconnection Service Agreements (ISAs) with internal organizations and external entities to support secure information system interconnections and data sharing
  • Participating in special projects as required
  • Fluency in English (written and spoken)
  • Must have active Secret or higher Security clearance

Education

  • Bachelor’s degree in computer science, information technology or information security, or the equivalent combination of education and work experience

Required Skills, Experience & Abilities

  • 5+ years of experience as an ISSO utilizing the RMF and NIST 800-53 guidelines
  • 5+ years of experience in security engineering and information technology
  • 3+ years of project management experience
  • Proficiency in writing technical analysis reports

Preferred Qualifications

  • Design and implementation of security solutions; Familiarity with security technology tools and applications for secure VPNs, Single Sign-on, Multi-Factor Authentications, etc.
  • Proficient in all facets and implementation of the Risk Management Framework (RMF), NIST 800-53 and DISA STIGs
  • Hands-on experience as an AISSO/ISSO driving successful system authorization and ATOs, and maintenance of system ATOs
  • Hands-on experience utilizing an automated security governance tool (i.e., Xacta, Archangel, etc.)
  • Certifications- CISSP, Security+, CASP+, CAP
  • Information Assurance
  • Cloud-based security principles
  • Project management
  • Agile methodology
  • Nessus and other system vulnerability identification tools
  • Strong problem solving, analytic, and oral/written communication skills
  • Ability to work well independently under pressure and time constraints, in a small team environment

Physical Demands & Work Environment

The physical demands and work environment described are representative of those that an employee encounters while performing the essential functions of this job. Reasonable accommodation may be made to enable individuals with disabilities to perform the essential functions.

  • Capable of lifting and moving information technology equipment up to 50 pounds
  • Ability to work occasional evenings and/or weekends as job duties demand
  • Ability to travel domestically and internationally up to 10% of the time, which may include extended periods of standing, walking, or navigating airports and government facilities.
  • Professional office environment with standard office equipment (computers, phones, printers).

See also

Security jobs by country — openings, pay and top skills →

Tailor your CV for this role?

We couldn't check your fit for this role — add a CV to your profile to see it next time.

A new version of freehire is available