Koniag Data Solutions, a Koniag Government Services company, is seeking an experiencedInformation System Security Officer (ISSO) / Control Evaluatorto support a comprehensive enterprise cybersecurity services engagement for a federal civilian agency. This position requires the ability to obtain and maintain a government background investigation commensurate with a Moderate Risk designation (Minimum Background Investigation or higher) and applicable system access authorizations prior to performing work. Work will be performed primarily at the client's facility located in Washington, DC, with potential for hybrid/remote arrangements as approved.
We offer competitive compensation and an extraordinary benefits package including health, dental and vision insurance, 401K with company matching, flexible spending accounts, paid holidays, three weeks paid time off, and more.
This role sits within the Information Security Division (ISD) and supports the agency's Risk Management Framework (RMF) program, FISMA compliance obligations, continuous monitoring activities, and security controls assessment and evaluation functions across a diverse portfolio of on-premises, cloud-hosted, and hybrid information systems.
The ideal candidate is a technically proficient and operationally experienced cybersecurity professional with a deep understanding of NIST security frameworks, federal information security policy, security assessment methodologies, and the practical application of security controls across complex, multi-technology enterprise environments. This individual must possess the ability to develop and maintain in-depth technical knowledge of assigned systems, build trusted relationships with system owners and stakeholders, and independently execute a broad range of ISSO responsibilities with minimal Government direction.
The ISSO / Control Evaluator is responsible for providing comprehensive information system security officer support and security controls assessment and evaluation services across an assigned portfolio of federal information systems. This individual develops and sustains in-depth technical, operational, and working-level expertise about each assigned system, advocates for system owner needs as they align to cybersecurity and privacy requirements, and ensures each system maintains its authorization to operate in accordance with federal and agency security policies and standards.
This role requires active participation in the agency's enterprise change control processes, continuous monitoring activities, Ongoing Authorization (OA) programs, and audit support functions, as well as contributions to automation, visualization, and data structure efforts that provide real-time visibility into control status and security posture across the enterprise.
Principal responsibilities will include but are not limited to:
ISSO Core Responsibilities
- Develop and sustain in-depth technical, operational, and working-level expertise about all assigned information systems, including thorough knowledge of system architecture, assets, data flows, operational environment, management hierarchy, and how each system fits into the broader enterprise IT ecosystem.
- Establish and maintain a professional rapport and trusted working relationship with system owners, program offices, and technical support personnel for all assigned systems, understanding their operational needs and advocating for those needs as they align to cybersecurity and privacy requirements.
- Read, absorb, and maintain current familiarity with all available system documentation for assigned systems, including System Security Plans (SSPs), topology diagrams, architecture diagrams, and data flow documentation.
- Establish access to and gain increasing proficiency with the operational tools, administrative consoles, and enterprise cybersecurity platforms used to manage and monitor assigned systems, extracting meaningful data to produce continuously updated control status visualizations and dashboards.
- Ensure assigned systems are onboarded into enterprise tools and reporting mechanisms, including the agency's Governance, Risk, and Compliance (GRC) tool, in accordance with established procedures and timelines.
- Actively participate in the weekly Enterprise Change Control Board (ECCB) process, ensuring security impacts of proposed changes are evaluated and documented for all assigned systems.
- Maintain current awareness of all active Acceptance of Risk (AOR) documents for assigned systems, ensuring resubmission for approval before expiration.
- Maintain knowledge management services for all accreditation-related artifacts, including appointment orders, Authority to Operate (ATO) documentation, AORs, Memoranda of Understanding/Agreement, and Data Sharing Agreements, ensuring all documents are organized and accessible in the designated central repository.
Documentation Support
- Create, update, revise, and maintain cybersecurity and privacy documentation for all assigned systems across the enterprise, ensuring all documentation is aligned to applicable agency implementation procedures and reviewed for acceptance by the Office of the CIO.
- Develop and maintain the following documentation types, among others:
- System Security Plans (SSPs) with detailed, technology-specific control implementation descriptions for all technologies within the system boundary
- Information System Contingency Plans (ISCPs) and Contingency Plan Test Reports (ISCP-TRs)
- Architecture, topology, and data flow diagrams (OV-1 and SV-1 equivalent)
- Ensure all control implementation descriptions are written to a level of detail that demonstrates how each control is specifically implemented across all technologies within the system boundary, avoiding high-level generalizations or simple restatement of NIST control language.
- Address all Government comments, edits, and questions on documentation within 10 business days of receipt, and elevate stakeholder unresponsiveness to the Government POC after 10 business days without response.
- Ensure selected policy and procedure documents are delivered in both Adobe and Word formats and are Section 508 accessibility remediated as directed.
Controls Assessment and Evaluation Support
- Provide security and privacy controls assessment and continuous monitoring assessment support for all assigned systems, including testing and validation of NIST SP 800-53 controls, documentation of NIST SP 800-53A Determine If Statements (DISs), and mapping of vulnerabilities to applicable controls.
- Develop draft Security and Risk Assessment Plans (SAPs) for delivery not less than 10 business days prior to beginning an assessment, and draft Security and Risk Assessment Reports (SARs) and Plan of Action and Milestones (POAMs) within 30 business days from point-in-time assessment kick-off.
- Conduct technical control assessments across all technology types within the system boundary (e.g., Windows, UNIX, Cisco, F5 Load Balancer), including sampling across in-scope devices, users, and services, ensuring assessments are comprehensive to the scope identified in the SAP and 100% aligned to the GRC tool.
- Develop and deliver Annual Assessment Reports (AARs) per in-scope system within 120 business days from point-in-time annual assessment kick-off, and multi-year assessment reports in accordance with applicable timelines.
- Incorporate all Government feedback into revised deliverables within 5 business days of receipt of comments, ensuring final deliverables are comprehensive, peer-reviewed, and aligned to agency templates.
- Develop assessment reports that include visual representation against the NIST Cybersecurity Framework (CSF) and are comprehensive to the scope identified in the SAP.
Ongoing Authorization (OA) Evaluation Support
- For systems approved for Ongoing Authorization (OA), develop and submit an OA Playbook to the agency for approval, including a documented testing methodology for each OA core control covering Test Strategy, Test Design, Test Execution, Results Evaluation, and Visualization.
- Conduct OA Positive Testing monthly in accordance with agency implementation procedures, documenting all results in the agency GRC tool.
- Conduct OA Negative Testing annually in accordance with agency implementation procedures, coordinating with penetration testing resources as necessary to execute negative test scenarios.
- Perform OA testing comprehensively across the technology stack of each target system, documenting results in detail within the GRC tool in a clear and concise manner.
FISMA Reporting Support
- Collect, compile, validate, and submit FISMA reporting metrics for all assigned systems and programs, leveraging automation to the greatest degree possible to ensure accuracy and completeness of collected data.
- Contribute to the consolidated FISMA metrics reports, ensuring data is mathematically accurate and representative of the total agency FISMA inventory, delivered for Government review not later than 10 business days prior to submission due dates.
- Support the development and maintenance of dynamically updatable FISMA metrics visualizations and dashboards that pull data directly or indirectly from collected metrics.
Audit Support
- Support and facilitate internal and external audits of assigned FISMA systems, including audits conducted by the Inspector General (IG), General Accountability Office (GAO), and internal auditors.
- Facilitate audit meetings and walkthroughs, coordinate with relevant support personnel, supply auditors with requested artifacts, and respond to follow-up questions in accordance with auditors' schedules and timelines.
- Ensure SOC reports are received from program offices for audit purposes as required, and that all audit artifacts are delivered on time, reviewable by the Government, and minimizing repeated requests from auditors.
High Value Asset (HVA) Assessment Support
- Complete CISA's on-demand High Value Assets Assessment 3.0 (HVA 3.0) Training and provide course completion certificate to the Information System Security Manager (ISSM).
- Develop, maintain, and regularly update the agency HVA inventory list at least annually, and incorporate HVA activities into broader IT and information security and privacy management planning activities.
- Identify, categorize, and prioritize HVAs, implement and validate required security controls, identify HVA connections and dependencies, and support timely remediation of HVA assessment findings in accordance with established plans, milestones, and timelines.
- Facilitate monthly FedRAMP CONMON meetings with applicable stakeholders for assigned systems, maintaining a general understanding of each system to provide appropriate guidance and comments to Cloud Service Providers (CSPs).
- Review vulnerability, penetration test, and ad hoc reporting from CSPs, ensuring vendor actions pose no security risks to the enterprise, and review and approve major changes when required by the vendor.
Automation, Visualization, and Data Structures Support
- Design, construct, automate, and maintain visualizations (dashboards) and underlying data structures that reflect the status or effectiveness of security controls, monitoring status, capabilities, and metrics for assigned systems.
- Intake continuous feeds from enterprise cybersecurity tools (typically in .csv format), using scripting or other automation techniques to construct visualizations that reflect the status or effectiveness of monitored capabilities.
- Build, maintain, and document the underlying data structures supporting all visualizations, including all Extract-Transform-Load (ETL) requirements, data intake, and data normalization processes.
- Make approved visualizations available via the agency intranet portal, ensuring they are updated automatically on a continual basis or refreshed on at least a weekly schedule as appropriate.
- Maintain cybersecurity and privacy risk registers for assigned systems, ensuring they are updated monthly and available via online visualization and internal web portal.
- Leverage the Factor Analysis of Information Risk (FAIR) methodology to assist in quantifying risk, and support the integration of cybersecurity and privacy risks into the agency ERM Risk Register as directed.
- Evaluate major risks related to cybersecurity, privacy, theft of information, and sensitive information protection (both internal and external threats), and collaborate on building out risk register entries with associated controls and planned mitigations.
Security & Compliance
- Ensure all ISSO activities comply with applicable Federal security requirements, including FISMA, NIST SP 800-53 Rev 5, NIST SP 800-53A Rev 5, NIST SP 800-37 Rev 2, FIPS 199, FIPS 200, OMB Circular A-130, HSPD-12, and all referenced agency policies and implementation procedures.
- Comply with annual cybersecurity awareness training requirements and maintain all required certifications as current and unexpired throughout the period of performance.
- Ensure all work products are Section 508 accessibility compliant where required, and that all documentation is government-owned and free of proprietary or company-specific markings.
Education and Experience:
Required:
- Bachelor's degree in Cybersecurity, Information Technology, Computer Science, Information Systems, or a related field from an accredited college or university. Equivalent combination of education and directly relevant work experience may be considered in lieu of a degree.
- Minimum of 5 years of experience in information security, with at least 3 years of dedicated experience serving as an ISSO, security control assessor, or equivalent role supporting federal information systems under the NIST RMF.
- Demonstrated experience developing, maintaining, and submitting System Security Plans (SSPs), Security Assessment Plans (SAPs), Security Assessment Reports (SARs), and Plans of Action and Milestones (POAMs) in a federal agency environment.
- Demonstrated experience conducting NIST SP 800-53A security and privacy controls assessments across multi-technology enterprise systems.
- Hands‑on experience with a federal agency Governance, Risk, and Compliance (GRC) tool for documentation management and continuous monitoring tracking.
- Ability to obtain and maintain a government background investigation commensurate with a Moderate Risk designation (Minimum Background Investigation or higher) and all required system access authorizations prior to performing work.
Preferred:
- Prior experience supporting federal civilian agency cybersecurity programs, particularly within an ISD or OCIO environment.
- Experience supporting Ongoing Authorization (OA) programs, including development of OA Playbooks and execution of positive and negative testing methodologies.
- Experience supporting FISMA reporting, including collection and submission of metrics via the CyberScope tool.
- Experience supporting HVA assessments and FedRAMP Continuous Monitoring activities.
Required Skills and Competencies:
- Exceptional communication skills in English—both written and oral—with the demonstrated ability to produce clear, concise, thorough, and professionally written technical documentation aligned to agency templates and implementation procedures.
- Deep knowledge of the NIST Risk Management Framework (RMF), including NIST SP 800‑37 Rev 2, NIST SP 800‑53 Rev 5, NIST SP 800‑53A Rev 5, NIST SP 800‑30 Rev 1, and NIST SP 800‑137.
- Strong understanding of federal information security law, policy, and standards, including FISMA, FIPS 199, FIPS 200, OMB Circular A‑130, HSPD‑12, and applicable OMB memoranda.
- Demonstrated ability to write detailed, technology‑specific security control implementation descriptions for all technology types within a system boundary (e.g., Windows, UNIX/Linux, network devices, web applications, cloud platforms), avoiding high‑level generalizations.
- Hands‑on experience assessing technical control families (AC, AU, IA, SC, SI) across mixed technology environments, including sampling strategies and cross‑technology testing.
- Proficiency with enterprise cybersecurity tools commonly used in federal environments, including vulnerability scanning platforms (e.g., Tenable Nessus/Security Center), SIEM platforms (e.g., Microsoft Sentinel), endpoint detection and response (EDR) tools, and GRC platforms.
- Experience developing and maintaining dashboard visualizations and underlying data structures using scripting, automation, and data analysis techniques (e.g., PowerShell, Python, Power BI, Kusto Query Language).
- Familiarity with cloud security principles and security assessment considerations for IaaS, PaaS, and SaaS environments, including AWS and Microsoft Azure Government.
- Strong organizational skills with the ability to manage multiple concurrent system assignments, documentation deadlines, and stakeholder relationships simultaneously with a high degree of accuracy and attention to detail.
- Knowledge of Section 508 accessibility compliance requirements as they apply to technical documentation and reporting deliverables.
- Proficiency with Microsoft Office Suite, SharePoint, and enterprise collaboration tools such as Microsoft Teams.
Desired Skills and Competencies:
- Certified Information Systems Security Professional (CISSP), Certified Information Security Manager (CISM), CompTIA Security+, or equivalent cybersecurity certification meeting DoD/Federal IAM or IAT level requirements.
- (ISC)² Systems Security Certified Practitioner (SSCP), ISACA Certified in Risk and Information Systems Control (CRISC), or equivalent risk management certification.
- Experience with the Factor Analysis of Information Risk (FAIR) methodology for quantitative cybersecurity risk assessment and risk register development.
- Experience supporting Ongoing Authorization (OA) programs, including development of OA Playbooks incorporating both positive and negative testing methodologies aligned to agency‑specific test procedures.
- Familiarity with FedRAMP Continuous Monitoring requirements and experience facilitating monthly CONMON meetings with Cloud Service Providers (CSPs).
- Experience supporting HVA assessment programs, including HVA inventory management, remediation plan development, and coordination with CISA in accordance with BOD 18‑02 and OMB M‑19‑03.
- Experience with enterprise GRC tools for documentation management, continuous monitoring tracking, POAM management, and FISMA metrics reporting, including familiarity with CyberScope submission processes.
- Experience developing and maintaining data automation pipelines, ETL processes, and dashboard visualizations using tools such as Power BI, PowerShell, Python, or Kusto Query Language (KQL) in support of continuous monitoring and FISMA reporting.
- Familiarity with Privacy Act requirements, Privacy Impact Assessment (PIA) development, Privacy Threshold Analysis (PTA), and System of Records Notice (SORN) processes.
- Experience with Microsoft Purview, Microsoft Defender for Endpoint, Microsoft Sentinel, Tenable Security Center, or other enterprise security tools identified in the agency's cybersecurity tool stack.
- Experience supporting internal or external audits conducted by the Inspector General (IG), General Accountability Office (GAO), or other oversight bodies, including artifact collection, facilitation of walkthroughs, and audit response preparation.
The company is an equal opportunity employer. The company shall not discriminate against any employee or applicant because of race, color, religion, creed, ethnicity, sex, sexual orientation, gender or gender identity (except where gender is a bona fide occupational qualification), national origin or ancestry, age, disability, citizenship, military/veteran status, marital status, genetic information or any other characteristic protected by applicable federal, state, or local law. We are committed to equal employment opportunity in all decisions related to employment, promotion, wages, benefits, and all other privileges, terms, and conditions of employment.
The company is dedicated to seeking all qualified applicants. If you require an accommodation to navigate or to apply to a position on our website, please contact Heaven Wood via e‑mail at accommodations@koniag‑gs.com or by calling 703‑488‑9377 to request accommodations.
Koniag Government Services (KGS) is an Alaska Native Owned corporation supporting the values and traditions of our native communities through an agile employee and corporate culture that delivers Enterprise Solutions, Professional Services and Operational Management to Federal Government Agencies. As a wholly owned subsidiary of Koniag, we apply our proven commercial solutions to a deep knowledge of Defense and Civilian missions to provide forward leaning technical, professional, and operational solutions. KGS enables successful mission outcomes for our customers through solution‑oriented business partnerships and a commitment to exceptional service delivery. We ensure long‑term success with a continuous improvement approach while balancing the collective interests of our customers, employees, and native communities. For more information, please visit www.koniag‑gs.com .
Equal Opportunity Employer/Veterans/Disabled. Shareholder Preference in accordance with Public Law 88‑352