Information System Security Officer (ISSO)

Hruckus LLC
Mount Rainier, MD, United States
2 days ago
Apply on www.disabledperson.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Experienced
Experience required
2 years minimum
Compensation
$116,000.0 - $140,000.0
Working hours
Regular working hours

Tech stack

Xacta Cyber Security Information Security Management Scrum Methodology Security Content Automation Protocol Information Technology Nessus Splunk Servicenow Vulnerability Analysis

Job description

Position Description: The ISSO will collaborate closely with the ISSE and engineering teams to integrate security controls, conduct vulnerability assessments, manage the continuous security posture of enterprise systems, and support authorization and accreditation processes in compliance with federal laws and regulations., * Assist in the development and maintenance of RMF documentation and artifacts, ensuring proper security controls and safeguards are implemented for all systems.

  • Collaborate with the ISSE and other engineering teams to assess and integrate security controls, providing security guidance for design and implementation efforts.
  • Monitor and manage the security posture of systems, ensuring that security controls are effective and compliant with applicable standards and regulations.
  • Conduct security assessments and audits, identifying vulnerabilities and recommending mitigations to strengthen the overall security posture.
  • Review and maintain security-related documentation, ensuring all system components and information types are clearly described and aligned with security policies.
  • Provide support for security authorization and accreditation processes, ensuring compliance with federal laws and regulations and assisting in the creation of security policies.

Requirements

The ideal candidate is a Washington, DC resident with an active Top Secret clearance with SCI eligibility, DoD 8570.1-M IAT Level II certification, and 6 years of Cyber Security experience, along with proficiency in tools like Nessus and Splunk., * Active Top Secret clearance with SCI eligibility.

  • 6 years of Cyber Security work experience will be considered in lieu of a Bachelors degree
  • Proven ISSO experience across a large-scale enterprise Information Technology (IT) program.
  • Experience with Scrum methodologies.
  • Strong written and verbal communication.
  • Analytical and problem-solving abilities.
  • Teamwork and collaboration.
  • Organizational and multitasking skills.
  • Proficiency with Nessus (ACAS), Splunk, STIGS, and SCAP tools.
  • DoD 8570.1-M IAT Level II certification (e.g., Security+ CE, CAP).

Desired Qualifications:

  • ITILv4 Foundation Certification.
  • Experience with ServiceNow.
  • Proficiency with eMASS and Xacta.
  • DoD 8570.1-M IAT Level III certification (e.g., CISSP or CISM).
  • 2 to 5 years with BS/BA or 0 to 2 years with MS/MA/MBA or 8 to 10 years with no degree.
  • 5 to 8 years with BS/BA or 3 to 5 years with MS/MA or 0 to 2 years with PhD

About the company

Veteran Firm Seeking an Information Systems Security Officer (ISSO) TS SCI for a Onsite Assignment in Joint Base Anacostia-Bolling, Washington, DC

My name is Stephen Hrutka. I lead a Veteran-Owned management consulting firm in Washington, DC. We specialize in Technical and Cleared Recruiting for the Department of Defense (DoD), the Intelligence Community (IC), and other advanced defense agencies.

At HRUCKUS, we support fellow Veteran-Owned businesses by helping them recruit for positions across organizations such as the VA, SBA, HHS, DARPA, and other leading-edge R&D-focused defense agencies.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.disabledperson.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

4:01 min

Finding personal fulfillment in the cybersecurity industry

LIVE

2:38 min

Establishing comprehensive monitoring and log management

Michael Eder +1 · LIVE

1:45 min

Transitioning from software development to security roles

Stefania Chaplin · World Congress 2022

3:10 min

Correlating dispersed logs using structured request tracing

Michael Eder +1 · LIVE

4:19 min

Introduction to network security and endpoint monitoring architectures

Christoph Ruggenthaler · LIVE

5:03 min

Navigating new cybersecurity compliance frameworks and laws

Kurt Eder · LIVE

Videos

See all

Related articles

See all