The ISSO is responsible for designing and implementing security solutions to protect sensitive information while ensuring compliance with federal policies. They conduct vulnerability and risk assessments, manage system authorizations, and provide technical evaluations to improve the organization's security posture.
The Information System Security Officer (ISSO) supports work performed under the contract possessing a substantial level of knowledge of federal information system security policy, industry best practices, security control assessments, Plan of Action and Milestones (POA&M) management, system authorizations, configuration management, and system analysis. Responsible for designing and implementing solutions for protecting the confidentiality, integrity, and availability of sensitive information.
Responsibilities:
Serves as a recognized information security expert in the areas of vulnerability assessment, risk assessment, network security, product evaluation, and security implementation.
From a technical perspective the Information System Security Officer is responsible for designing and implementing solutions for protecting the confidentiality, integrity, and availability of sensitive information.
Provides technical evaluations of customer systems and assists with making security improvements.
Participates in the design of information system business impact analysis, system categorization, contingency plans, privacy documents, and other system security documentation to maintain appropriate levels of protection and meet requirements for minimizing operational impact to the enterprise.
Conducts testing and audit log reviews to evaluate the effectiveness of current security measures.
Conducts security product evaluations, and recommends products, technologies, and upgrades to improve the customer’s security posture.
Requirements:
5+ years of relevant experience
Experience with RMF and applying the NIST Cybersecurity Framework.
Possesses substantial knowledge of federal information system security policy, industry best practices, security control assessments, Plan of Action and Milestones (POA&M) management, system authorizations, configuration management, and system analysis
Experience designing and implementing solutions for protecting the confidentiality, integrity, and availability of sensitive information. - A technical expert providing technical support in the areas of vulnerability assessment, risk assessment, network security, product evaluation, and security implementation.
Experience designing and implementing solutions for protecting the confidentiality, integrity, and availability of sensitive information.
Experience using JCAM highly preferred, not required.
Solid understanding and application of NIST Special Publications including SP 800-53
Solid understanding of FISMA audit requirements.
Solid understanding of IT audit requirements.
Ability to work with cooperatively and at a technical level with developers, engineers, and managers on system teams.
Knowledge of computer networking concepts, protocols, and network security methodologies.
Knowledge of risk management processes and tools (e.g., methods and tools for assessing and mitigating risks).
Knowledge of laws, regulations, policies, and ethics as they relate to cybersecurity and privacy in a federal environment.
Knowledge of current and past cybersecurity threats and vulnerabilities.
“I was the first applicant for a remote marketing position that got listed on the company website the same day I applied. Had an interview within 48 hours!”