Information System Security Officer (ISSO)
- Discuss this with your agent
- Open in Claude
- Open in ChatGPT
Role details
Tech stack
+1 more
Job description
Tactibit Technologies provides innovative information technology, cybersecurity, and cloud support services to the Federal Government. We support some of the nation’s most critical and demanding projects including satellite operations, critical infrastructure, and search and rescue. We are a diverse team of hands-on professionals dedicated to solving problems and developing innovative solutions in support of our customers’ critical missions. Our success is dependent on our inclusive, collaborative environment with a shared commitment to excellence in everything we do., We are looking for a talented cybersecurity professional to join our team in Suitland, MD. You will provide information security support for NOAA’s satellite operations missions. You will help develop and maintain effective security and risk management programs on complex government information systems. As an Information System Security Officer, you will be expected to maintain security documentation, communicate and oversee policy changes, and plan and report on security-related initiatives. We expect you to have a passion for cybersecurity and improving overall security posture. You should have a desire to work with satellite data and products for the public and government. Besides, you should be able to perform well working in a team, along with system administrators, engineers and scientists. This position is located at a government facility in Suitland, MD. The position is eligible for a flexible work arrangement.
Information System Security Officer responsibilities are:
- Write and maintain core security documentation including System Security Plans and Contingency Plans
- Plan, manage, and oversee Plans of Actions and Milestone (POA&Ms)
- Coordinate security efforts and improvements with stakeholders including system administrators and operations teams
- Monitor and oversee vulnerability management program including vulnerability scanning, timely patch management, and reporting
- Coordinate security assessment efforts including Security Controls Assessments (SCAs), penetration testing, and risk assessments
- Gather technical artifacts to demonstrate the effectiveness of implemented security controls
- Serve as a principal staff advisor to the System Owner (SO) on all matters involving the security of the information system
- Plan, manage, and coordinate annual system assessment and authorization activities, to include continuous monitoring
- Coordinate incident response, continuity of operations, and similar activities
- Create and maintain documents including Standard Operating Procedures
Requirements
- 8+ years of cybersecurity experience
- CISSP or equivalent certification
- Experience with Federal government environments and concepts including NIST Risk Management Framework, NIST SP 800-53 security controls, and DISA Security Technical Implementation Guides (STIGs)
- Strong problem solving skills and ability to work under pressure
- BS degree in Computer Science, Cybersecurity, or other related area
- Must be a US Citizen and eligible to obtain a security clearance, + Prior experience functioning as Information System Security Officer on federal government systems
- Experience with issue tracking and configuration management systems and processes
- Additional industry certifications such as GIAC certifications, Security+, and others
- Experience with vulnerability management tools including Tenable Nessus
- Experience with continuous monitoring and log management tools including ArcSight, BigFix, ePolicy Orchestrator, and similar tools
- Active Secret security clearance
Apply for this position
This job is hosted externally. Click below to view the full posting and apply.
Apply on www.wayup.comGood distractions
Talks and stories from around this role — technically off-topic, practically not.
Moments
Explore playlistsVideos
See allRelated articles
See all
Dev Digest 134 - Where pixels sing?
9 Ways to Make Money Hacking
Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.
Understanding and Mitigating Common Web Vulnerabilities