Senior Information System Security Officer (ISSO)
Embedded Alliance, Inc.
Gaithersburg, MD, United States
about 2 months ago
- Discuss this with your agent
- Open in Claude
- Open in ChatGPT
Role details
Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
3 years minimum
Compensation
$145,000.0 - $190,000.0
Working hours
Regular working hours
Job source
Tech stack
Xacta
Disaster Recovery
Information Security Management
Zero Trust Network Access
Software Vulnerability Management
Patch Management
Nessus
Splunk
Servicenow
Vulnerability Analysis
Job description
- A&A Leadership: Initiate, coordinate, and execute all Risk Management Framework (RMF) and A&A renewal activities in direct coordination with NGA Designated Authorization Officials (DAO/DAOR).
- Vulnerability Management: Oversee scanning, analysis, and remediation verification across three distinct classification enclaves using Nessus and Tenable-ACAS.
- Documentation & Records: Develop and maintain critical security artifacts-including System Security Plans (SSPs), Security CONOPS, IT Disaster Recovery (ITDR) plans, and POA&Ms utilizing XACTA-360 and ServiceNow.
- Cross-Functional Collaboration: Partner with System Engineers, Administrators, Lab Teams, and leadership to drive security process improvements and evaluate secure software/hardware integrations.
- Incident & Tasking Response: Rapidly address cybersecurity notices, orders, and directives in accordance with NGA vulnerability and patch management processes.
- Architecture Evaluation: Assess the effectiveness of defense-in-depth architectures and Zero Trust policy implementations against emerging threats.
Requirements
Do you have experience in Vuls?, Do you have a Bachelor’s degree?, * Clearance: Active TS/SCI with Polygraph (US Citizenship required).
- Education & Experience: Bachelor’s degree with 8-12 years of relevant cybersecurity/information assurance experience.
- Framework Expertise: Proven understanding and hands-on application of ICD-503 and the Risk Management Framework (RMF).
- Technical Toolset: Experience with XACTA/XACTA-360, ACAS, Nessus, and SPLUNK., * Direct experience supporting the National Geospatial-Intelligence Agency (NGA) or broader Intelligence Community (IC).
- Active CISSP or CISM certification.
- 3+ years of deep-dive experience analyzing and resolving vulnerability scan results using Tenable Security Center / Nessus.
Benefits & conditions
Pulled from the full job description
- Referral program
- Parental leave
- 401(k)
- Health insurance
- Retirement plan
- 401(k) matching
- Paid time off, We combine a mission-first mindset with agile innovation. Here, you aren’t just a number you are a critical asset to national security. We offer competitive compensation, a collaborative culture, and the opportunity to work on the cutting edge of sustainment., * 401(k)
- 401(k) matching
- Dental insurance
- Health insurance
- Life insurance
- Paid time off
- Parental leave
- Referral program
- Retirement plan
- Vision insurance
Apply for this position
This job is hosted externally. Click below to view the full posting and apply.
Apply on indeed.comGood distractions
Talks and stories from around this role — technically off-topic, practically not.
Moments
Explore playlistsVideos
See allRelated articles
See all
CH
Chris Heilmann
almost 2 years ago
DC
Daniel Cranney
The Overflow: Security and Privacy
5 months ago
BB
Benedikt Bischof
Walking Into The Era of Supply Chain Risks
about 4 years ago
DC
Daniel Cranney
Understanding and Mitigating Common Web Vulnerabilities
over 1 year ago
LM
Luis Minvielle
9 Ways to Make Money Hacking
about 2 years ago
DC
Daniel Cranney
Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.
6 months ago