Information Security Systems Officer (ISSO)

Guidehouse

Washington (District of Columbia)

On-site

USD 74,000 - 124,000

Full time

8 days ago
Application generator

A complete application in a minute — tailored resume and cover letter, ready to send.

Get past ATS filters

Benefits offered by this job

Medical, Rx, Dental & Vision Insurance
401(k) Retirement Plan
Parental Leave

Job summary

Guidehouse is seeking a skilled cybersecurity professional to support RMF implementation and ongoing authorization activities for U.S. federal systems. You will help categorize systems, tailor NIST SP 800-53 controls, and maintain security documentation across authorization boundaries.

The role requires a Security+ certification and 3+ years of cybersecurity experience, with the ability to obtain a Federal Public Trust. Experience with RMF, NIST SP 800-37/800-53 is preferred.

Qualifications

  • Bachelor’s degree in computer science, information technology, or cybersecurity.
  • Security+ certification required.
  • 3+ years of experience in cybersecurity.

Responsibilities

  • Support RMF implementation across authorization boundaries.
  • Assist in system categorization per FIPS 199 and NIST SP 800-60.
  • Identify and document NIST SP 800-53 r5 controls and tailoring.
  • Develop and maintain RMF/security documentation (SSPs, POA&Ms, risk assessments).
  • Support security control assessments and remediation efforts.
  • Coordinate vulnerability scanning and track remediation.

Skills

Cybersecurity
Risk management
Cloud security

Education

Bachelor’s degree in computer science or cybersecurity

Tools

Risk management tools
Governance tools

Job description

Job Family:IT Cyber SecurityTravel Required:Up to 10%Clearance Required:Ability to Obtain Public TrustWhat You Will Do:Support the implementation and ongoing execution of the NIST RMF requirements across assigned authorization boundaries.Assist in system categorization in accordance with FIPS 199 and NIST SP 800-60 guidance.Help identify, document, and maintain applicable NIST SP 800-53 r5 security and privacy control implementations, control tailoring and inheritance.Develop, review, and/or maintain RMF or security related documentation, including:FIPS 199System Security Plans (SSPs)Plans of Action and Milestones (POA&Ms)Privacy and risk assessmentsContinuous monitoring documentationSystem specific security control or organizational level standard operating proceduresMemorandums of Agreement/Understanding or Interconnection Security AgreementsSupport security control assessments, remediation efforts, and authorization activities.Identify security weaknesses, vulnerabilities, and compliance gaps; document findings and work with stakeholders to develop corrective actions.Manage and maintain POA&Ms resulting from continuous monitoring or assessment results to ensure weaknesses are tracked through to remediation and closure.Support the preparation of boundaries for Authorization to Operate (ATO), reauthorization, and ongoing authorization activities.Monitor systems for compliance with FISMA and organizational cybersecurity policies, standards, and procedures.Ensure security requirements are integrated into system design, development, implementation, and operational changes.Support continuous monitoring activities, including control status reviews, vulnerability management, configuration management, and periodic assessments.Coordinate vulnerability scanning, review scan results, and track remediation of identified findings.Assist in incident response coordination, reporting, investigation, and follow-up corrective actions.Promote security best practices and help ensure systems maintain an acceptable level of risk.Manage boundary records in the applicable governance, risk, and compliance tool.What You Will Need:Bachelor’s degree in computer science, information technology, or cybersecurity.Current Security+ certificate.Minimum (3) three years of experience in cybersecurity.Experience utilizing enterprise cybersecurity risk management and governance tools.Experience with cloud security.Must be able to obtain and maintain a Federal or DoD Public Trust. Candidates must receive approved adjudication of their Public Trust prior to onboarding with Guidehouse. Candidates with an active Public Trust or existing suitability are preferred.Working knowledge or familiarity with:FISMA (2014): Federal mandated framework for information securityNIST SP 800-37 Rev. 2: Risk Management Framework for Information Systems and OrganizationsNIST SP 800-53 Rev. 5: Security and Privacy Controls for Information SystemsNIST SP 800-53A: Assessing Security and Privacy ControlsWhat Would Be Nice To Have:Working knowledge or experience with NIST IR 8467 Genomic Data Cybersecurity and Privacy Frameworks Community ProfileThe annual salary range for this position is $74,000.00-$124,000.00. Compensation decisions depend on a wide range of factors, including but not limited to skill sets, experience and training, security clearances, licensure and certifications, and other business and organizational needs.What We Offer:Guidehouse offers a comprehensive, total rewards package that includes competitive compensation and a flexible benefits package that reflects our commitment to creating a diverse and supportive workplace.Benefits include:Medical, Rx, Dental & Vision InsurancePersonal and Family Sick Time & Company Paid HolidaysParental Leave401(k) Retirement PlanGroup Term Life and Travel AssistanceVoluntary Life and AD&D InsuranceHealth Savings Account, Health Care & Dependent Care Flexible Spending AccountsTransit and Parking Commuter BenefitsShort-Term & Long-Term DisabilityTuition Reimbursement, Personal Development, Certifications & Learning OpportunitiesEmployee Referral ProgramCorporate Sponsored Events & Community OutreachCare.com annual membershipEmployee Assistance ProgramSupplemental Benefits via Corestream (Critical Care, Hospital Indemnity, Accident Insurance, Legal Assistance and ID theft protection, etc.)Position may be eligible for a discretionary variable incentive bonusAbout GuidehouseGuidehouse is an Equal Opportunity Employer–Protected Veterans, Individuals with Disabilities or any other basis protected by law, ordinance, or regulation.Guidehouse will consider for employment qualified applicants with criminal histories in a manner consistent with the requirements of applicable law or ordinance including the Fair Chance Ordinance of Los Angeles and San Francisco.If you have visited our website for information about employment opportunities, or to apply for a position, and you require an accommodation, please contact Guidehouse Recruiting at 1-571-633-1711 or via email at RecruitingAccommodation@guidehouse.com. All information you provide will be kept confidential and will be used only to the extent required to provide needed reasonable accommodation.All communication regarding recruitment for a Guidehouse position will be sent from Guidehouse email domains including @guidehouse.com or guidehouse@myworkday.com. Correspondence received by an applicant from any other domain should be considered unauthorized and will not be honored by Guidehouse. Note that Guidehouse will never charge a fee or require a money transfer at any stage of the recruitment process and does not collect fees from educational institutions for participation in a recruitment event. Never provide your banking information to a third party purporting to need that information to proceed in the hiring process.If any person or organization demands money related to a job opportunity with Guidehouse, please report the matter to Guidehouse’s Ethics Hotline. If you want to check the validity of correspondence you have received, please contact recruiting@guidehouse.com. Guidehouse is not responsible for losses incurred (monetary or otherwise) from an applicant’s dealings with unauthorized third parties.Guidehouse does not accept unsolicited resumes through or from search firms or staffing agencies. All unsolicited resumes will be considered the property of Guidehouse and Guidehouse will not be obligated to pay a placement fee.
Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

IT Security Control Assessor
IT Security Control Assessor

Dovel Technologies, Inc • McLean (VA)

On-site
USD 90,000 - 120,000
Medical, Rx, Dental & Vision Insurance
401(k) Retirement Plan
Tuition Reimbursement
Cybersecurity Consultant
Cybersecurity Consultant

Navigant • McLean (VA)

On-site
USD 85,000 - 141,000
Medical Insurance
401(k) Plan
Paid Holidays
+1
IT Advisory Manager
IT Advisory Manager

Dovel Technologies, Inc • McLean (VA)

On-site
USD 110,000 - 150,000
Medical, Rx, Dental & Vision Insurance
401(k) Retirement Plan
Short-Term & Long-Term Disability
IT Security Auditor - Consultant
IT Security Auditor - Consultant

Guidehouse • Chantilly (VA)

On-site
USD 120,000 - 160,000
Medical insurance
Parental Leave
401(k)
+2
IT Security Auditor – Senior Consultant
IT Security Auditor – Senior Consultant

Dovel Technologies, Inc • Chantilly (VA)

On-site
USD 120,000 - 180,000
Medical Insurance
401(k) Retirement Plan
Paid Holidays
+1
Workforce Operations Senior Consultant
Workforce Operations Senior Consultant

Guidehouse • Arlington (VA)

On-site
USD 110,000 - 160,000
Systems Engineer – Senior
Systems Engineer – Senior

Guidehouse • Washington

On-site
USD 98,000 - 163,000
Medical, Rx, Dental & Vision Insurance
401(k) Retirement Plan
Paid Holidays
+4
Cybersecurity Strategy Consultant
Cybersecurity Strategy Consultant

Guidehouse • McLean (VA)

Hybrid
USD 120,000 - 160,000
Medical, Rx, Dental & Vision Insurance
401(k) Retirement Plan
Parental Leave and Adoption Assistance
+2
ICAM Requirements and Training Specialist
ICAM Requirements and Training Specialist

Guidehouse • McLean (VA)

On-site
USD 113,000 - 188,000
Medical, Rx, Dental & Vision Insurance
401(k) Retirement Plan
Paid Holidays & Time Off
+1
IT Security Auditor - Consultant
IT Security Auditor - Consultant

Guidehouse • McLean (VA)

On-site
USD 120,000 - 180,000
Medical Insurance
401(k) Retirement Plan
Tuition Reimbursement
+2