Information Systems Security Officer (ISSO) - Mid-Level
- Discuss this with your agent
- Open in Claude
- Open in ChatGPT
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Role details
Tech stack
+5 more
Job description
Working in a dynamic federal cybersecurity environment, the ISSO will collaborate with Lead ISSOs, system owners, technical teams, security assessors, program stakeholders, and cybersecurity leadership. The position will provide hands-on technical and compliance support throughout the system lifecycle, quantify technical risk, implement security controls, and execute Risk Management Framework activities supporting Authorization to Operate decisions..
- Execute Risk Management Framework activities supporting ATO, ongoing authorization, and risk-based decisions.
- Implement, assess, document, and monitor security controls throughout the system development lifecycle.
- Conduct system assessments to identify security vulnerabilities, control deficiencies, and compliance gaps.
- Develop, update, and maintain System Security Plans, Configuration Management Plans, Contingency Plans, Incident Response Plans, POA&Ms, and related authorization artifacts.
- Conduct Security Impact Analyses for proposed system, software, infrastructure, and configuration changes.
- Test configuration changes before and after deployment to confirm that required security controls remain effective.
- Support continuous monitoring activities, including vulnerability scanning, control assessments, compliance reviews, remediation tracking, and security-status reporting.
- Develop, manage, and track POA&Ms for identified vulnerabilities and control deficiencies.
- Develop security requirements traceability matrices.
- Maintain and validate hardware and software inventory lists.
- Support cloud security, FedRAMP, and cloud-authorization activities involving AWS, Azure, or comparable platforms.
- Participate in Change Advisory Board reviews and provide cybersecurity recommendations concerning proposed changes.
- Conduct technical vulnerability assessments and coordinate remediation activities with system administrators, engineers, and system owners.
- Prepare audit-support documentation and respond to cybersecurity data calls with timely, accurate information.
- Review and analyze Risk Assessment Reports and FISMA Scorecard information.
- Prepare Security Test Plans at least 90 days before scheduled testing.
- Prepare Security Test Reports within 15 days after testing.
- Generate POA&Ms within 0-15 days after identifying a vulnerability.
- Complete Security Impact Analysis Reports within five business days after receiving change notification.
- Update System Security Plans, Configuration Management Plans, and Contingency Plans annually and whenever significant system changes occur.
- Prepare Weekly Activity Reports and Monthly Program Reports.
- Follow the applicable ISSO Guide, federal cybersecurity requirements, 4300 Series security policies, and component-level directives when developing, updating, or reviewing security artifacts.
- Evaluate and recommend technologies, processes, controls, and practices that protect networks, systems, devices, applications, and data from malicious attacks, damage, or unauthorized access.
- Provide technical guidance, coaching, and work-product reviews for junior cybersecurity personnel when required.
Requirements
- U.S. citizenship is required due to federal contract requirements.
- Bachelor’s degree and at least 10 years of applicable experience, or an equivalent combination of education and experience.
- At least five years of information-security experience.
- Must satisfy the program’s IAT Level III certification requirement by holding at least one of the following active certifications:
- Certified Information Systems Security Professional (CISSP)
- Certified Information Security Manager (CISM)
- CompTIA SecurityX, formerly CASP+
- Demonstrated expertise with the NIST Risk Management Framework, FISMA, NIST SP 800-37, and NIST SP 800-53.
- Experience supporting federal ATO or ongoing-authorization processes.
- Experience developing and maintaining SSPs, POA&Ms, and Contingency Plans.
- Knowledge of applicable 4300 Series security policies and federal cybersecurity requirements.
- Experience with continuous monitoring, vulnerability management, security-control assessments, and remediation tracking.
- Ability to independently address difficult or complex technical and compliance problems with limited supervision.
- Strong technical writing, communication, analysis, organization, and stakeholder-management skills.
- Ability to support the required hybrid work arrangement., * Current or previous federal civilian-agency EOD suitability.
- Active Secret security clearance. A Top Secret clearance is not required.
- Previous federal civilian or Department of Defense cybersecurity experience.
- Experience with CSAM, RegScale, eMASS, Xacta, RiskVision, or comparable governance, risk, and compliance platforms.
- Cloud-security experience involving AWS, Azure, or other cloud platforms.
- Knowledge of FedRAMP and cloud-authorization processes.
- Experience with Nessus, ACAS, Qualys, automated security tools, DevSecOps technologies, or scripting.
- Experience supporting Change Advisory Boards, Security Impact Analyses, Security Test Plans, Security Test Reports, and security requirements traceability matrices.
- Experience leading complex technical activities and coaching or reviewing the work of other cybersecurity professionals., * Bachelor’s (Preferred)
Experience:
- Information security: 10 years (Required)
License/Certification:
- Certified Information Systems Security Professional (CISSP) (Required)
- Certified Information Security Manager (CISM) (Required)
- CompTIA SecurityX, formerly CASP+ (Required)
Work Location: Hybrid remote in Washington, DC 20024
Benefits & conditions
Pulled from the full job description
- 401(k)
- Health insurance
- 401(k) matching
- Vision insurance
- Dental insurance, * 401(k)
- 401(k) matching
- Dental insurance
- Health insurance
- Vision insurance
Apply for this position
This job is hosted externally. Click below to view the full posting and apply.
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Good distractions
Talks and stories from around this role — technically off-topic, practically not.
Moments
Explore playlistsVideos
See allRelated articles
See all
Best Paying Jobs in Technology
Dev Digest 134 - Where pixels sing?
The Overflow: Security and Privacy
Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.