Information System Security Officer

After School Matters, Inc.
Washington, DC, United States
14 days ago
Apply on testpros.applytojob.com
Prepare application

Role details

Contract type
Contract
Employment type
Full-time (> 32 hours)
Experience level
Experienced
Experience required
3 years minimum
Compensation
$70,000.0 - $145,000.0
Working hours
Regular working hours

Tech stack

Xacta Amazon Web Services Microsoft Azure Configuration Management Cyber Security Security Content Automation Protocol Software Vulnerability Management SARS Software Products Cloud Platform System Information Technology Nessus Qualys
+1 more
Vulnerability Analysis

Job description

The Information System Security Officer (ISSO) supports the cybersecurity and compliance requirements of federal information systems in accordance with NIST, RMF, FISMA, FedRAMP, DoD, and agency-specific security requirements. The ISSO serves as the primary liaison between system owners, cybersecurity teams, and government stakeholders to ensure systems maintain an acceptable security posture and remain compliant throughout the system lifecycle., * Support the implementation and maintenance of Risk Management Framework (RMF) processes.

  • Develop, review, and maintain security documentation, including:
  • System Security Plans (SSPs)
  • Security Assessment Reports (SARs)
  • Plans of Action & Milestones (POA&Ms)
  • Security Control Traceability Matrices (SCTMs)
  • Continuous Monitoring (ConMon) documentation
  • Conduct security control assessments and compliance reviews.
  • Coordinate Authorization to Operate (ATO), Interim ATO (IATO), and authorization package updates.
  • Support vulnerability management activities, including reviewing and tracking findings from tools such as Nessus, ACAS, Tenable, Qualys, and SCAP.
  • Monitor and assess cybersecurity risks and recommend mitigation strategies.
  • Coordinate with system administrators, network engineers, developers, and security personnel to address security requirements.
  • Review system changes and participate in configuration control boards (CCBs) as required.
  • Support audits, inspections, and cybersecurity assessments.
  • Ensure compliance with NIST 800-53, FISMA, agency policies, and applicable federal regulations.
  • Maintain security metrics and provide regular status reports to government stakeholders.
  • Support incident response activities and security investigations when required.

Requirements

  • Bachelor’s degree in Information Technology, Cybersecurity, Computer Science, or related field (or equivalent experience).
  • 3+ years of experience supporting federal cybersecurity, RMF, or information assurance programs.
  • Experience developing and maintaining RMF authorization packages.
  • Working knowledge of:
  • NIST 800-53
  • NIST 800-37
  • FISMA
  • Security Control Assessments
  • Continuous Monitoring
  • Experience with vulnerability scanning and remediation processes.
  • Strong written and verbal communication skills.
  • Active Top Secret or Secret or Pubic Trust clearance or ability to obtain one.

Preferred Qualifications

  • Experience with eMASS, XACTA, CSAM, or similar governance and compliance tools.
  • Knowledge of FedRAMP, DoD RMF, or Intelligence Community security requirements.
  • Experience supporting cloud environments (AWS, Azure, GovCloud).
  • Security certification such as:
  • Security+
  • CISSP
  • CAP
  • CISM
  • GSLC

Desired Skills

  • Risk assessment and mitigation
  • Security compliance and auditing
  • Vulnerability management
  • Cybersecurity policy implementation
  • Security documentation development
  • Stakeholder coordination
  • Continuous monitoring and reporting

Typical Federal Customers: DHS, DoD, VA, HHS, Treasury, and other civilian federal agencies.

Salary Range: $70,000 - $145,000 (depending on experience, clearance level, and location). This range represents a good-faith estimate and is not a guarantee; final compensation is determined by factors such as experience, qualifications, and government contract labor rate requirements and may fall outside the stated range.

Benefits & conditions

Invitation for Job Applicants to Self-Identify as a U.S. Veteran

  • A “disabled veteran” is one of the following:
  • a veteran of the U.S. military, ground, naval or air service who is entitled to compensation (or who but for the receipt of military retired pay would be entitled to compensation) under laws administered by the Secretary of Veterans Affairs; or
  • a person who was discharged or released from active duty because of a service-connected disability.
  • A “recently separated veteran” means any veteran during the three-year period beginning on the date of such veteran’s discharge or release from active duty in the U.S. military, ground, naval, or air service.
  • An “active duty wartime or campaign badge veteran” means a veteran who served on active duty in the U.S. military, ground, naval or air service during a war, or in a campaign or expedition for which a campaign badge has been authorized under the laws administered by the Department of Defense.
  • An “Armed forces service medal veteran” means a veteran who, while serving on active duty in the U.S. military, ground, naval or air service, participated in a United States military operation for which an Armed Forces service medal was awarded pursuant to Executive Order 12985.

About the company

TestPros delivers innovative independent IT assessment solutions to critical challenges facing the nation and the world. We support the U.S. Federal Government and Commercial clients within the continental USA. TestPros is dedicated to making lives better, safer and more secure.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on testpros.applytojob.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

4:01 min

Finding personal fulfillment in the cybersecurity industry

LIVE

1:45 min

Transitioning from software development to security roles

Stefania Chaplin · World Congress 2022

1:13 min

Structuring a comprehensive corporate security organization

Eileen Uchitelle Eileen Uchitelle +1 · Coffee With Developers

Videos

See all

Related articles

See all