Information System Security Officer

Hiring Our Heroes

Arlington (VA)

Hybrid

USD 90,000 - 130,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Hiring Our Heroes is seeking an Information Systems Security Officer (ISSO) to support full lifecycle A&A activities for federal information systems in Arlington, VA. The ISSO will ensure compliance with cybersecurity standards and maintain Authority to Operate through continuous monitoring and documentation.

The role covers risk assessments, Security Control Assessments, A&A documentation, vulnerability mitigation, ISCM, and the development of security plans and COOP/testing coordination with

Qualifications

  • Five (5) years in Information Security or IT field.
  • Experience developing, maintaining SA&A packages.
  • Experience developing and maintaining POA&Ms.
  • Strong problem solving and teamwork.
  • Knowledge of federal cybersecurity frameworks (NIST RMF, FIPS 199, FISMA).
  • Experience in security documentation and plans.
  • Experience conducting audits and CPTs.

Responsibilities

  • Lead and conduct Pre-Security Assessment and Authorization (A&A) activities.
  • Support day-to-day IT security activities.
  • Review system security posture and report findings to leadership.
  • Perform FIPS-199 assessments and BIAs/PIAs.
  • Develop and maintain System Security Plans and related documentation.
  • Coordinate IT Contingency Plan testing with BCDR Office.
  • Manage inter-agency documents (MOUs, MOAs, ISAs).
  • Document and update Security Control Implementation details.
  • Coordinate vulnerability scans and SCA activities.
  • Manage POA&Ms and remediate findings.
  • Prepare and present SAR to Authorizing Officials for ATO.
  • Perform ISCM activities and maintain project schedules.
  • Define baseline IT security requirements and system boundaries.

Skills

InfoSec experience
RMF knowledge
POA&M management
Vulnerability mgmt
Audit logs review

Tools

GRC tool
SA&A packages

Job description

Military Friendly & Preferred - Hoh Sponsor

The Information Systems Security Officer (ISSO) is responsible for supporting the full lifecycle of security assessment and authorization (A&A) activities for information systems. The ISSO ensures that assigned systems comply with federal cybersecurity standards and maintain their Authority to Operate (ATO) through continuous monitoring and documentation.

The ISSO will be responsible for developing and providing risk assessments, Security Control Assessments (SCA), A&A documentation and various reports, based on NIST guidelines and client's policies, procedures and request. The ISSO will be responsible for providing security recommendations on any system changes or new technologies, analysis on vulnerability scans, conducting continuous monitoring activities, and provide mitigation recommendations for any risks or threats.

Responsibilities
  • Lead and conduct Pre-Security Assessment and Authorization (A&A) activities, including stakeholder identification, change request submissions, appointment memorandums, and IT Security Kickoff meetings.
  • Supports the ISBO in day-to-day IT security activities.
  • Assists the ISBO with reviews of the security posture of the system and report any findings to the ISBO, CISO, and the AO.
  • Conduct Information System Categorization by identifying information types, completing FIPS-199 assessments, and facilitating Business Impact Analyses (BIA), Privacy Threshold Analyses (PTA), and Privacy Impact Assessments (PIA).
  • Develop and maintain system security documentation, including:
    • System Administration Plan (SAM)
    • Configuration Management Plan (CMP)
    • IT Contingency Plan (ITCP)
    • Information Security Continuous Monitoring (ISCM) Plan
    • Incident Response Plan (IRP)
    • Security Assessment Report (SAR)
    • System Security Plan (SSP)
  • Coordinate initial and annual ITCP testing in collaboration with the OCIO Business Continuity and Disaster Recovery (BCDR) Office.
  • Develop and manage inter-agency agreements and documentation such as MOUs, MOAs, ISAs, IT Security Waivers, and Risk Acceptance Memorandums.
  • Document and maintain Security Control Implementation details, ensuring updates are made according to required frequency.
  • Coordinate vulnerability and compliance scans, Security Control Assessments (SCA), and track remediation efforts with the IT Security Test Team.
  • Manage and update Plan of Action and Milestones (POA&M) entries, submitting remediated findings for closure.
  • Prepare and present SAR to Authorizing Officials to obtain or renew ATO.
  • Perform Information Security Continuous Monitoring (ISCM) activities to ensure ongoing compliance and security posture of systems.
  • Develop and update project schedule, including A&A / SCA task and milestones, task dependencies, and personnel resources.
  • Conduct A&A activities and tasks and obtain ATO in line with NIST and client guidance and directives.
  • Determining the baseline IT Security requirements for IT Systems, identifying system boundaries, determining information categories, assisting with FIPS-199.
  • Ensure that IT Systems are operated, used, maintained, and disposed of in accordance with internal security policies and practices.
  • Enforce security policies and safeguards on all personnel having access to the IT System for which the ISSO has responsibility.
  • Ensure users and system support personnel have the required authorization and need-to-know; have been indoctrinated; and are familiar with internal security practices before access to the IT System.
  • Implement security controls based on IT System FIPS categorization.
  • Document security control implementation in the system's Security Plan using the client's GRC tool.
  • Document system's risk assessment per client directives and requirements.
  • Review and monitoring system security and audit logs.
  • Develop and maintain Plan of Actions and Milestones (POA&Ms) for IT systems.
  • Update A&A documentation and artifacts on a regular basis (e.g. annually, after approved change).
Qualifications
  • A minimum of five (5) years of demonstrated experience in the Information Security or IT field.
  • Demonstrates a proficiency with developing, maintaining and managing SA&A packages.
  • Experience with developing and managing POA&M's.
  • Strong problem solving and analysis skills, self-motivated, and able to work and communicate in a team environment.
  • Strong understanding of federal cybersecurity frameworks (e.g., NIST RMF, FIPS-199, FISMA).
  • Experience in developing and maintaining security documentation and plans.
  • Possess experience conducting CPT's.
  • Experience conducting audit log reviews.
  • Technical experience with conducting vulnerability management, compliance scanning, and providing mitigation techniques.
  • Excellent communication and coordination skills with technical and non-technical stakeholders.
  • Ability to manage multiple systems and projects simultaneously in a dynamic environment.
  • Excellent communication (written and verbal) skills.
Certification
  • A minimum of at least one (1) certification that meet DOD 8570 IAT Level II (e.g., Security+, GSEC, CASP) requirements or any equivalent or more advanced.
Clearance
  • Client Suitability and Public Trust
LOCATION and HOURS:
  • Location: Primary location is at Zermount HQ (Arlington, VA) and the Client Site (Washington, D.C.). Remote work is authorized.
    • Onsite work at the primary location, may be occasionally required.
  • Hours of Operation (Business Hours): 8:00 am ET - 5:30 pm ET
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Information Systems Security Officer (ISSO)
Senior Information Systems Security Officer (ISSO)

Independent Software, Inc. • Maryland

On-site
USD 100,000 - 130,000
Information Systems Security Officer (ISSO)
Information Systems Security Officer (ISSO)

Skysoft Inc. • Maryland

Hybrid
USD 120,000 - 170,000
Information System Security Officer (ISSO)
Information System Security Officer (ISSO)

Ara • Albuquerque (NM), Northern (KY)

Hybrid
USD 95,000 - 130,000
Information Systems Security Officer (ISSO)
Information Systems Security Officer (ISSO)

MDAEdge • Washington

On-site
USD 160,000 - 210,000
Information Systems Security Officer (ISSO)
Information Systems Security Officer (ISSO)

MDAEdge • Reston (VA)

On-site
USD 150,000 - 190,000
Information Systems Security Officer
Information Systems Security Officer

Open Systems Technologies Corporation • Maryland

On-site
USD 80,000 - 115,000
3 weeks paid time off
11 Federal Holidays
Medical/dental coverage
+3
Information Systems Security Officer (ISSO) Mid Level (TS w/ SCI Eligibility) -
Information Systems Security Officer (ISSO) Mid Level (TS w/ SCI Eligibility) -

RedTrace Technologies • Washington

On-site
USD 80,000 - 100,000
Competitive salary
401(k) plan
Annual performance bonus
+5
Information System Security Officer (ISSO)
Information System Security Officer (ISSO)

Akima • Petaluma (CA)

On-site
USD 145,000 - 180,000
Medical insurance
Dental insurance
Vision insurance
+2
ISSO - Information Systems Security Officer
ISSO - Information Systems Security Officer

Anavationllc • Huntsville (AL)

On-site
USD 95,000 - 150,000
Information Systems Security Officer (ISSO)
Information Systems Security Officer (ISSO)

Modern Technology Solutions, Inc. (MTSI) • Washington

On-site
USD 90,000 - 130,000