Information Systems Security Officer
- Discuss this with your agent
- Open in Claude
- Open in ChatGPT
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Role details
Tech stack
+4 more
Job description
TDI is seeking an Information Systems Security Officer (ISSO) to provide expertise needed to align and help mature the organization and technology-specific risk management plans and processes, through the implementation of the Risk Management Framework (RMF). This position is hybrid with commute to the DC area 3 times per week. RESPOSIBILITIES:
- Serve as the primary cybersecurity advisor to the System Owner (SO), Information Systems Security Manager (ISSM), and Chief Information Security Officer (CISO) on all security matters related to assigned information systems.
- Lead and support all phases of the Risk Management Framework (RMF) Security Assessment and Authorization (A&A) process, ensuring assigned systems achieve and maintain a compliant Authority to Operate (ATO).
- Develop, maintain, and update all required RMF security documentation, including System Security Plans (SSPs), Security Impact Analyses (SIAs), Plans of Action and Milestones (POA&Ms), Risk Acceptances, Configuration Management Plans, Supply Chain Risk Management Plans, Interconnection Security Agreements (ISAs), Memorandums of Understanding (MOUs), Information Exchange Agreements (IEAs), vulnerability reports, authorization letters, and other required security artifacts.
- Perform continuous monitoring activities to verify security controls are implemented correctly, operating effectively, and meeting cybersecurity requirements by conducting security control self-assessments, reviewing vulnerability and compliance scan results, validating system log reviews, and ensuring periodic user account reviews are completed.
- Assess the cybersecurity impact of system changes, document findings through Security Impact Analyses, and communicate associated risks and recommendations to stakeholders.
- Identify security control deficiencies, manage the POA&M process, and coordinate remediation efforts with system owners and technical teams to resolve vulnerabilities identified through assessments, audits, inspections, and continuous monitoring activities.
- Collaborate with engineering, operations, and system owners to strengthen the security posture of assigned systems while ensuring compliance with organizational cybersecurity policies and RMF requirements.
- Support internal and external security assessments, audits, and authorization activities by providing required system access, documentation, evidence, and technical guidance.
Requirements
- U.S. Citizenship is required
- Active CISSP, CISM, CRISC, or equivalent cybersecurity certification required.
- Bachelor’s degree in Computer Science, Information Technology, Cybersecurity, or a related technical field.
- 5+ years of experience performing security assessments, developing RMF/A&A documentation, and supporting the authorization of enterprise systems, networks, servers, databases, or cloud environments.
- Working knowledge of NIST Risk Management Framework (RMF), NIST security and privacy publications, and security authorization processes.
- Experience using Archer or a similar governance, risk, and compliance (GRC) platform to support Assessment and Authorization (A&A) activities.
- Understanding of cloud service models (IaaS, PaaS, SaaS), hybrid cloud environments, financial applications, and mobile security technologies.
Benefits & conditions
The anticipated salary range for this position is $110,000 - $135,000. This range is a good-faith estimate and not a guarantee of compensation. Final compensation will be based on factors including experience, education, skills, geographic location, internal equity, market data and applicable contract requirements, and may fall outside the posted range.
TDI does business with the federal government, which restricts employment to individuals who are either US citizens or lawful permanent residents of the United States.
“TDI is an Equal Opportunity Employer. Employment decisions are made based on individual qualifications, merit, and business needs. We do not discriminate in employment opportunities or practices based on race, color, religion, sex, or national origin, in accordance with applicable federal laws.”, Invitation for Job Applicants to Self-Identify as a U.S. Veteran
- A “disabled veteran” is one of the following:
- a veteran of the U.S. military, ground, naval or air service who is entitled to compensation (or who but for the receipt of military retired pay would be entitled to compensation) under laws administered by the Secretary of Veterans Affairs; or
- a person who was discharged or released from active duty because of a service-connected disability.
- A “recently separated veteran” means any veteran during the three-year period beginning on the date of such veteran’s discharge or release from active duty in the U.S. military, ground, naval, or air service.
- An “active duty wartime or campaign badge veteran” means a veteran who served on active duty in the U.S. military, ground, naval or air service during a war, or in a campaign or expedition for which a campaign badge has been authorized under the laws administered by the Department of Defense.
- An “Armed forces service medal veteran” means a veteran who, while serving on active duty in the U.S. military, ground, naval or air service, participated in a United States military operation for which an Armed Forces service medal was awarded pursuant to Executive Order 12985.
About the company
Tetrad Digital Integrity (TDI) is a cybersecurity firm built for high-consequence environments where mission, complexity, and trust intersect. Our single focus has been delivering cyber solutions to effectively manage risk & the business of cyber for 25 years!
Apply for this position
This job is hosted externally. Click below to view the full posting and apply.
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Good distractions
Talks and stories from around this role — technically off-topic, practically not.
Moments
Explore playlistsVideos
See allRelated articles
See all
How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again
Dev Digest 134 - Where pixels sing?
9 Ways to Make Money Hacking
Understanding and Mitigating Common Web Vulnerabilities