Information Systems Security Officer (ISSO)

Cgsfederal

Chicago (IL)

On-site

USD 110,000 - 165,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Health, Dental, and Vision
Life Insurance
401k
Flexible Spending Account (Health, Dep
Dependent Care
Commuter

Job summary

Contact Government Services, LLC is seeking an Information Systems Security Officer (ISSO) with RMF and DIACAP background to support Department of Commerce systems and achieve Authorization to Operate (ATO). The role entails full life-cycle A&A management, NIST 800-53 compliance, and RMF oversight for government systems at a Washington, DC client site.

The ISSO will conduct security assessments, manage risk, and provide guidance on configuration management, vulnerability remediation, and

Qualifications

  • Bachelor’s Degree.
  • Minimum of five (5) years experience as an Information Assurance (IA) Analyst, ISSE, ISSO, or similar role in ATO package development.
  • eMASS experience.
  • Professional security certification such as: CCNA Security, CySA+, GICSP, GSEC, CompTIA Security+ CE, SSCP, or higher.
  • Strong desktop publishing skills using Microsoft Word and Excel.
  • Experience with industry writing styles such as grammar, sentence form, and structure.
  • Ability to multi-task in a deadline‑oriented environment.

Responsibilities

  • Review systems to identify potential security weaknesses and recommend improvements to amend vulnerabilities, implement changes, and document upgrades.
  • Maintain responsibility for managing cybersecurity risk from an organizational perspective.
  • Identify organizational risks, prioritize those risks, and maintain a risk registry for escalating and presenting those risks to senior leadership.
  • Provide security guidance and IS validation using the National Institute of Standards and Technology (NIST) RMF, DoC, and local security policies.
  • Provide configuration management (CM) recommendations for information system security software, hardware, and firmware and coordinate changes and modifications with the ISSM, Security Control Assessor (SCA), and Authorizing Official (AO).
  • Maintain vulnerability scanning tool compliance, such as HBSS or ACAS, and patch management, such as IAVM to ensure IT staff pushes patches to all systems in an effort to maintain compliance with all applicable directives, manage system changes, and assess the security impact of those changes.
  • Support security authorization activities, including transitioning from the legacy Information Assurance Certification and Accreditation Process (DIACAP) to compliance with the DoC RMF.
  • Provide subject matter expertise for cyber security and trusted system technology.
  • Apply advanced technical knowledge and analysis of specialized functional areas in task requirements to develop solutions to complex problems.
  • Research, write, review, disposition feedback, and finalize recommendations regarding cyber security policy, assessment and authorization assessments (A&A), security test and evaluation reports, and security engineering practices and processes.
  • Conduct research and write risk assessment reports to include risk thresholds, evaluation, and scoring.
  • Support analysis of the findings and provide expert technical guidance for mitigation strategies, including implementation advice on the cyber security risk findings, and other complex problems.

Skills

IA Analyst
ISSO/ISSE
eMASS
NIST RMF
Security+ / CISSP

Education

Bachelor's Degree

Tools

HBSS
ACAS
IAVM
STIG

Job description

Overview

CGS is seeking an Information Systems Security Officer (ISSO) with DIACAP and/or RMF experience who has deep expertise in security assessment documentation to support Dept. of Commerce systems and efforts to achieve their Authorization to Operate (ATO). This position is located at the client site in the Herbert Hoover building in Washington, DC. The role includes full life‑cycle Assessment and Authorization (A&A) management through all six steps of the RMF process in support of the Government ISSM. The ISSO will conduct security assessment and information system security oversight activities in accordance with NIST 800‑53 that support systems from the perspective of RMF requirements.

Responsibilities
  • Review systems to identify potential security weaknesses and recommend improvements to amend vulnerabilities, implement changes, and document upgrades.
  • Maintain responsibility for managing cybersecurity risk from an organizational perspective.
  • Identify organizational risks, prioritize those risks, and maintain a risk registry for escalating and presenting those risks to senior leadership.
  • Provide security guidance and IS validation using the National Institute of Standards and Technology (NIST) RMF, DoC, and local security policies.
  • Provide configuration management (CM) recommendations for information system security software, hardware, and firmware and coordinate changes and modifications with the ISSM, Security Control Assessor (SCA), and Authorizing Official (AO).
  • Maintain vulnerability scanning tool compliance, such as HBSS or ACAS, and patch management, such as IAVM to ensure IT staff pushes patches to all systems in an effort to maintain compliance with all applicable directives, manage system changes, and assess the security impact of those changes.
  • Support security authorization activities, including transitioning from the legacy Information Assurance Certification and Accreditation Process (DIACAP) to compliance with the DoC RMF.
  • Provide subject matter expertise for cyber security and trusted system technology.
  • Apply advanced technical knowledge and analysis of specialized functional areas in task requirements to develop solutions to complex problems.
  • Research, write, review, disposition feedback, and finalize recommendations regarding cyber security policy, assessment and authorization assessments (A&A), security test and evaluation reports, and security engineering practices and processes.
  • Conduct research and write risk assessment reports to include risk thresholds, evaluation, and scoring.
  • Support analysis of the findings and provide expert technical guidance for mitigation strategies, including implementation advice on the cyber security risk findings, and other complex problems.
Qualifications
  • Bachelor’s Degree.
  • Minimum of five (5) years experience as an Information Assurance (IA) Analyst, ISSE, ISSO, or similar role in ATO package development, including generating security documentation for requirements, security control assessment, STIG and IAVA compliance, Standard Operating Procedures, test results, etc.
  • eMASS experience.
  • Professional security certification such as: CCNA Security, CySA+, GICSP, GSEC, CompTIA Security+ CE, SSCP, or higher.
  • Strong desktop publishing skills using Microsoft Word and Excel.
  • Experience with industry writing styles such as grammar, sentence form, and structure.
  • Ability to multi-task in a deadline‑oriented environment.
Desired Qualifications
  • CISSP, CASP, or a similar certificate is preferred.
  • Master's Degree in Cybersecurity or related field.
  • Strong initiative, detail orientation, organizational skills, and aptitude for analytical thinking.
  • Demonstrated ability to work well independently and as a part of a team.
  • Excellent work ethic and a high commitment to quality.
Benefits
  • Health, Dental, and Vision
  • Life Insurance
  • 401k
  • Flexible Spending Account (Health, Dependent Care, and Commuter)
  • Paid Time Off and Observance of State/Federal Holidays
Equal Opportunity Employer

Contact Government Services, LLC is an Equal Opportunity Employer. Applicants will be considered without regard to their race, color, religion, sex, sexual orientation, gender identity, national origin, disability, or status as a protected veteran.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Information Systems Security Officer (ISSO)
Information Systems Security Officer (ISSO)

Cgsfederal • New York (NY)

On-site
USD 95,000 - 150,000
Health, Dental, and Vision
Life Insurance
401k
+2
Information Systems Security Officer (ISSO)
Information Systems Security Officer (ISSO)

Cgsfederal • Miami (FL)

On-site
USD 110,000 - 150,000
Health, Dental, Vision
Life Insurance
401k
+2
Information Systems Security Officer (ISSO)
Information Systems Security Officer (ISSO)

Cgsfederal • Los Angeles (CA)

On-site
USD 110,000 - 140,000
Health, Dental, and Vision
Life Insurance
401k
+2
Information Systems Security Officer (ISSO)
Information Systems Security Officer (ISSO)

Cgsfederal • Dallas (TX)

On-site
USD 110,000 - 160,000
Health, Dental, Vision
Life Insurance
401k
+2
Information Systems Security Officer (ISSO)
Information Systems Security Officer (ISSO)

Cgsfederal • Atlanta (GA)

On-site
USD 110,000 - 140,000
Health, Dental, and Vision
Life Insurance
401k
+2
Information Systems Security Officer (ISSO)
Information Systems Security Officer (ISSO)

CGS Federal (Contact Government Services) • Miami (FL)

On-site
USD 92,000 - 126,000
Health Insurance
401k
Paid Time Off
+1
Information Systems Security Officer (ISSO)
Information Systems Security Officer (ISSO)

CGS Federal (Contact Government Services) • Atlanta (GA)

On-site
USD 92,000 - 126,000
Health Insurance
Dental Insurance
401(k)
+2
Information Systems Security Officer (ISSO)
Information Systems Security Officer (ISSO)

Contact Government Services, LLC • Washington

On-site
USD 92,000 - 126,000
Health, Dental, and Vision
Life Insurance
401k
+2
Information Systems Security Officer (ISSO)
Information Systems Security Officer (ISSO)

CGS Federal (Contact Government Services) • Massachusetts

On-site
USD 92,000 - 126,000
Health, Dental, Vision Insurance
401k
Flexible Spending Account
+1
Information Systems Security Officer (ISSO)
Information Systems Security Officer (ISSO)

Contact Government Services, LLC • Washington

On-site
USD 120,000 - 180,000
Health, Dental, and Vision
Life Insurance
401k
+2