Cybersecurity Specialist and ISSO Support - (162)
Job Title
Cybersecurity Specialist and ISSO Support
Job Type
Full-time
Category
Information Technology
Location
FAIRFAX - , VA 22030 US (Primary)
Education
Bachelor's Degree
Travel
0 - 10%
Job Description
You keep federal mission systems authorized and defensible, on premises and in the cloud, with continuous monitoring, POA&M discipline and the evidence an assessor asks for ready before they ask. Full time, W-2, based in Fairfax, Virginia with some telework, starting October 2026.
Why this job exists
SPN Solutions has won a new contract to operate and modernize the information systems behind the Strategic National Stockpile, part of HHS's Administration for Strategic Preparedness and Response (ASPR). The Stockpile holds the nation's reserve of medicines and medical supplies for public health emergencies. When a hurricane, an outbreak or another emergency calls for those supplies, the systems this team runs are how the country knows what it has, where it is and how fast it can move. The platform is Oracle E-Business Suite, and the program is moving it to Oracle Cloud while raising the quality of the inventory data and tightening the integration with the warehouse partners that hold the stock. You would join at the start, on a new team, with real work to own from the first week.
Why people take this job
- A mission you can explain at the dinner table: the nation's emergency medical supplies
- Hybrid in Fairfax, Virginia with some telework, sensible core hours and federal holidays off
- A modern Oracle stack and a real cloud migration, not a maintenance backwater
- A new team being built now: early hires shape how the work is done and grow with it
- Certifications and training paid for, with time set aside to earn them
- A company small enough that the people who run it know your name and answer your messages
What you will do
- Support the Information System Security Officer for the legacy and cloud systems under the NIST Risk Management Framework: control implementation, assessment support and authorization packages.
- Run continuous monitoring: vulnerability scanning, analysis, remediation tracking against federal timelines, and POA&M currency.
- Maintain system security plans, contingency plans, privacy and security artifacts, and assessment evidence.
- Conduct privileged access reviews, audit log review and configuration compliance checks; coordinate patching priorities with the infrastructure team.
- Advise on the security impact of changes before they are made, across on-premises and cloud environments.
- Support incident response, FISMA reporting and audits, and keep compliance evidence current.
What you need
- CISSP (or CISM or CASP+ with equivalent experience).
- 8 or more years in federal cybersecurity, including NIST RMF assessment and authorization and continuous monitoring.
- Hands‑on vulnerability management and POA&M management under NIST SP 800-53.
- Experience supporting an ISSO or serving as one on a FISMA Moderate or High system.
- U.S. citizenship and the ability to obtain an HHS Tier 2 public trust determination.
What sets a candidate apart
- HHS or CDC security programs and tools.
- FedRAMP and cloud security (Oracle Cloud Infrastructure).
- Oracle E-Business Suite and Oracle Database security.
- CAP, CCSP or CEH.
Pay is discussed with you directly when we speak. These are the benefits every full‑time SPN employee receives.
- Medical and prescription coverage, dental and vision, with employer‑subsidized premiums for employees and dependents
- 401(k) with employer match
- Group life insurance at no cost to you
- Short‑term and long‑term disability
- Paid time off, 11 federal holidays, paid sick leave, bereavement leave
- Parental leave
- Certification reimbursement (Oracle, OCI, AWS/Azure, PMP, ITIL, Security+, CISSP and others), an annual training budget and tuition assistance
Terms, and how to apply
- Full time, W-2, salaried (exempt), employed by SPN Solutions
- Target start: October 2026
- Hybrid: based at SPN's office in Fairfax, Virginia, with some telework; occasional days at the customer's Atlanta, Georgia campus when the work requires it
- Core hours 9:00 a.m. to 3:30 p.m. Eastern, Monday to Friday, with flexible start between 6:00 and 9:00 a.m. Eastern; federal holidays off
- You must be a U.S. citizen and obtain and keep an HHS Tier 2 (moderate risk) public trust determination; no security clearance is required
- You complete HHS security, privacy and records management training before access, and cGMP training shortly after you start
- Work is done on customer‑furnished or SPN‑furnished equipment under HHS security rules
SPN Solutions is an Equal Opportunity Employer. All qualified applicants are considered without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability, or protected veteran status. SPN participates in E-Verify.
Keywords: Cybersecurity Specialist, ISSO, Information System Security Officer, NIST RMF, continuous monitoring, POA&M, NIST SP 800-53, FISMA, FedRAMP, vulnerability management, CISSP, assessment and authorization, security plan, HHS, public trust, Fairfax VA, Northern Virginia, hybrid