Information Systems Security Officer

HRsmart

Washington (District of Columbia)

Hybrid

USD 100,000 - 130,000

Full time

3 days ago
Be an early applicant
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Benefits offered by this job

Salary package
Medical insurance
Paid leave
401k plan

Job summary

Business Operational Concepts (BOC) is currently seeking an Information System Security Officer (ISSO) to support a federal client. The ISSO will assist with CSF 2.0 implementation, risk management, and continuous monitoring across cloud and on-prem environments.

The ideal candidate holds a Security+ and experience with SSPs, SARs, POA&Ms, SIAs, and ATO documentation, and will support privacy compliance and annual audits.

Qualifications

  • A Bachelor's degree or equivalent in an IT-related field.
  • A minimum of five (5) years of hands-on ISSO experience in a federal environment.
  • Experience developing SSPs, SARs, POA&Ms, SIAs, and ATO documentation.
  • Experience with continuous monitoring, vulnerability management, risk assessments, and privacy compliance activities.

Responsibilities

  • Advise IT management and system owners on security and privacy matters.
  • Support agency systems, cloud and on-prem environments, and hybrid ecosystems.
  • Collaborate to categorize systems, define boundaries, and ensure compliance with federal policies.

Skills

Federal cybersecurity knowledge
Governance & compliance
Cloud security (Azure/M365)
Vulnerability management
Risk assessments

Education

Bachelor's degree or equivalent in IT

Tools

SSPs
SARs
POA&Ms
SIAs
ATO documentation

Job description

Information Systems Security Officer - (248)

Job Title

Information Systems Security Officer

Location

Washington, DC 20002 US (Primary)

Category

Information Technology

Job Type

Full Time

Professional

Education

Refer to Job Requirements: Qualifications

Travel

Occasional

Salary Range

$100,000 - $130,000

Security Clearance Required

None

Salary Grade

Job Description

Business Operational Concepts (BOC) is a recognized leader in providingTechnical and Program Management Services, Information Technology, and Support.

BOC has enabled their Government and Commercial clients to achieve their organizational initiatives through the application of high quality, innovative, and cost-effective professional services and solutions. We provide a positive working environment, with opportunities for advancement in our growing Federal sector workforce.

We offer an excellent compensation package which includes a generous salary, insurance (medical, dental, etc.), paid leave, 401k plan and more.We arecommitted to the diversity we bring to the marketplace and believe customer satisfaction comes first.

JOB SUMMARY:

Business Operational Concepts (BOC) is currently seeking a seeking an Information System Security Officer (ISSO) to work with our federal client. The ideal candidate will support cybersecurity, governance, risk management, compliance, engineering, automation, and program management activities for the federal client.

The ISSO will support agency information systems and cybersecurity processes in accordance with federal cybersecurity requirements and will assist with implementation of the NIST Cybersecurity Framework (CSF) 2.0, Risk Management Framework activities, system authorization, continuous monitoring, vulnerability management, privacy compliance, and related cybersecurity activities.

DUTIES AND RESPONSIBILITIES:
  • Serve as an advisor to IT management, system owners, business process owners, and senior management on matters related to the security and privacy of assigned information systems.
  • Support applicable agency systems, cloud environments, on-premises infrastructure, hybrid systems, SaaS platforms, identity services, endpoint platforms, vulnerability management tools, logging and monitoring platforms, and security governance processes.
  • Coordinate with stakeholders to categorize systems, define system boundaries, establish interconnection agreements, and support adherence to applicable federal policies, including Zero Trust principles where applicable.
  • Support cybersecurity governance, risk management, compliance, engineering, automation, and program activities associated with implementation of NIST Cybersecurity Framework 2.0.
  • Develop and/or update cybersecurity processes and artifacts in alignment with NIST CSF 2.0.
  • Support Privacy Threshold Analyses (PTAs), Privacy Impact Assessments (PIAs), and other privacy compliance activities.
  • Support identification, tracking, remediation, and closure of Non-Functional Requirements (NFRs) and security findings.
  • Support transition from a static three-year system authorization model to an ongoing authorization and Continuous Monitoring model.
  • Support the agency's use of the Caveonix platform for governance, risk, compliance, and continuous monitoring activities.
  • Assess and support Authority to Operate (ATO) packages for assigned systems.
  • Develop and maintain required system authorization artifacts, including:
    • System Security Plans (SSPs)
    • Security Assessment Reports (SARs)
    • Plans of Action and Milestones (POA&Ms)
    • Security Impact Analyses (SIAs)
  • Support Continuous Monitoring activities, including security control validation, vulnerability management, risk assessments, evidence collection, cybersecurity metrics, and reporting.
  • Support applicable federal and agency cybersecurity, security, privacy, and AI requirements.
  • Support cybersecurity activities associated with the agency's cloud environment, including Azure and Microsoft 365, as required.
  • Support cybersecurity activities associated with changes to infrastructure and security posture.
  • Provide ongoing cybersecurity subject-matter support, including support for annual FISMA audit activities.
  • Maintain required cybersecurity documentation and provide status and supporting information as required by program management and the Government.

Job Requirements

QUALIFICATIONS:
Required (Minimum) Qualifications – Education, Certification, Experience, and Skills
  • A Bachelor's degree or equivalent work experience in an IT-related field.
  • A minimum of five (5) years of hands-on experience performing ISSO or equivalent functions in a federal environment.
  • Demonstrated experience developing and maintaining:
    • SSPs
    • SARs
    • POA&Ms
    • SIAs
    • ATO documentation
  • Experience with:
    • Continuous Monitoring
    • Vulnerability Management
    • Risk Assessments
    • Privacy compliance activities, including PTA and PIA support.
Preferred Qualifications – Education, Certification, Experience, Skills, Knowledge, and Abilities
  • Required Certification
    • CompTIA Security+
  • Preferred Certifications
    • The following certifications are preferred but are not required:
    • (ISC)² Certified Information Systems Security Professional (CISSP)
    • Certified Information Security Manager (CISM)
    • Certified Information Systems Auditor (CISA)

Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, age, pregnancy, genetic information, disability, status as a protected veteran, or any other protected category under applicable federal, state, and local laws. If you are an individual with a disability and would like to request a reasonable accommodation as part of the employment selection process, please contact the Human Resources Department via email at HR@boc.us.com or by phone at 301-359-1721.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Information System Security Officer
Information System Security Officer

Hiring Our Heroes • Arlington (VA)

On-site
USD 90,000 - 130,000
Information Systems Security Officer (ISSO)
Information Systems Security Officer (ISSO)

Quantum Sky • Washington

On-site
USD 110,000 - 140,000
Information Systems Security Officer
Information Systems Security Officer

Base-2 Solutions, LLC • Maryland

On-site
USD 120,000 - 160,000
Information Systems Security Officer (ISSO)
Information Systems Security Officer (ISSO)

8 Consulting LLC • Washington

Hybrid
USD 110,000 - 170,000
Information Systems Security Officer Senior
Information Systems Security Officer Senior

Saic • Ashburn (VA)

On-site
USD 120,000 - 160,000
Senior Information Systems Security Officer (ISSO)
Senior Information Systems Security Officer (ISSO)

Independent Software, Inc. • Maryland

On-site
USD 100,000 - 130,000
Information System Security Officer* Atlantic City, NJ
Information System Security Officer* Atlantic City, NJ

InfiniSource Consulting Solutions, Inc. • Atlantic City (NJ)

On-site
USD 110,000 - 160,000
Information Systems Security Officer
Information Systems Security Officer

The Hawaii Pacific Foundation • Hanahan (SC)

On-site
USD 250,000 - 300,000
Information Systems Security Officer (ISSO)
Information Systems Security Officer (ISSO)

CACI • Reston (VA)

On-site
USD 121,000 - 266,000
Information Systems Security Officer
Information Systems Security Officer

Open Systems Technologies Corporation • Maryland

On-site
USD 80,000 - 115,000
3 weeks paid time off
11 Federal Holidays
Medical/dental coverage
+3