Information Security Systems Officer

TechSur Solutions
Washington, United States
18 days ago
Apply on www.dice.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
5 years minimum
Working hours
Regular working hours
Job source

Tech stack

Software System Penetration Testing Confluence JIRA Code Review CompTIA Security+ Databases Federal Information Processing Standards (FIPS) Information Security Management Open Source Technology Software Vulnerability Management SolarWinds (Software) Splunk
+6 more
Devsecops Servicenow Plan of Action and Milestones Static Application Security Testing Vulnerability Analysis Dynamic Application Security Testing

Job description

TechSur is seeking an Information System Security Officer to support DOL OCIO/ETA SWARAS security compliance, authorization, continuous monitoring, vulnerability management, POA&M remediation, risk register maintenance, and security documentation. This role serves as the security compliance lead for a FISMA Moderate application ecosystem and coordinates with DOL OCIO cybersecurity stakeholders, application teams, database teams, and program leadership., * Lead SWARAS FISMA Moderate compliance support, including NIST 800-53 controls, NIST 800-171 alignment, FIPS, HSPD-12/PIV, TIC, and DOL security policy compliance.

  • Maintain CSAM artifacts, system security documentation, security/privacy plans, risk registers, POA&Ms, audit responses, and ATO support documentation.
  • Analyze vulnerability scan results, audit findings, penetration testing results, and security control assessments, then coordinate remediation with DevSecOps, DBA, and system owner stakeholders.
  • Track POA&M milestones, remediation timelines, evidence packages, and closure documentation within Government-defined timelines.
  • Support secure SDLC controls, code review evidence, static/dynamic testing evidence, third-party/open-source component tracking, and security release gates.
  • Support incident response requirements, including rapid escalation for PII-related incidents and coordination with DOL OCIO security stakeholders.
  • Provide security input for CPIC reporting, portfolio data calls, continuous monitoring, and governance reviews.

Requirements

  • 5+ years of federal cybersecurity, ISSO, RMF, ATO, or security compliance experience.
  • Hands-on experience with FISMA Moderate, NIST 800-53, RMF, POA&M management, vulnerability management, security documentation, and ATO support.
  • Experience Supporting Department of Labor IT programs is REQUIRED.
  • Experience coordinating remediation across application, database, infrastructure, and DevSecOps teams.
  • Strong understanding of federal security documentation, security control assessment findings, remediation planning, and continuous monitoring.
  • U.S. Citizenship and ability to obtain and maintain DOL Public Trust suitability.
  • Prior DOL OCIO, ETA, CSAM, ATO, or federal civilian ISSO experience.
  • Security+, CISSP, CISM, CAP, CGRC, CEH, or equivalent security certification.
  • Experience with Splunk, ServiceNow, Jira, Confluence, SolarWinds, SAST/DAST, and vulnerability scanning tools.

About the company

TechSur Solutions is a digital services company whose mission is to enable digital transformation for our customers to improve quality and efficiency. Based in the DC metropolitan area, TechSur specializes in advanced cloud services, modernization for both IT structures and applications, leveraging Agile development, and Data Analytics. Since we were formed in August of 2016, we have supported multiple impactful and exciting government programs.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.dice.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

1:45 min

Transitioning from software development to security roles

Stefania Chaplin · World Congress 2022

3:04 min

Database evolution and the funding behind vector databases

Erik Bamberg · LIVE

2:38 min

Establishing comprehensive monitoring and log management

Michael Eder +1 · LIVE

3:05 min

Integrating an assistant application with Jira software

Felix Augenstein · LIVE

4:01 min

Managing application isolation via pluggable database models

Wei Hu Wei Hu · World Congress 2022

3:10 min

Correlating dispersed logs using structured request tracing

Michael Eder +1 · LIVE

Videos

See all

Related articles

See all