Washington, District of Columbia, United States
About the job Information Systems Security Officer
Job Title: Information Systems Security Officer (ISSO)
Location: Washington, DC
Salary: $110,000 - $120,000 / yr
Roles and Responsibilities:
- Support IS Security activities performed by the Senior Cloud Information System Security Officer (ISSO), including:
- Implement, oversee, monitor, and maintain security configurations, practices, and procedures for each IS
- Serve as liaison between the system owner and IS security personnel
- Ensure security controls are implemented and functioning during all phases of the IS lifecycle
- Maintain and update security documentation continuously
- Conduct vulnerability scans and develop POAMs for reported vulnerabilities
- Manage risks by coordinating correction actions and tracking POAM completion
- Coordinate with system owners for mitigation actions
- Monitor security controls to maintain ATO
- Upload security evidence to GRC application during monitoring
- Report changes affecting authorization status to system owner and ISSM
- Coordinate decommissioning of ISs
- Provide baseline security controls based on IS categorization and type
- Recommend impact levels and authorization boundaries to the Authorizing Official
- Create entities in GRC with proper security categorization
- Handle interconnection agreements (ISAs, MOUs, MOAs)
- Review SSP and make approval decisions
- Negotiate testing levels with security sections and the Authorizing Official
- Schedule and coordinate security assessments and inspections
- Submit final security packages for ATO decisions
- Ensure security communications are logged properly
- Advise on vulnerabilities and residual risks
- Ensure POA&M actions are completed and tested
- Coordinate reauthorization events
What are the 3-4 non-negotiable requirements of this position?
- Active U.S. Government (DoD-Issued) Top Secret Security Clearance with SCI and a CI-Polygraph eligibility
- At least 5 years as an ISSO at a cleared DoD facility, following DoD Instruction 8570.1
- IAM Level III Certification
Nice-to-have skills:
- Bachelor's or advanced degree in computer science, business management, or IT-related discipline