Information Systems Security Officer (ISSO)

GRIOT Solutions LLC
United States
28 days ago
Apply on www.indeed.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Compensation
$110,000.0 - $125,000.0
Working hours
Regular working hours
Job source

Tech stack

Artificial Intelligence Cloud Computing Cloud Engineering Cyber Security Computer Literacy Payment Systems Federal Information Processing Standards (FIPS) SAP (Applications) Software Vulnerability Management Data Analytics Devsecops Plan of Action and Milestones

Job description

Griot Solutions is a Service-Disabled Veteran-Owned Small Business focused on AI, data analytics, and technical solutions. We are recruiting an Information Systems Security Officer (ISSO) to serve as proposed key personnel for a Centers for Medicare & Medicaid Services (CMS) federal contract pursuit supporting the Medicare Payment System Modernization (MPSM) environment.

This position is contingent upon contract award and includes participation in proposal and oral-presentation preparation before award.

Position Overview

The ISSO will support security, risk, compliance, and continuous Authority to Operate (ATO) activities across the Medicare Payment System Environment (MPSE).

This role requires enough technical and engineering understanding to evaluate security issues and work effectively with DevSecOps and cloud engineering teams, but it is not primarily a hands-on security engineering or remediation-coding position.

The emphasis is on security process and policy, thoughtful risk-based decision-making, vulnerability prioritization, security risk assessment, stakeholder coordination, and guiding teams through CMS security and compliance requirements.

The successful candidate must be able to determine which security findings require immediate action, which findings may appropriately be deferred through an approved risk-management process, and how to gain stakeholder alignment around those decisions.

What You’ll Do

  • Support continuous Authority to Operate (ATO) compliance across MPSE products and services.
  • Support CMS/HHS Assessment and Authorization (A&A), FedRAMP, and continuous-monitoring activities.
  • Support the development, maintenance, and coordination of authorization and security artifacts, including System Security Plans (SSPs), Security Assessment Plans and Reports (SAP/SAR), Plans of Action and Milestones (POA&Ms), contingency-planning artifacts, and related authorization-package documentation.
  • Evaluate security findings and vulnerabilities using risk, exploitability, operational impact, and applicable CMS/HHS remediation requirements.
  • Help determine which vulnerabilities require immediate remediation and which findings may appropriately be managed through a documented POA&M or other approved risk-management process.
  • Conduct and support security risk assessments and clearly communicate security risks, tradeoffs, and recommendations.
  • Guide delivery teams through security and compliance processes and build stakeholder understanding and buy-in.
  • Coordinate closely with DevSecOps, cloud, platform, delivery, and program stakeholders on security findings and remediation activities.
  • Support continuous monitoring, including review and coordination of vulnerability findings, updated POA&Ms, authorization-package updates, and changes that may affect the system security posture.
  • Support security and compliance reporting and coordination associated with operational or security events.
  • Participate in the team’s shared on-call production-support rotation.
  • Participate in proposal preparation, mock sessions, team preparation, and the CMS oral-presentation process as proposed key personnel., The program operates within a federal security and privacy environment that includes:
  • ATO and A&A
  • FedRAMP
  • FIPS 199 security categorization
  • NIST SP 800-53 and applicable NIST SP 800-171 requirements
  • FIPS 140 validated protections
  • CFACTS
  • POA&M management
  • Continuous monitoring
  • PII and CUI protection
  • HHS/CMS security and privacy policies
  • Security and compliance reporting

The applicable system environment is designated Moderate for confidentiality, integrity, availability, and overall impact under FIPS 199., Work is primarily remote/off-site within the United States. Meetings may occasionally be required at CMS facilities in the Baltimore/Washington metropolitan area.

Performance of contract work outside the United States or its territories requires prior Government approval.

Contingent-Award Notice

This position supports a federal contract pursuit and is contingent upon contract award. Selection for proposal participation or designation as proposed key personnel does not constitute a guarantee of employment or contract award.

Pay: $110,000.00 - $125,000.00 per year

Requirements

  • Demonstrated experience supporting information security governance, risk assessment, security compliance, authorization, or closely related security responsibilities.
  • Practical knowledge of Authority to Operate (ATO), Assessment and Authorization (A&A), continuous monitoring, vulnerability management, and POA&M processes.
  • Ability to assess the operational and security significance of vulnerabilities and make risk-based recommendations regarding remediation, prioritization, and documented deferral.
  • Technical literacy sufficient to evaluate security issues and work effectively with DevSecOps, cloud, platform, and software-engineering personnel.
  • Knowledge of applicable federal security and privacy frameworks and requirements, including NIST, FIPS, FedRAMP, and HHS/CMS security requirements relevant to the work.
  • Experience working in cloud and Agile delivery environments.
  • Strong written and verbal communication skills, including the ability to explain security risks and decisions to technical and nontechnical stakeholders.
  • Ability to build consensus, gain stakeholder buy-in, and guide teams through security processes in a collaborative environment.
  • Ability to reason through ambiguous security scenarios, articulate tradeoffs, and collaborate effectively with other technical and program leaders.
  • Willingness and ability to be proposed as key personnel, participate in proposal and oral-presentation preparation, and perform the role if the contract is awarded.
  • Willingness to participate in a shared on-call production-support rotation.
  • Ability to satisfy applicable CMS/HHS suitability, background-investigation, identity-proofing, and credentialing requirements., The selected candidate must be comfortable representing the proposed team in CMS’s remote, interview-style oral-presentation process. The Government may provide core questions and hypothetical scenarios or solutioning exercises and evaluate both the substance of the response and how the team collaborates to reach its conclusions.

The candidate should be able to think on their feet, communicate security tradeoffs clearly, collaborate visibly with other team members, and explain complex security issues to nontechnical government stakeholders.

Personnel Security & Eligibility

An active security clearance is not currently listed as a requirement for this role. The selected candidate must be authorized to work in the United States and able to satisfy applicable CMS/HHS suitability, background-investigation, identity-proofing, and credentialing requirements, including HSPD-12/PIV requirements where applicable.

The selected candidate must be authorized to work in the United States and able to satisfy applicable CMS/HHS suitability, background-investigation, identity-proofing, and credentialing requirements, including HSPD-12/PIV requirements where applicable., * Are you willing to be proposed as 100% dedicated key personnel and perform the role if the contract is awarded?

  • Do you have professional experience supporting ATO/A&A, continuous monitoring, and POA&M activities?
  • Are you willing to participate in proposal preparation, mock sessions, and a remote CMS oral presentation?
  • Are you able to satisfy applicable CMS/HHS suitability, background-investigation, and credentialing requirements?
  • Are you able to perform the role remotely within the United States and attend occasional Baltimore/Washington-area meetings if required?

Benefits & conditions

$110,000 - $125,000 a year - Full-time

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.indeed.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

4:01 min

Finding personal fulfillment in the cybersecurity industry

LIVE

1:15 min

Key lessons learned from implementing automated mobile DevSecOps

Moataz Nabil Moataz Nabil · LIVE

4:11 min

Introduction to cloud-native application developer security

Micah Silverman · World Congress 2022

1:32 min

Structuring platforms for new services and data analytics

Nevelina Aleksandrova · LIVE

3:22 min

Transitioning from software engineering to security roles

Anna Oliveira · Coffee With Developers

2:09 min

Shifting security left using the DevSecOps approach

Aarno Aukia · LIVE

Videos

See all

Related articles

See all