Information System Security Officer (ISSO)

ZTI Solutions LLC
Fort Meade, MD, United States
about 2 months ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Experienced
Experience required
2 years minimum
Compensation
$150,000.0 - $190,000.0
Working hours
Regular working hours
Job source

Tech stack

Microsoft Azure Cyber Security Identity and Access Management Information Security Management Security Information and Event Management Software Vulnerability Management Information Technology Microsoft Sentinel Vulnerability Analysis

Job description

ZTI Solutions is seeking an Information System Security Officer (ISSO) to support the cybersecurity and Risk Management Framework (RMF) program for a multinational IL5/IL6 collaboration effort in an operational Department of War (DoW) environment hosting multiple Coalition Mission Partner Environments (MPE). This is a hands-on role focused on day-to-day security operations, continuous monitoring, and maintaining the security posture and compliance of assigned systems across multiple enclaves., Clearance: Active Secret required, with the ability to obtain TS/SCI. TS/SCI preferred. The effort spans IL5 work (Secret) and IL6 work on the TS side, which ZTI supports. Citizenship: U.S. Citizen (required). Certification: Active DoD 8140 IAT/IAM Level II or higher. Reports To: Information System Security Manager (ISSM)., The ISSO supports the ISSM in implementing and maintaining the information system security program for assigned systems across classified, multinational, and mission-critical enclaves. The ISSO executes the day-to-day RMF and continuous monitoring activities, maintains system security documentation, tracks vulnerabilities and POA&Ms, and ensures assigned systems remain compliant and operationally secure. The ideal candidate brings solid RMF knowledge, strong attention to detail, and the ability to work closely with the ISSM, infrastructure, operations, and mission partner teams to identify and address risks., * Serve as the ISSO for assigned systems within a secure, multinational DoW environment.

  • Support the ISSM in implementing and maintaining the information system security program and policies.
  • Execute day-to-day RMF and continuous monitoring activities for assigned systems.
  • Maintain and update system security documentation, including SSPs, and supporting RMF artifacts.
  • Track and manage POA&Ms, coordinating timely remediation of findings and risks.
  • Review ACAS vulnerability scan results and coordinate remediation with infrastructure and MPE teams.
  • Support STIG compliance, system hardening, and IAVM remediation efforts.
  • Monitor endpoint security and Trellix alerts for assigned systems and escalate as appropriate.
  • Support security assessments, audits, and authorization activities under the direction of the ISSM.
  • Document and report security incidents and support incident response activities.
  • Monitor the security posture of assigned systems and identify emerging risks.
  • Other duties, as assigned., Engagement: ZTI Solutions is filling this position as a subcontractor on a multinational IL5/IL6 collaboration effort. Final selection is subject to an interview with the prime contractor / customer. Work Requirements: Onsite work required at Ft. Meade, MD - 5 business days per week. No remote work options available. Standard business hours with occasional flexibility for operational needs. About ZTI Solutions, LLC

Requirements

Do you have experience in Vuls?, Do you have a Bachelor’s degree?, * U.S. Citizen.

  • Active Secret security clearance with the ability to obtain TS/SCI (TS/SCI preferred).
  • Active DoD 8140 IAT/IAM Level II or higher certification (e.g., Security+ CE, CySA+, CAP, CISSP).
  • 4+ years of overall IT experience, including at least 2 years of hands-on experience in cybersecurity, RMF, or information assurance in an ISSO or equivalent role.
  • Ability to work full-time, onsite in Ft. Meade, MD, 5 business days per week.
  • Working knowledge of the Risk Management Framework (RMF) and the DoD authorization (A&A) process.
  • Experience maintaining system security documentation, SSPs, and POA&Ms.
  • Experience reviewing ACAS/Tenable scan results and supporting vulnerability remediation.
  • Familiarity with STIG compliance, system hardening, and IAVM remediation.
  • Familiarity with endpoint security (Trellix ESS) and SIEM platforms such as Microsoft Sentinel.
  • Strong attention to detail, organizational, problem-solving, and communication skills., * Bachelor’s degree in Computer Science, Information Security, or another STEM discipline.
  • Active Top Secret clearance with the ability to obtain SCI.
  • Experience supporting systems in a DISA-administered DoW environment.
  • Experience with Azure environments and cloud authorization (e.g., FedRAMP/DoD CC SRG).
  • Experience supporting ATO packages and control implementation statements.
  • Prior experience working alongside an ISSM and cybersecurity engineering teams., Security Clearance: Active Secret clearance required prior to start date, with the ability to obtain TS/SCI; TS/SCI preferred. The effort includes IL5 work (Secret) and IL6 work on the TS side. Applicants must be U.S. Citizens and able to pass a background investigation and maintain clearance.

Benefits & conditions

Pulled from the full job description

  • 401(k)
  • Health insurance
  • Paid time off
  • Vision insurance
  • Dental insurance
  • Paid holidays
  • Career development plan, * Competitive salary commensurate with experience and clearance.
  • Comprehensive medical, dental, and vision coverage.
  • Paid time off and federal holidays.
  • 401(k) retirement plan.
  • Professional development and certification support.
  • Mission-driven work in a classified, high-impact DoW environment.
  • Full benefits package details provided during the offer process.

About the company

ZTI Solutions, LLC was founded in 1997 in Virginia and is classified as a small business. The company is owned and operated by its founder, Rudy Zadnik, who emphasizes moral and business excellence over increasing company profits. This results in a more customer-oriented attitude towards mission accomplishment, as opposed to growing profits or sales.Our approach to consulting and engineering centers around using only highly skilled personnel who are seasoned industry veterans. All employees hold high-level industry and vendor certifications. We offer a comprehensive set of consulting and staff augmentation services, primarily focused on networking and security consulting in the classified space.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on indeed.com

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

1:06 min

Outline of free tools for Microsoft Azure

Radu Vunvulea Radu Vunvulea · WWC 2022

4:11 min

Introduction to cloud-native application developer security

Micah Silverman · WWC 2022

4:01 min

Finding personal fulfillment in the cybersecurity industry

LIVE

5:01 min

Container hosting options available on Microsoft Azure

Federico Fregosi · WWC 2022

3:44 min

Current industry adoption and future security initiatives

Alexander Allmendinger · LIVE

1:53 min

Transitioning toward DevSecOps with dynamic scanning and secrets management

Christoph Ruggenthaler · LIVE

Videos

See all

Related articles

See all