Senior Information System Security Officer
- Discuss this with your agent
- Open in Claude
- Open in ChatGPT
Role details
Tech stack
Job description
Experteer Overview In this Senior ISSO role, you will lead RMF activities to secure FEMA information systems and ensure compliant security posture. You’ll act as the main security liaison for the Cyber Security Division, guiding ATO decisions and security documentation. You will work with system owners and cybersecurity professionals to design and implement controls, contingency and incident response plans, and continuous monitoring. You will help protect mission-critical FEMA data and systems in a fast-paced government environment. This is a chance to influence security posture across multiple programs and drive safe, compliant operations. Compensation / Benefits * Lead RMF activities for ATO decisions, including categorization, control selection, self-assessments, POA&Ms, and continuous monitoring * Develop and maintain System Security Plans (SSPs), control baselines, and inventories * Create and maintain Configuration Management Plans; approve change requests and test config changes * Develop contingency and incident response plans; perform risk and security assessments and vulnerability testing * Design security architectures, requirement traceability, and authorization boundary diagrams; advise leadership on cybersecurity matters * Prepare remediation plans for audit findings; maintain daily FISMA scorecard analysis * Maintain hardware/software inventories; ensure proper access controls for system and facility access * Produce Security Test Plans/reports, Risk Assessment Reports, and periodic program reports to track progress * Research and apply current security tools, techniques, and countermeasures against vulnerabilities Tasks * U.S. Citizenship required * Active Top Secret security clearance required * FEMA EOD suitability or current DHS/FEMA EOD preferred * BS/BA + 15 years of information security experience * IAT Level III qualification: CISSP or CISM or CASP+ * 10+ years in information security * Strong RMF, NIST, FISMA, and DHS 4300 Series knowledge * Experience developing SSPs, POA&Ms, and Configuration Management Plans * Knowledge of NIST SP 800-37/800-53 and DHS 4300 Series requirements Key requirements * flexible time off * robust learning resources * healthcare * retirement benefits * continuing education * time off benefits
Requirements
- Develop contingency and incident response plans; perform risk and security assessments and vulnerability testing * Design security architectures, requirement traceability, and authorization boundary diagrams; advise leadership on cybersecurity matters * Prepare remediation plans for audit findings; maintain daily FISMA scorecard analysis * Maintain hardware/software inventories; ensure proper access controls for system and facility access * Produce Security Test Plans/reports, Risk Assessment Reports, and periodic program reports to track progress * Research and apply current security tools, techniques, and countermeasures against vulnerabilities Tasks * U.S. Citizenship required * Active Top Secret security clearance required * FEMA EOD suitability or current DHS/FEMA EOD preferred * BS/BA + 15 years of information security experience * IAT Level III qualification: CISSP or CISM or CASP+ * 10+ years in information security * Strong RMF, NIST, FISMA, and DHS 4300 Series knowledge * Experience developing SSPs, POA&Ms, and Configuration Management Plans * Knowledge of NIST SP 800-37/800-53 and DHS 4300 Series requirements Key requirements * flexible time off * robust learning resources * healthcare * retirement benefits * continuing education * time off benefits
Apply for this position
This job is hosted externally. Click below to view the full posting and apply.
Apply on us.experteer.comGood distractions
Talks and stories from around this role — technically off-topic, practically not.
Moments
Explore playlistsVideos
See allRelated articles
See all
Dev Digest 134 - Where pixels sing?
Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.
Best Paying Jobs in Technology
Understanding and Mitigating Common Web Vulnerabilities