Information System Security Officer

XPECT Solutions Inc.
Arlington, VA, United States
6 days ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
5 years minimum
Working hours
Regular working hours

Tech stack

Agile Methodology Amazon Web Services Audit Trail Microsoft Azure Cloud Computing Security Cyber Security Information Systems Information Security Management Zero Trust Network Access Software Vulnerability Management Webinspect Information Security Management System
+9 more
Google Cloud Containerization Information Technology Patch Management Nessus Devsecops Qualys Plan of Action and Milestones Vulnerability Analysis

Job description

XPECT Solutions seeks an experienced Information Systems Security Officer (ISSO) to lead compliance and security operations for government information systems. In this role, you will navigate the full NIST Risk Management Framework, ensure adherence to NIST 800-53 controls and DHS 4300A requirements, and oversee continuous authorization and monitoring activities. You will partner with Government Security Assurance Management teams, IT Program Managers, and security operations centers to protect critical systems and maintain compliance posture. This role demands deep technical security expertise, regulatory knowledge, and the ability to communicate complex security concepts to diverse stakeholders.

Core Responsibilties (to include but not limited to):

Risk Management Framework & Authorization

  • Participate in all phases of the NIST 800-37 Risk Management Framework (Prepare, Categorize, Select, Implement, Assess, Authorize, Monitor)
  • Ensure systems comply with NIST 800-53 security controls and DHS 4300A requirements
  • Prepare comprehensive security documentation and collect security artifacts in advance of assessments
  • Conduct self-assessments and support Security Control Assessment activities

Security Compliance & Remediation

  • Evaluate effectiveness of proposed solutions to audit findings, Security Control Assessments, and other security weaknesses
  • Perform root cause analysis of audit findings and security incidents
  • Develop requirements for security control remediation activities
  • Review vulnerability scans from security assessment tools (Nessus, WebInspect, DbProtect, etc.)
  • Develop security control implementation statements and review supporting procedures and work instructions

Security Documentation & Planning

  • Review and update the System Security Plan (SSP) and supporting security documentation
  • Work with Government Security Assurance Management (SAM) on Plan of Action and Milestones (POA&M) closure requests
  • Prepare status reports on security control accuracy and completeness
  • Interpret security principles and requirements for remediation plans
  • Brief Security Assurance Management and support teams on security posture and remediation strategies

Configuration & Change Management

  • Perform security impact analysis of proposed configuration changes
  • Review security implications of system changes with Government IT Program Managers (ITPMs) and support staff

Continuous Monitoringg & Ongoing Operations

Once a system is operational, the ISSO performs recurring activities-ad hoc, daily, weekly, monthly, quarterly, and annually-documented in the continuous monitoring plan:

  • Support all Authorization to Operate (ATO) and continuous authorization activities
  • Plan of Action and Milestones (POA&M) Management to track identified system weaknesses to resolution
  • Information Security Vulnerability Management (ISVM)-review system scans at least monthly for new weaknesses, missed patches, unauthorized assets, or configuration changes
  • Patch Management to ensure all systems are patched regularly and compliance is maintained
  • Document and monitor any security issues or inconsistencies
  • Review ISVM findings for applicability and create POA&Ms or take corrective action as required
  • Audit Log Monitoring and Event Management-periodically review logs for security incidents, unauthorized access attempts, and anomalous activity
  • Awareness and Training-ensure all system users complete security awareness and role-based security training annually
  • Work with federal product managers to prioritize security-related POA&Ms or enhancements into active sprints and releases
  • Provide 24×7 on-call support for security incidents and escalations
  • Ensure compliance with Zero Trust cybersecurity principles and support agency adoption of zero trust network architectures

Requirements

  • Must Be Able to Obtain Public Trust Level 6C
  • Bachelor’s Degree in Physics, Mathematics, Information Technology, Computer Science, Business, or related discipline
  • Minimum of 5 years of professional experience in cybersecurity, information assurance, or related technical roles.
  • Demonstrable expertise in NIST RMF, NIST 800-53, NIST 800-37, and DHS 4300A requirements
  • Knowledge and experience of information security practices within federal and/or state government environments.
  • Excellent written and oral skills
  • Ability to work on-site in Crystal City, Virginia,1 day per week

Preferred Additional Skills and Qualifications:

  • CISSP, CCSK, GCIH, or other advanced cybersecurity certification
  • Experience with FedRAMP, FISMA, or other federal compliance frameworks
  • Hands-on experience with vulnerability assessment tools (Nessus, WebInspect, Qualys, etc.)
  • Experience in Zero Trust architecture design and implementation
  • Knowledge of cloud security (AWS, Azure, GCP) and containerized environments
  • Experience working with Security Operations Centers (SOCs) and incident response teams
  • Demonstrated success working with Agile/DevSecOps practices and sprint-based development environments

Benefits & conditions

Xpect Solutions, Inc. is a one-of-a-kind employer with a talented team that is cleared at various levels and is certified in dozens of industry-recognized certifications. Our talented staff are the key to our success. They bring the knowledge, experience and technical skills to deliver the best solutions to our customers.

We support our team by providing open communication, win-win partnerships with clients and vendors, a team-oriented culture that supports an employee focus on professional development and growth for a long-lasting and happy career.

We offer a benefits package that is designed to keep our most important assets - our employees - healthy, happy, energized and moving forward. Our philosophy is simple - empower our employees with the benefits, resources and the financial incentives they need to be successful.

Benefits and Perks:

  • A competitive Medical, Dental, and Vision plan
  • Retirement Savings Plan
  • Life Insurance
  • AD&D Insurance
  • Short Term and Long Term Disability Insurance
  • 3 weeks of annual PTO
  • 11 days of Holiday PTO
  • Performance Awards
  • Referral Bonus Plan (of up to $2,500/year)
  • Education Reimbursement/Training (of up to $2,500/year)

About the company

XPECT Solutions, LLC. has built a strong reputation by supporting our clients in meeting their strategic goals and mission objectives. We provide high quality resources for a wide range of IT and security solutions at best-value pricing. Our success is built on a solid foundation of well-vetted, highly technical personnel, a disciplined project management approach, and an overarching commitment to customer service. We develop, test, deploy, and support exceptional solutions that enhance system functionality, while maximizing reliability and availability, and ensure the tightest security.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.clearancejobs.com

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

1:15 min

Key lessons learned from implementing automated mobile DevSecOps

Moataz Nabil Moataz Nabil · LIVE

4:01 min

Finding personal fulfillment in the cybersecurity industry

LIVE

2:09 min

Shifting security left using the DevSecOps approach

Aarno Aukia · LIVE

3:22 min

Transitioning from software engineering to security roles

Anna Oliveira · Coffee With Developers

1:45 min

Transitioning from software development to security roles

Stefania Chaplin · WWC 2022

2:07 min

Integrating security practices for devsecops adoption

Nevelina Aleksandrova · LIVE

Videos

See all

Related articles

See all