Information System Security Officer (ISSO)

Andy Frain Services, Inc.
Washington, DC, United States
16 days ago
Apply on www.careerjet.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Working hours
Regular working hours

Tech stack

Microsoft Windows Microsoft Antivirus Systems Engineering Microsoft Azure Cloud Computing CompTIA Security+ Cyber Security Information Systems Information Security Management Microsoft Security Essentials Cloud Services Zero Trust Network Access
+12 more
Security Software Software Vulnerability Management Cloud Platform System Okta Software Security Microsoft InTune Palo Alto Networks Tenable Nessus Splunk Qualys Servicenow Plan of Action and Milestones

Job description

The ISSO will provide senior-level, hands-on cybersecurity support for assigned federal information systems and will be qualified to assume Lead ISSO responsibilities during scheduled or unscheduled absences. The position will support Risk Management Framework (RMF), authorization, continuous monitoring, vulnerability management, POA&M management, audit readiness, and cybersecurity compliance activities across enterprise and cloud environments. The Senior ISSO will work closely with the Lead ISSO, Government ISSM, System Owners, technical teams, assessors, and other cybersecurity stakeholders to maintain system security posture, develop and maintain authorization artifacts, track remediation activities, review security controls and evidence, and support Government cybersecurity reviews and audits. Candidates with a combination of federal RMF/ISSO experience, a recognized cybersecurity certification, and Microsoft security certifications will be strongly preferred., You will be able to use these resources to investigate technical issues, validate security approaches, reproduce and assess configurations, evaluate emerging technologies, and develop practical solutions to security and compliance challenges. The position offers an opportunity to lead not only the execution of RMF activities, but also to help shape the technical approaches, processes, tools, and practices used by the cybersecurity team. Technical Environment and Professional Resources You will be supported by capabilities beyond those normally available to an embedded ISSO team, including:

  • Access to a dedicated cybersecurity and engineering laboratory for testing, validation, prototyping, and technical investigation
  • Reach-back access to experienced cybersecurity, cloud, network, systems, identity, application, and infrastructure SMEs
  • Opportunities to work directly with engineers to translate security findings and control requirements into implementable technical solutions
  • Ability to evaluate and test security tools, configurations, architectures, and remediation approaches outside of the production environment
  • Access to organizational lessons learned, technical expertise, reusable engineering approaches, and cybersecurity research developed across other federal programs
  • Opportunity to help mature the team’s RMF, continuous monitoring, vulnerability management, security engineering, and automation practices
  • Ability to influence the technical direction and operating model of a growing federal cybersecurity team, Job Summary: Provide security detail as outlined in the post orders and establish working relationships with customers, local law enforcement and fire departments. Security person…
  • 2 days ago, Job Summary: Provide security detail as outlined in the post orders and establish working relationships with customers, local law enforcement and fire departments. Security person…
  • 2 days ago +

Requirements

  • Experience supporting cybersecurity, information assurance, or ISSO activities in a federal environment
  • Hands-on experience with FISMA, NIST RMF, NIST SP 800-53, FedRAMP, ATO packages, SSPs, continuous monitoring, vulnerability management, and POA&M management
  • Experience supporting FISMA Moderate systems, major applications, general support systems, or FedRAMP-authorized cloud services
  • Working familiarity with cybersecurity tools and platforms such as CSAM, ServiceNow, Splunk, Tenable Nessus or Qualys, Microsoft Defender, Azure, Microsoft 365, Entra ID, Intune, Okta, Palo Alto, and Zscaler
  • Strong technical writing, documentation, risk analysis, and stakeholder communication skills
  • Must be a U.S. Citizen
  • Must be eligible to successfully complete and maintain a Tier 4 background investigation

Microsoft Certifications One or more Microsoft security certifications is required

  • SC-500 - Microsoft Certified: Cloud and AI Security Engineer Associate
  • SC-300 - Microsoft Certified: Identity and Access Administrator Associate
  • SC-200 - Microsoft Certified: Security Operations Analyst Associate
  • SC-100 - Microsoft Certified: Cybersecurity Architect Expert
  • Other relevant Microsoft Azure, Microsoft 365, security, identity, or compliance certifications

Cybersecurity Certifications One or more of the following is highly desirable:

  • CISSP
  • CompTIA Security+
  • CISM
  • CGRC / CAP
  • CCSP
  • Similar recognized cybersecurity or information assurance certification

Corporate Resources Unlike traditional ISSO positions that are primarily compliance and documentation focused, this role is backed by a broader cybersecurity and engineering organization. You will have access to a large cybersecurity laboratory environment, engineering resources, and reach-back subject matter experts across cloud, networking, identity, systems engineering, application security, vulnerability management, security operations, and federal cybersecurity compliance.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.careerjet.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

4:01 min

Finding personal fulfillment in the cybersecurity industry

LIVE

2:38 min

Establishing comprehensive monitoring and log management

Michael Eder +1 · LIVE

2:33 min

Introduction to security advocacy and automation testing

Chris Heilmann Chris Heilmann +2 · LIVE

1:45 min

Transitioning from software development to security roles

Stefania Chaplin · World Congress 2022

3:10 min

Correlating dispersed logs using structured request tracing

Michael Eder +1 · LIVE

4:37 min

Architecting single sign-on flows across multiple application domains

Gift Egwuenu · World Congress 2023

Videos

See all

Related articles

See all