Senior Information System Security Officer (ISSO)

Farfield Systems
United States
17 days ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Working hours
Regular working hours
Job source

Tech stack

Microsoft Azure Cloud Computing Information Systems Information Security Management Log Analysis Package Development Process Azure Active Directory Security Information and Event Management Software Vulnerability Management Okta Microsoft InTune Azure Security Center
+8 more
Palo Alto Networks Tenable Nessus RSA Archer Platform Splunk Qualys Servicenow Plan of Action and Milestones Vulnerability Analysis

Job description

In this role, you will work alongside the Lead ISSO to support the full RMF system authorization lifecycle across 32 DFC information systems in an environment processing CUI across headquarters and satellite offices. Your day-to-day responsibilities will include developing and maintaining authorization-package artifacts, executing continuous monitoring activities, managing vulnerability findings and POA&Ms in CSAM, supporting security impact assessments for system changes, contributing to audit and assessment evidence production, and participating in DFC governance activities. You will apply deep technical knowledge across the DFC security tool stack - from SIEM and GRC platforms to endpoint security and cloud security controls - to keep DFC systems authorized and audit-ready. These roles are designated Key Personnel.

Requirements

  • U.S. citizenship required
  • Eligible for and capable of obtaining a Tier 4 High-Risk Public Trust background investigation; suitability adjudication must be completed before being granted privileged or administrative system access
  • Demonstrated hands-on experience performing ISSO functions in a federal RMF environment, with the ability to serve as Lead ISSO when required
  • Working familiarity with: CSAM (GRC/authorization-package platform), Splunk (SIEM/log analytics), ServiceNow ITSM modules, Tenable Nessus or Qualys vulnerability scanners, Microsoft Defender for Endpoint/Identity/Cloud/M365, Microsoft Intune and BigFix, Microsoft Azure and M365 security and compliance centers, Microsoft Entra ID, Okta, Palo Alto Panorama, and Zscaler administration consoles
  • Experience with authorization package development, POA&M management, continuous monitoring, vulnerability management, and audit support in a federal cybersecurity context
  • Ability to independently manage ISSO workloads and deliver quality artifacts under defined timelines
  • Must maintain all qualifications, certifications, experience levels, and clearance eligibility throughout the period of performance

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.indeed.com

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

5:03 min

Navigating new cybersecurity compliance frameworks and laws

Kurt Eder · LIVE

2:38 min

Establishing comprehensive monitoring and log management

Michael Eder +1 · LIVE

2:33 min

Introduction to security advocacy and automation testing

Chris Heilmann +2 · LIVE

1:45 min

Transitioning from software development to security roles

Stefania Chaplin · WWC 2022

3:10 min

Correlating dispersed logs using structured request tracing

Michael Eder +1 · LIVE

4:37 min

Architecting single sign-on flows across multiple application domains

Gift Egwuenu · WWC 2023

Videos

See all

Related articles

See all