Information System Security Officer

ANALYGENCE

Washington (District of Columbia)

On-site

USD 140,000 - 190,000

Full time

3 days ago
Be an early applicant
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Job summary

Tharros in Washington, DC, is seeking an Information System Security Officer (ISSO) to own the security posture of DHS Intelligence Enterprise systems, including Cross Domain Solutions and cloud-hosted systems, in accordance with ICD 503 and DHS 4300C. The role is on-site in a Government SCIF.

Responsibilities include maintaining ATOs, performing RMF assessments, managing POA&Ms, weekly audit reviews, and mentoring junior ISSOs. Requires TS/SCI, U.S. citizenship, and strong RMF knowledge.

Qualifications

  • BS degree in IT, Cybersecurity, Information Systems, or CS, or 6+ years in IT/cybersecurity.
  • Minimum 3 years' experience as an ISSO or RMF package owner.
  • Active TS/SCI clearance and U.S. citizenship; DHS polygraph required.
  • Strong knowledge of RMF, NIST SP 800-37/53, and ICD 503.
  • Experience with Cross Domain Solution engineering and governance.
  • Experience with hybrid or cloud environments; DevSecOps and Agile.

Responsibilities

  • Create and maintain ATO packages in the GRC tool and monitor compliance.
  • Perform self-assessments of on-premise and cloud systems against the A&A SOP.
  • Manage POA&Ms, waivers, risk exceptions; provide regular reports.
  • Perform audit log reviews weekly, respond to NOSC alerts, ensure periodic scanning.
  • Coordinate changes via IATT requests and join CM B when designated.
  • Facilitate annual contingency plan tests and submit CPEM reports.
  • Deliver ISSO reports to ISSMs and system owners.
  • Serve as SCIF ISCR and mentor junior ISSOs.

Skills

RMF
NIST SP 800-37
NIST SP 800-53
Cross Domain
Cloud security
DevSecOps
Agile
Communication

Education

Bachelor's degree in IT/Cybersecurity/CS

Tools

RSA Archer
eMASS

Job description

Tharros supports the Department of Homeland Security (DHS) with cybersecurity services across its Intelligence Enterprise.

In support of this mission, we have an immediate opportunity for an Information System Security Officer (ISSO). In this role you will independently own the security posture of a portfolio of DHS Intelligence Enterprise systems, including Cross Domain Solutions and cloud-hosted systems, in accordance with ICD 503 and DHS 4300C. You will maintain ATO packages, manage POA&Ms and change control, and serve as a SCIF Information Security Compliance Representative (ISCR). This position is on-site in a Government SCIF in Washington, DC.

Responsibilities
  • Create and maintain ATO packages for assigned systems in the GRC tool and monitor their compliance.
  • Perform self-assessments of assigned on-premise and cloud systems against the A&A SOP.
  • Manage POA&Ms, waivers, and risk exceptions; provide weekly or bi-weekly activity reports.
  • Perform audit log reviews at least weekly, respond to NOSC alerts, and ensure periodic scanning.
  • Coordinate system changes through IATT requests and serve on the Configuration Management Board when designated.
  • Facilitate annual contingency plan tests and submit quarterly CPEM reporting.
  • Deliver ISSO reports (incident response, POA&M, ConMon metrics) to ISSMs and system owners.
  • Serve as SCIF ISCR and mentor junior ISSOs.
Requirements
  • BS degree in Information Technology, Cybersecurity, Information Systems, or Computer Science OR minimum of 6 years' experience in IT or cybersecurity.
  • Minimum of 3 years' experience as an ISSO or in RMF package ownership.
  • Active TS/SCI clearance and U.S. citizenship; willingness to undergo a DHS counterintelligence-scope polygraph.
  • Knowledge of the Risk Management Framework (RMF), NIST SP 800-37, NIST SP 800-53, and ICD 503.
  • Knowledge of Cross Domain Solution engineering and governance, including NCDSMO mandates and Raise the Bar requirements.
  • Knowledge of hybrid classified/unclassified, on-premise and cloud environments, DevSecOps, and agile methodologies.
  • Skill in securing Linux and Windows operating systems and cloud technologies.
  • Skill in managing change control and authorization impacts.
  • Ability to independently manage a portfolio of systems.
  • Proficient in Microsoft Office Suite to include Teams or similar workplace chat and videoconferencing tools.
  • Excellent written and oral communications skills.
Desired
  • CGRC (formerly CAP), CompTIA Security+, or CySA+ certification.
  • Experience with RSA Archer, eMASS, or a similar GRC tool.
Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Junior Information System Security Officer
Junior Information System Security Officer

ANALYGENCE • Washington

On-site
USD 70,000 - 100,000
Information System Security Officer
Information System Security Officer

Jimmy Jazz • Washington

On-site
USD 120,000 - 170,000
Junior Information System Security Officer
Junior Information System Security Officer

Jimmy Jazz • Washington

On-site
USD 80,000 - 110,000
Senior Information Systems Security Officer (ISSO)
Senior Information Systems Security Officer (ISSO)

Independent Software, Inc. • Maryland

On-site
USD 100,000 - 130,000
Information System Security Officer (ISSO) / System Administrator
Information System Security Officer (ISSO) / System Administrator

Sanmina-SCI Systems de México • Huntsville (AL)

On-site
USD 90,000 - 150,000
Information Systems Security Officer
Information Systems Security Officer

Zohorecruit • United States

Remote
USD 110,000 - 165,000
Information Systems Security Officer (ISSO)
Information Systems Security Officer (ISSO)

Quantum Sky • Washington

On-site
USD 110,000 - 140,000
Information Systems Security Officer
Information Systems Security Officer

Open Systems Technologies Corporation • Maryland

On-site
USD 80,000 - 115,000
3 weeks paid time off
11 Federal Holidays
Medical/dental coverage
+3
Senior Information System Security Officer (ISSO)
Senior Information System Security Officer (ISSO)

Ortman Consulting LLC • Washington

On-site
USD 90,000 - 130,000
Information System Security Officer (ISSO)
Information System Security Officer (ISSO)

PD Inc • Washington

On-site
USD 120,000 - 170,000