Information System Security Officer

Jimmy Jazz

Washington (District of Columbia)

On-site

USD 120,000 - 170,000

Full time

28 hours ago
Be an early applicant
Application generator

Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Job summary

Tharros combines extensive cyber defense knowledge with the world’s preeminent vulnerability expertise to identify and defend against attacks before they become problems. This ISSO role owns the security posture for DHS Intelligence Enterprise systems, including Cross Domain Solutions and cloud-hosted environments, in accordance with ICD 503 and DHS 4300C.

On-site in a Government SCIF in Washington, DC. Responsibilities include creating and maintaining ATO packages, performing RMF

Qualifications

  • BS degree in Information Technology, Cybersecurity, Information Systems, or Computer Science OR minimum of 6 years' IT/cybersecurity experience.
  • Minimum of 3 years' experience as an ISSO or RMF package owner.
  • Active TS/SCI clearance and U.S. citizenship; willingness to undergo a DHS polygraph.
  • Knowledge of RMF, NIST SP 800-37, NIST SP 800-53, and ICD 503.
  • Knowledge of cross-domain solution governance and related mandates.
  • Experience with hybrid classified/unclassified, on-premise and cloud environments, DevSecOps, and agile.

Responsibilities

  • Create and maintain ATO packages for assigned systems in the GRC tool and monitor their compliance.
  • Perform self-assessments of on-premise and cloud systems against the A&A SOP.
  • Manage POA&Ms, waivers, and risk exceptions; provide weekly or bi-weekly activity reports.
  • Perform audit log reviews weekly; respond to NOSC alerts and ensure periodic scanning.
  • Coordinate system changes through IATT requests and serve on the CM Board when designated.
  • Facilitate annual contingency plan tests and submit quarterly CPEM reporting.
  • Deliver ISSO reports (incident response, POA&M, ConMon metrics) to ISSMs and system owners.
  • Serve as SCIF ISCR and mentor junior ISSOs.

Skills

RMF expertise
NIST SP 800-53
Cross Domain Solutions
Cloud security
Windows/Linux security
Communication skills

Education

BS degree in IT or Cybersecurity

Tools

RSA Archer
eMASS

Job description

Contact information
  • Location 1790 Ash Street Southeast,Washington, DC, 20032,United States
  • Employee Type Regular Full-Time
Description

Tharros supports the Department of Homeland Security (DHS) with cybersecurity services across its Intelligence Enterprise.

In support of this mission, we have an immediate opportunity for an Information System Security Officer (ISSO). In this role you will independently own the security posture of a portfolio of DHS Intelligence Enterprise systems, including Cross Domain Solutions and cloud-hosted systems, in accordance with ICD 503 and DHS 4300C. You will maintain ATO packages, manage POA&Ms and change control, and serve as a SCIF Information Security Compliance Representative (ISCR). This position is on-site in a Government SCIF in Washington, DC.

  • Create and maintain ATO packages for assigned systems in the GRC tool and monitor their compliance.
  • Perform self-assessments of assigned on-premise and cloud systems against the A&A SOP.
  • Manage POA&Ms, waivers, and risk exceptions; provide weekly or bi-weekly activity reports.
  • Perform audit log reviews at least weekly, respond to NOSC alerts, and ensure periodic scanning.
  • Coordinate system changes through IATT requests and serve on the Configuration Management Board when designated.
  • Facilitate annual contingency plan tests and submit quarterly CPEM reporting.
  • Deliver ISSO reports (incident response, POA&M, ConMon metrics) to ISSMs and system owners.
  • Serve as SCIF ISCR and mentor junior ISSOs.
Requirements
  • BS degree in Information Technology, Cybersecurity, Information Systems, or Computer Science OR minimum of 6 years' experience in IT or cybersecurity.
  • Minimum of 3 years' experience as an ISSO or in RMF package ownership.
  • Active TS/SCI clearance and U.S. citizenship; willingness to undergo a DHS counterintelligence-scope polygraph.
  • Knowledge of the Risk Management Framework (RMF), NIST SP 800-37, NIST SP 800-53, and ICD 503.
  • Knowledge of Cross Domain Solution engineering and governance, including NCDSMO mandates and Raise the Bar requirements.
  • Knowledge of hybrid classified/unclassified, on-premise and cloud environments, DevSecOps, and agile methodologies.
  • Skill in securing Linux and Windows operating systems and cloud technologies.
  • Skill in managing change control and authorization impacts.
  • Ability to independently manage a portfolio of systems.
  • Proficient in Microsoft Office Suite to include Teams or similar workplace chat and videoconferencing tools.
  • Excellent written and oral communications skills.
  • CGRC (formerly CAP), CompTIA Security+, or CySA+ certification.
  • Experience with RSA Archer, eMASS, or a similar GRC tool.
Summary

Tharros combines extensive cyber defense knowledge with the world’s preeminent vulnerability expertise to identify and defend against attacks before they become problems. Working at mission speed, we harden mission systems faster and secure them for longer, so agencies never lose the mission edge. Tharros lifts the veil of enterprise cybersecurity to detect zero days before they affect you, enabling mission maneuverability and the confidence to move missions forward.

In the ever-evolving realm of cyberspace, we are dedicated to becoming the paramount defender in the 5th warfighting domain. By pioneering innovative security solutions and fostering an environment of continuous learning and vigilance, we aim to protect the interests of our nation’s security. Our commitment to excellence in cybersecurity will establish new benchmarks, transforming the digital landscape into a secure and thriving frontier for future generations.

Tharros. See Everything. Secure Anything.

Tharros is committed to hiring and retaining a diverse workforce. We are proud to be an Equal Opportunity/Affirmative Action Employer and make employment decisions without regard to race, color, religion, creed, sex, sexual orientation, gender identity, marital status, national origin, age, veteran status, disability, or any other protected status.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Junior Information System Security Officer
Junior Information System Security Officer

Jimmy Jazz • Washington

On-site
USD 80,000 - 110,000
Junior Information System Security Officer, National Vetting Center
Junior Information System Security Officer, National Vetting Center

Jimmy Jazz • Washington

On-site
USD 90,000 - 120,000
Information System Security Officer
Information System Security Officer

ANALYGENCE • Washington

On-site
USD 140,000 - 190,000
IT Security Operations Specialist
IT Security Operations Specialist

Jimmy Jazz • Washington

On-site
USD 90,000 - 130,000
Junior Information System Security Officer
Junior Information System Security Officer

ANALYGENCE • Washington

On-site
USD 70,000 - 100,000
Junior Security Control Assessor
Junior Security Control Assessor

Jimmy Jazz • Washington

On-site
USD 70,000 - 100,000
Senior Security Control Assessor
Senior Security Control Assessor

Jimmy Jazz • Washington

On-site
USD 120,000 - 150,000
Security Governance and Policy Analyst
Security Governance and Policy Analyst

Jimmy Jazz • Washington

On-site
USD 120,000 - 170,000
Junior Security Engineer
Junior Security Engineer

Jimmy Jazz • Washington

On-site
USD 90,000 - 130,000
Senior Software Assurance and Vulnerability Assessment Engineer
Senior Software Assurance and Vulnerability Assessment Engineer

Jimmy Jazz • Washington

On-site
USD 140,000 - 200,000