Information Assurance Engineer / ISSO

Onyx Consulting Services

Washington (District of Columbia)

Hybrid

USD 120,000 - 160,000

Full time

7 days ago
Be an early applicant
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Job summary

Onyx Consulting Services is seeking an experienced Information Assurance Engineer / ISSO to support a Federal Government customer. The role focuses on protecting government information systems through implementing and managing cybersecurity controls across cloud and on-prem environments.

The candidate will collaborate with system owners, engineers, and leadership to ensure compliance with RMF, NIST and FedRAMP requirements throughout the system lifecycle.

Qualifications

  • Bachelor’s degree in Computer Science, Information Technology, Cybersecurity, or related discipline.
  • 6+ years ISSO/Information Assurance experience.
  • CompTIA Security+ or equivalent DoD-approved cybersecurity certification.
  • Relevant certifications such as CAP CIS MCISA GIAC or equivalent DoD-approved certs.
  • Experience with RMF, NIST SP 800-37/53, FISMA, and FedRAMP.
  • Experience across cloud and on-premises environments with stakeholders.

Responsibilities

  • Develop, maintain, and implement cybersecurity policies, standards, procedures, and communications.
  • Design and implement security controls for information systems, applications, and networks.
  • Conduct security assessments and remediate findings; track compliance with NIST/FISMA/FedRAMP.
  • Participate in incident response planning, testing, and documentation.
  • Monitor security tools, logs, and events; support audits and remediation efforts.
  • Develop, maintain, and monitor POA&Ms; report status to leadership.

Skills

ISSO/Information Assurance experience
Security certifications
Analytical and communication skills
Stakeholder collaboration

Education

Bachelor’s degree in Computer Science / IT / Cybersecurity

Tools

eMASS

Job description

Job Description Information Assurance Engineer / ISSOClearance: US Citizen required; Ability to obtain and maintain a Public Trust clearanceExperience: 6+ years of ISSO/Information Assurance experienceEducation: Bachelor’s degreeCertification: CompTIA Security+ or equivalent approved cybersecurity certificationWork Environment: Federal Government / Cloud & Enterprise IT EnvironmentCandidate must go onsite daily for 5 weeks for orientation to culture and team.Hybrid schedule is determined by customer; it will transition to 3 days onsite and 2 days remote.

Position Overview

Onyx is seeking an experienced Information Assurance Engineer / Information System Security Officer (ISSO) to support a Federal Government customer.The Information Assurance Engineer/ISSO will help protect the confidentiality, integrity, and availability of government information systems by supporting the implementation, assessment, and continuous management of cybersecurity controls.This position will collaborate with system owners, engineers, cybersecurity professionals, and program leadership to support secure system operations and compliance with applicable federal cybersecurity requirements throughout the system lifecycle.

Key Responsibilities
  • Cybersecurity Policy & Governance Support the development, maintenance, and implementation of cybersecurity policies, standards, procedures, strategies, and communications. Support security activities in accordance with applicable federal cybersecurity requirements, including NIST SP 800-37, NIST SP 800-53, and FISMA. Apply organizational policies, directives, procedures, and security guidelines to assigned systems and environments.
  • Security Architecture & Implementation Support the design and implementation of security controls for information systems, applications, and networks. Develop and maintain security documentation aligned with federal cybersecurity requirements. Support cybersecurity activities across cloud and on-premises environments. Work with technical and program stakeholders to address security requirements throughout the system lifecycle.
  • Security Assessments & Compliance Conduct or support security assessments and vulnerability reviews. Identify security weaknesses and assist with developing appropriate mitigation strategies. Support compliance activities associated with NIST, FISMA, and FedRAMP requirements. Collaborate with stakeholders to track and remediate security findings.
  • Incident Response Participate in cybersecurity incident response activities. Support the development and testing of incident response plans and playbooks. Assist with the investigation, documentation, and resolution of security incidents.
  • Continuous Monitoring Monitor security tools, system logs, and network activity for potentially suspicious activity. Analyze security alerts and available data for indicators of compromise. Support continuous monitoring and cybersecurity assessment activities. Assist with internal and external cybersecurity audits and remediation efforts.
  • POA&M Management Develop, maintain, and monitor Plans of Action and Milestones (POA&Ms). Track remediation activities through completion. Provide status updates and security-related reporting to program/customer leadership.
Required Qualifications
  • Bachelor’s degree in Computer Science, Information Technology, Cybersecurity, or a related discipline.
  • 6+ years of Information System Security Officer (ISSO), Information Assurance, or closely related cybersecurity experience.
  • CompTIA Security+ certification or equivalent DoD-approved cybersecurity certification.
  • Relevant cybersecurity certifications such as: CAP CIS MCISA CompTIA Security+ GIAC certifications Equivalent DoD-approved certifications.
  • Demonstrated experience supporting information security programs within the Federal Government or another highly regulated environment.
  • Working knowledge of the NIST Risk Management Framework (RMF).
  • Knowledge of: NIST SP 800-37, NIST SP 800-53, FISMA, FedRAMP.
  • Experience with enterprise security technologies such as: Firewalls, Intrusion Detection/Prevention Systems (IDS/IPS), Security Information and Event Management (SIEM), Encryption technologies, Identity and Access Management (IAM), Authentication protocols.
  • Strong analytical, problem-solving, organizational, written, and verbal communication skills.
  • Ability to work effectively with technical teams, system owners, security professionals, and program stakeholders.
Preferred Qualifications
  • Experience supporting cloud security initiatives within AWS, Microsoft Azure, or Microsoft Government Cloud environments.
  • Experience supporting Authorization to Operate (ATO) packages and RMF lifecycle activities.
  • Experience using Enterprise Mission Assurance Support Service (eMASS).
  • Experience supporting Security Control Assessments (SCAs).
  • Knowledge of vulnerability management tools and Continuous Diagnostics and Mitigation (CDM) practices.
Equal Employment Opportunity

Onyx is an equal opportunity employer. Employment decisions are made based on qualifications, skills, experience, business requirements, and other lawful considerations. We are committed to providing equal employment opportunities to qualified applicants without regard to legally protected characteristics in accordance with applicable federal, state, and local laws.

Company Description

Onyx Consulting Services, LLC is a technology consulting firm delivering mission-focused IT solutions to the Federal Government. Since 2007, we have partnered with federal agencies to provide expertise in cybersecurity, systems engineering, software engineering, and data management, supporting some of the nation's most critical missions.At Onyx, our employees are our greatest asset. We foster a collaborative, inclusive, and growth-oriented environment where talented professionals can make a meaningful impact while advancing their careers.Onyx is a certified Woman-Owned Small Business (WOSB) and HUBZone-certified company, committed to delivering exceptional service, technical excellence, and innovative solutions to our government customers.

Company Description

Onyx Consulting Services, LLC is a technology consulting firm delivering mission-focused IT solutions to the Federal Government. Since 2007, we have partnered with federal agencies to provide expertise in cybersecurity, systems engineering, software engineering, and data management, supporting some of the nation's most critical missions.At Onyx, our employees are our greatest asset. We foster a collaborative, inclusive, and growth-oriented environment where talented professionals can make a meaningful impact while advancing their careers.Onyx is a certified Woman-Owned Small Business (WOSB) and HUBZone-certified company, committed to delivering exceptional service, technical excellence, and innovative solutions to our government customers.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Information System Security Officer 1 at Onyx Point, Inc. Annapolis Junction, MD
Information System Security Officer 1 at Onyx Point, Inc. Annapolis Junction, MD

Onyx Point, Inc. • Maryland

On-site
USD 78,000 - 250,000
Health insurance
401(k) plan with company match
Paid time off
+4
ISSO I — RMF/NIST Specialist, TS/SCI, Remote
ISSO I — RMF/NIST Specialist, TS/SCI, Remote

Onyx Point, Inc. • Maryland

On-site
USD 78,000 - 250,000
ISSO Information Assurance Engineer – Federal Cloud
ISSO Information Assurance Engineer – Federal Cloud

Onyx Consulting Services • Washington

Hybrid
USD 120,000 - 160,000
Information Systems Security Officer (ISSO)
Information Systems Security Officer (ISSO)

8 Consulting LLC • Washington

Hybrid
USD 110,000 - 170,000
ISSO - (Active TS/SCI Clearance with Full Scope Poly Required)
ISSO - (Active TS/SCI Clearance with Full Scope Poly Required)

J&T • Maryland

On-site
USD 140,000 - 190,000
Health Insurance
Dental and Vision Insurance
Life Insurance
+5
Information Security Systems Officer (ISSO)
Information Security Systems Officer (ISSO)

Isys Technologies • Boulder (CO)

On-site
USD 150,000 - 190,000
Senior Information Systems Security Officer
Senior Information Systems Security Officer

Data Intelligence LLC • Vienna (VA)

On-site
USD 83,000 - 96,000
Information System Security Officer - TS/SCI (req-290)
Information System Security Officer - TS/SCI (req-290)

Cathexisfederal • Tysons (VA), Northern (KY)

Hybrid
USD 125,000 - 190,000
Performance Bonuses
Medical Insurance
Dental Insurance
+2
Information Systems Security Officer (ISSO)
Information Systems Security Officer (ISSO)

Dynamic Solutions Technology LLC • Washington

Hybrid
USD 120,000 - 170,000
Information System Security Officer - TS/SCI (req-290)
Information System Security Officer - TS/SCI (req-290)

CATHEXIS • Tysons (VA)

On-site
USD 125,000 - 190,000
Performance Bonuses
Medical Insurance
Dental Insurance
+11