ISSO

Indigo It
Fort Liberty, NC, United States
12 days ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
10 years minimum
Working hours
Regular working hours

Tech stack

Xacta Active Directory Cloud Computing Cyber Security Information Systems Information Technology Consulting Intrusion Detection Systems Knowledge Management System Center Configuration Manager Network Monitoring Security Content Automation Protocol Security Software
+8 more
Software Vulnerability Management Workflow Management Systems Identity Services Engine Forescout Information Technology Tenable Nessus Malware Detection Vulnerability Analysis

Job description

Founded in 2001, Indigo IT is an award winning information technology consulting and services company. We are a trusted services provider to government agencies seeking innovative Cloud, Cybersecurity, Knowledge Management, and Enterprise solutions. We know our defense, federal, and civilian customers have critical IT infrastructures that must remain reliable, available, and maximized. Indigo IT is mission focused and committed to maintaining a sense of urgency in anticipating and supporting our customers’ technology goals and objectives. Our unique ability to think beyond today allows our clients to stay ahead of their IT challenges. As a Veteran-Friendly employer, we are proudly partnered with the Virginia Values Veterans (V3) Program, and a recipient of the HIRE Vets Gold Medallion Award, which recognizes our commitment to recruiting our nation’s Veterans. Recognized on the Inc. 5000 list of America’s fastest growing companies in 2020 & 2021 and named as one of the 2022 Best Places to Work in Virginia, we are always looking to hire top talent in the field - come join us today! The ISSO will work to create and maintain the Authority to Operate (ATO) of several information systems within the United States Army Reserve Command (USARC). The ISSO takes direction from a team lead but has reasonable autonomy to seek process improvements and to engage in enterprise and system-level cybersecurity-related engineering tasks. This is an onsite position, and the successful candidate will provide expert level support in the implementation of the Risk Management Framework in accordance with NIST guidance, maintaining security assessment and authorization (SA&A) packages, and supporting operational and technical security capabilities including incident handling, vulnerability scanning, and compliance reporting. ESSENTIAL FUNCTIONS/RESPONSIBILITIES:

  • Create and maintain the Authority to Operate (ATO) for assigned USARC information systems in accordance with the Risk Management Framework (RMF)
  • Perform assessment and authorization (A&A) tasks and prepare/maintain SA&A packages for completeness and compliance with FISMA and other Federal and agency standards
  • Interpret and facilitate the implementation of NIST and Department of War (DoW) cybersecurity guidance
  • Engage in enterprise and system-level cybersecurity-related engineering tasks with reasonable autonomy under the direction of a team lead
  • Document and assess RMF controls, Plans of Action and Milestones (POA&Ms), and vulnerabilities using eMASS and XACTA
  • Read and interpret DoD STIG results from SCAP scans and self-assessment checklists via STIG Viewer, as well as ACAS scan results
  • Support DISA and Army security change request procedures and Cyber Command vulnerability remediation timelines
  • Identify, collect, process, document, and report cybersecurity and incident response events
  • Develop and deliver briefings on system security posture and compliance status to senior management
  • Recommend process improvements to strengthen the organization’s overall security posture

Requirements

  • Working knowledge of common DoW IT and cybersecurity tools, including ACAS, ESS, Trellix, DISA STIGs, Forescout, Cisco ISE, Active Directory, and MECM
  • Proficiency with A&A/RMF workflow tools such as eMASS and XACTA
  • Knowledge of Information Certification & Accreditation Regulations, FISMA, and NIST 800-series guidance, and the SA&A process in alignment with the RMF
  • Experience with DOD 8510 (DIACAP and RMF), DoD 6510 and 8500 series instructions, IAVMs, and related Federal/DoD policies and regulations
  • Familiarity with network monitoring and intrusion/malware detection using host- and network-based intrusion detection systems (IDS) and log management applications
  • Familiarity with vulnerability scanning and management using Tenable Nessus and reviewing scan reports
  • Strong analytical and problem-solving skills for resolving security issues and identifying trends and false positives in operational reports
  • Excellent verbal and written communication skills, including competence in developing and delivering briefings to senior management
  • Strong organizational and time management skills with the ability to balance multiple priorities and complete tasks on time
  • Ability to work independently and as part of a team, and to maintain a professional appearance and demeanor, * Bachelor’s degree in an information technology related field, or a master’s level certification (CISSP, CISM, etc.) in lieu of degree
  • At least ten (10) years of direct experience in computer and systems security
  • Experience performing assessment and authorization tasks within the federal government in accordance with the Risk Management Framework (RMF)
  • Ability to meet DoD 8140 requirements
  • Active Secret security clearance required

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on jobs.localjobnetwork.com

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

4:11 min

Introduction to cloud-native application developer security

Micah Silverman · WWC 2022

1:45 min

Transitioning from software development to security roles

Stefania Chaplin · WWC 2022

3:44 min

Current industry adoption and future security initiatives

Alexander Allmendinger · LIVE

2:07 min

Summarizing critical actions for organizational cybersecurity compliance readiness

Matthew Brady Matthew Brady · WWC Europe 2026

2:59 min

Why existing security and device management tools fail

Marcus Wermuth Marcus Wermuth · WWC Europe 2026

4:27 min

Embracing a new perspective on mobile cyber attacks

Tom Tovar · WWC 2023

Videos

See all

Related articles

See all