ISSO / Cybersecurity Analyst

Farfield Systems
United States
17 days ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Working hours
Regular working hours
Job source

Tech stack

Microsoft Azure Cloud Computing Cyber Security Information Systems Log Analysis Azure Active Directory Security Information and Event Management Software Vulnerability Management Okta Microsoft InTune Azure Security Center Palo Alto Networks
+6 more
Tenable Nessus Splunk Qualys Servicenow Plan of Action and Milestones Vulnerability Analysis

Job description

Working under the direction of the Lead and Senior ISSOs, you will perform the practical, outcome-driven cybersecurity work that keeps DFC’s 32 information systems authorized and operationally secure. Your responsibilities will span the ISSO support spectrum: creating and updating POA&M entries in CSAM after finding identification; preparing Security Impact Assessments for standard and significant system changes; supporting continuous monitoring activities; producing vulnerability assessment data from Tenable Nessus or Qualys; contributing to audit and assessment evidence packages; documenting corrective actions and RCA findings; and supporting incident response by providing affected-system context from CSAM to incident responders. You will work within defined SLA timelines and contribute to the team’s quality-first delivery culture. This is a full-time, direct-support role - not a coordination function.

Requirements

  • U.S. citizenship required
  • Eligible for and capable of obtaining a Tier 4 High-Risk Public Trust background investigation; suitability adjudication must be completed before being granted privileged or administrative system access
  • Hands-on experience supporting ISSO functions, RMF activities, or cybersecurity operations in a federal IT environment
  • Working familiarity with: CSAM (GRC/authorization-package platform), Splunk (SIEM/log analytics), ServiceNow ITSM modules, Tenable Nessus or Qualys vulnerability scanners, Microsoft Defender for Endpoint/Identity/Cloud/M365, Microsoft Intune and BigFix, Microsoft Azure and M365 security and compliance centers, Microsoft Entra ID, Okta, Palo Alto Panorama, and Zscaler administration consoles
  • Experience creating and managing POA&Ms, supporting vulnerability management workflows, and preparing cybersecurity documentation in a federal GRC platform
  • Ability to meet defined response and deliverable timelines in a fast-paced, audit-sensitive environment
  • Strong attention to detail and commitment to accurate, complete recordkeeping

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.indeed.com

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

4:01 min

Finding personal fulfillment in the cybersecurity industry

LIVE

2:38 min

Establishing comprehensive monitoring and log management

Michael Eder +1 · LIVE

2:33 min

Introduction to security advocacy and automation testing

Chris Heilmann +2 · LIVE

1:45 min

Transitioning from software development to security roles

Stefania Chaplin · WWC 2022

3:10 min

Correlating dispersed logs using structured request tracing

Michael Eder +1 · LIVE

4:37 min

Architecting single sign-on flows across multiple application domains

Gift Egwuenu · WWC 2023

Videos

See all

Related articles

See all