Information System Security Officer

Everforth Apex
Oxon Hill, MD, United States
6 days ago
Apply on www.dice.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Starter
Working hours
Regular working hours
Job source

Tech stack

Amazon Web Services Microsoft Azure Cloud Computing Security Configuration Management CompTIA Security+ Information Security Management Smartsuite Software Vulnerability Management Vulnerability Analysis

Job description

We are seeking a Junior Information System Security Officer (ISSO) to join our team. In this role, you will support Senior ISSOs with Risk Management Framework (RMF) compliance and system security. You will be responsible for maintaining security documentation, supporting Authority to Operate (ATO) efforts, and conducting risk and vulnerability assessments to ensure federal systems remain compliant and secure., * Execute Risk Management Framework (RMF) activities to support ATO packages and authorization decisions.

  • Implement and assess security controls in accordance with NIST, FISMA, and DHS requirements.
  • Develop, update, and maintain cybersecurity documentation, including System Security Plans (SSPs), Contingency Plans (CPs), Configuration Management Plans (CMPs), and Plans of Action & Milestones (POA&Ms).
  • Support continuous monitoring activities, conduct system assessments, and manage vulnerability remediation efforts.
  • Perform Security Impact Analyses (SIAs) for system changes and deployments.
  • Assist with cloud security and compliance initiatives.
  • Provide documentation for audits and respond to cybersecurity data calls.
  • Analyze Risk Assessment Reports and FISMA scorecard metrics.

Requirements

  • Must be able to obtain and maintain a DHS/FEMA EOD.
  • Bachelor’s degree and 5+ years of relevant experience, or an equivalent combination of education and experience (Associate’s & 7 years, Master’s & 3 years, or 11 years without a degree).
  • Experience with Risk Management Framework (RMF), FISMA compliance, NIST SP 800-37, and NIST SP 800-53.
  • Experience creating and maintaining SSPs, POA&Ms, and Contingency Plans.
  • Knowledge of DHS 4300 Series requirements.
  • Experience with continuous monitoring and vulnerability management.

Preferred Qualifications

  • Previous experience with DHS or a similar federal agency.
  • Experience with GRC tools such as CSAM, RegScale, or eMASS.
  • Awareness of cloud security concepts (AWS, Azure) and FedRAMP.
  • Relevant security certifications such as CompTIA Security+, CISA, or CISSP.
  • Technical writing and communication skills.

About the company

Everforth Apex is a world-class IT services company that serves thousands of clients across the globe. When you join Everforth Apex, you become part of a team that values innovation, collaboration, and continuous learning. We offer quality career resources, training, certifications, development opportunities, and a comprehensive benefits package. Our commitment to excellence is reflected in many awards, including ClearlyRateds Best of Staffing in Talent Satisfaction in the United States and Great Place to Work in the United Kingdom and Mexico.

Everforth Apex uses a virtual recruiter as part of the application process. Click for more details. By applying for this job, you agree to receive calls, AI-generated calls, text messages, or emails from Everforth Apex and its affiliates, and contracted partners. Frequency varies for text messages. Message and data rates may apply. Carriers are not liable for delayed or undelivered messages. You can reply STOP to cancel and HELP for help. You can access our privacy policy at

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.dice.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

1:06 min

Outline of free tools for Microsoft Azure

Radu Vunvulea Radu Vunvulea · World Congress 2022

1:13 min

Structuring a comprehensive corporate security organization

Eileen Uchitelle Eileen Uchitelle +1 · Coffee With Developers

5:01 min

Container hosting options available on Microsoft Azure

Federico Fregosi · World Congress 2022

4:01 min

Finding personal fulfillment in the cybersecurity industry

LIVE

1:45 min

Transitioning from software development to security roles

Stefania Chaplin · World Congress 2022

2:06 min

Generating embeddings using the OpenAI API

Rainer Stropek Rainer Stropek · LIVE

Videos

See all

Related articles

See all