Information System Security Officer

INADEV Corporation
Reston, VA, United States
about 1 month ago
Apply on www.indeed.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
5 years minimum
Compensation
$200,000.0 - $220,000.0
Working hours
Regular working hours
Job source

Tech stack

Amazon Web Services Cloud Computing Information Security Management CIS Benchmarks Devsecops Security Orchestration, Automation & Response Plan of Action and Milestones

Job description

The Information System Security Officer (ISSO) is responsible for maintaining the security posture and authorization of the system. You will manage the Risk Management Framework (RMF) lifecycle, maintain ATO documentation and continuous-monitoring artifacts, and ensure the system remains compliant with NIST 800-53 and federal security requirements., * Maintain the system’s Risk Management Framework (RMF) documentation and ATO package

  • Manage security control implementation evidence against NIST 800-53 / FedRAMP
  • Track and remediate findings via POA&Ms and coordinate continuous monitoring
  • Support security assessments, audits, and authorization activities
  • Coordinate with the client ISSM, security teams, and DevSecOps on compliance
  • Review changes for security impact and maintain security baselines
  • Report security posture, risks, and incidents to program and client stakeholders

PHYSICAL DEMANDS:

  • Reasonable accommodations may be made to enable individuals with disabilities to perform the essential functions

Inadev Corporation does not discriminate against qualified individuals based on their status as protected veterans or individuals with disabilities and prohibits discrimination against all individuals based on their race, color, religion, sex, sexual orientation/gender identity, or national origin

INTEGRITY AND COMPLIANCE NOTICE:

All information provided by applicants must be complete, truthful, and accurate. Any intentional misrepresentation of skills, experience, credentials, or identity may result in removal from consideration for this and future employment opportunities.

For positions supporting U.S. federal government contracts, applicants may be subject to background investigations and employment eligibility verification in accordance with federal regulations. Providing false information during this process may be subject to review and action as required under applicable federal laws and security regulations.

Inadev is proud to be an Equal Opportunity Employer and a federal contractor committed to compliance with all applicable EEO, OFCCP, and federal hiring standards.

Requirements

  • Must be a U.S. Citizen.
  • Must be willing to work a HYRBID Schedule (2 Days) in Reston, VA & client locations in the Washington D.C. area as required.
  • Ability to pass a 7-year background check and obtain/maintain a U.S. Government Clearance
  • Strong communication and presentation skills.
  • Must be able to prioritize and self-start.
  • Must be adaptable/flexible as priorities shift.
  • Must be enthusiastic and have passion for learning and constant improvement.
  • Must be open to collaboration, feedback and client asks.
  • Must enjoy working with a vibrant team of outgoing personalities., * CISSP, CAP, or equivalent security certification
  • 5+ years of information system security / ISSO experience
  • Strong knowledge of RMF, NIST 800-53, and federal ATO processes
  • Experience with continuous monitoring and POA&M management

Preferred Qualifications:

  • FedRAMP and cloud (AWS) security experience
  • Financial-regulatory security experience
  • Experience with security automation and GRC tooling

Benefits & conditions

11921 Freedom Drive, Reston, VA 20190 $200,000 - $220,000 a year - Full-time

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.indeed.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

2:27 min

Introduction to WebAssembly in a cloud computing context

Edo Edo · World Congress 2024

2:15 min

Auditing container configurations against CIS benchmark security standards

Madhu Akula · LIVE

1:15 min

Key lessons learned from implementing automated mobile DevSecOps

Moataz Nabil Moataz Nabil · LIVE

1:45 min

Transitioning from software development to security roles

Stefania Chaplin · World Congress 2022

2:07 min

Integrating security practices for devsecops adoption

Nevelina Aleksandrova · LIVE

2:57 min

Securing team and management buy-in for DevSecOps adoption

Moataz Nabil Moataz Nabil · LIVE

Videos

See all

Related articles

See all