Senior Information Systems Security Officer

RED CANYON TECHNOLOGIES LLC

Scottsdale (AZ)

On-site

USD 140,000 - 190,000

Full time

4 days ago
Be an early applicant
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Benefits offered by this job

Medical Insurance
Dental Insurance
Vision Insurance
Life and Disability
Retirement Match
Paid Time Off
Voluntary Benefits
Employee Assistance Program
Tuition Reimbursement

Job summary

Diné Development Corporation (DDC) seeks a Senior Information Systems Security Officer to lead ISSO and Risk & Compliance teams. You will oversee RMF, FedRAMP, and accreditation activities for federal healthcare and commercial clients, driving risk management and security control implementation.

You will serve as a trusted expert on RMF, coordinate with 3PAOs, and develop comprehensive security documentation (SSPs, SARs, POA&Ms) while mentoring staff and aligning practices with NIST guidelines.

Qualifications

  • Minimum 10+ years in federal IT, security and RMF.
  • Experience leading large Federal healthcare projects.
  • Public trust clearance or eligibility required or preferred.

Responsibilities

  • Lead accreditation assessments for clients in government and commercial sectors.
  • Develop and review RMF packages with accuracy and detail.
  • Coordinate FedRAMP readiness with 3PAOs and prepare SSPs/SARs/POA&Ms.

Skills

RMF expertise
FedRAMP
NIST RMF
ISSO leadership
GRC coordination
HIPAA knowledge

Education

Bachelor’s Degree
Master’s Degree preferred

Tools

Archer GRC
Nessus

Job description

We are seeking a Senior Information Systems Security Officer to join our dynamic team. In this role, you will lead our client's ISSO and Risk and Compliance teams, overseeing activities related to risk management, compliance, and information system security. Your expertise in FedRAMP, RMF, and accreditation assessments will be crucial in ensuring our client's systems adhere to Federal standards.Responsibilities:Accreditation Assessments:Perform security control assessment services for clients in commercial and government sectors, ensuring compliance with NIST RMF and FedRAMP requirements.Develop and review RMF packages with meticulous attention to detail and accuracy.Assist contract companies in meeting Federal agency including OMB, and EO or Intelligence Community mandates for security compliance.Collaborate with private entities to establish effective cybersecurity programs, particularly for critical infrastructure.Maintain FISMA authorization to operate for information systems through internal audits and adherence to NIST RMF security controls.Act as the primary advisor on NIST RMF compliance, offering guidance on resolving outstanding issues and meeting security control requirements.Conduct comprehensive security control assessments following NIST, IHS, and CISA guidelines.Provide expert recommendations to the Approval Official regarding network and system authorizationsAssist with implementing General Support Systems (GSS)Assist with implementing Common ControlsAssist advising continuous monitoring and implementing RBD programTrain and educate team members and stakeholders on NIST RMF principles and best practices.FedRAMP Compliance:Serve as the organization's trusted Subject Matter Expert (SME) for FedRAMP, wielding a deep understanding of its requirements, guidelines, and controls. Continuously update your FedRAMP knowledge to advise the organization of new requirements, guidelines, and controls.Conduct internal FedRAMP readiness assessments to identify and remediate gaps or deficiencies prior to Third-Party Assessment Organizations (3PAOs) assessmentsCoordinate FedRAMP readiness assessments with 3PAOsDevelop and maintain essential FedRAMP compliance documentation (System Security Plans (SSPs), Security Assessment Reports (SARs), and Plan of Actions and Milestones (POA&Ms).Assist with remediating any findings identified during FedRAMP assessments and preparing for audits by the Federal government or authorized entities.Act as a liaison with the FedRAMP program office to facilitate effective communication and compliance alignment.ISSO Tasks:Develop a real-time risk management system that fosters collaboration and enhances security practices within the organization.Conduct regular security risk analyses for hospitals and healthcare systems to identify vulnerabilities and mitigate potential threats.Provide daily advisory support to the National Security Director, addressing security concerns and participating in the implementation of a robust incident response program.Stay abreast of Healthcare IT technologies and apply NIST 800 series methodologies to safeguard them effectively.Train and mentor IT Security Team members, equipping them with the knowledge and skills needed to perform their roles efficiently.Provide technical leadership to accreditation assessors and ISSOs.Conduct analysis of current environment and provide recommendations to align accreditation processes with NIST and RMF guidanceCreate and maintain information security policies in compliance with NIST and HIPAA regulations.Utilize Archer to develop and maintain system accreditation lifecycle workflows and ATO packet management processes.Conduct comprehensive security control assessments following NIST, IHS, and CISA guidelinesRisk and Compliance Management:Conduct security risk analyses for current and emerging systemsProvide expert recommendations to the Approval Official regarding network and system authorizations.Coordination of risk assessment and compliance activities between R&C and ISSO teams.Conduct comprehensive assessments of security controls for IHS systems and sites, following NIST and CISA guidelines and ensuring adherence to risk management practices.Offer guidance and advice on risk management techniques, procedures, and best practices to subordinate commands.Act as Lead consultant for security control assessors and ISSO coordination, develop the processes and document standard procedures, fostering a collaborative and high-performing work environment.Provide expert recommendations to the Approval Official (AO) regarding the authorization of organizations' networks and systems on IHS networks.Thoroughly review system and site artifacts to verify compliance with NIST RMF requirements and identify potential areas for improvement.Utilize network scanning and patching tools to mitigate vulnerabilities and enhance system security.Prepare and present Approval to Operate (ATO) or Interim Approval to Test (IATT) documents, ensuring compliance with assessment requirements and CATOs.Stay current with relevant NIST publications, NIST, CISA and IHS standards, and other guidelines.Contribute to the development of policies, procedures, and methodologies that align with NIST RMF and support the organization's transition to these frameworks.Train new security control assessors and other team members, ensuring they possess the necessary skills and knowledge to excel in their roles.Utilize network scanning and patching tools to mitigate vulnerabilities and enhance system security.Conduct staff assistance visits and annual FISMA security control assessments for DRSN sites, providing valuable insights and recommendations for improvement.Manage deliverables, coordinate briefings, and oversee staff visits using effective project management practices.Provide expert advice and produce necessary artifacts to ensure ongoing compliance with NIST RMF requirements and maintain a robust security posture.Experience leading large projects in a Federal healthcare environmentAbility to coordinate risk assessment and compliance activities between GRC and ISSO teamsProvide leadership and guidance to ISSO and GRC teamsExpert level knowledge of RMF process, accreditation assessments, and DISA-STIGs for both on premises and cloud environmentsExcellent communication and briefing skills to communicate to client leadershipConduct regular security risk analyses for healthcare systems to identify vulnerabilities and mitigate potential threats.Managing vulnerability remediation activities, ensuring their timely and effective resolution.Coordinating external penetration testing to identify security weaknesses and collaborate with internal stakeholders for remediation activitiesConduct comprehensive vulnerability assessments to identify potential weaknesses within the organization's systems and infrastructureDevelop robust risk assessment methodologies aligned to NIST, FedRAMP, and HIPPA requirements and assist ISSO and Risk and Compliance team to implement the solution.Continuously monitor and track risk mitigation efforts, update risk registers, and provide risk management guidance to maintain a resilient security posture.Overseeing continuous monitoring processes; crafting and maintaining essential security metrics; and staying vigilant against emerging threats in the ever-evolving threat landscape, and train ISSO team and GRC team to work to the level they can perform their tasks independently.Ensure compliance with relevant regulations and standards to provide guidance to system owners on the selection and implementation of appropriate security controls.Support vulnerability management through regular assessments and compliance reporting.Experience with Tenable to request ad-hoc scans, review reports, and provide analysis to stakeholders.Provide input to the design and delivery training programs to educate system owners and employees on risk management, compliance, and security best practices to foster and maintain a comprehensive and proactive security culture.Qualifications:Years of Experience: 10+ Years Relevant ExperienceEducation Level: Bachelor’s Degree; Master’s Degree preferredClearance Requirements: Public TrustCertification Requirements: CISSPAny other work-related qualifications needed for the role:Experience leading large projects in a Federal healthcare environment.Strong knowledge and understanding of HIPAA, PII, NIST, FISMA, and FedRAMP.Proficiency with Nessus and Archer GRC (2 years desired).Expert knowledge of RMF, NIST, accreditation assessments, and DISA-STIGs.Excellent communication and briefing skills for client leadership.About UsDiné Development Corporation (DDC) is a Navajo Nation–owned family of companies that provides government agencies and commercial organizations with high-quality IT, professional, environmental, and research and development services. DDC is dedicated to empowering the Navajo Nation and the communities we serve.BenefitsEligible full-time employees receive a comprehensive benefits package, including medical, dental, vision, life and disability coverage, retirement savings with company match, and paid time off. Additional benefits include voluntary supplemental benefits, access to an employee assistance program, and educational assistance with tuition reimbursement.Equal Opportunity & Compliance StatementThis contractor and subcontractor shall abide by the requirements of 41 CFR 60-1.4(a), 60-300.5(a), and 60-741.5(a). These regulations prohibit discrimination against qualified individuals based on their status as protected veterans or individuals with disabilities, and prohibit discrimination against all individuals based on their race, color, religion, sex, sexual orientation, gender identity, national origin, or for inquiring about, discussing, or disclosing information about compensation, or any other basis prohibited by law.We participate in E-Verify.DDC is committed to providing equal employment opportunities to all applicants and employees. If you require a reasonable accommodation to participate in the application or interview process, please contact Recruiting for assistance recruiting@ddc-dine.com
Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Senior Information Systems Security Engineer
Senior Information Systems Security Engineer

Ddc Dine • United States

Remote
USD 140,000 - 190,000
Medical, dental, vision
Life and disability coverage
Retirement with company match
+2
Senior Information Systems Security Engineer
Senior Information Systems Security Engineer

RED CANYON TECHNOLOGIES LLC • Scottsdale (AZ)

On-site
USD 140,000 - 190,000
Medical, dental, vision
Life and disability coverage
Retirement savings with company match
+1
Senior Information Systems Security Officer
Senior Information Systems Security Officer

Ddc Dine • United States

Remote
USD 120,000 - 180,000
Intermediate Cybersecurity Analyst
Intermediate Cybersecurity Analyst

Ddc Dine • Virginia (MN), Northern (KY)

Hybrid
USD 90,000 - 150,000
Medical insurance
Dental insurance
Vision insurance
+5
Intermediate Information Assurance (IA) Analyst - Lead
Intermediate Information Assurance (IA) Analyst - Lead

NOVA DINE LLC • Fort Meade (MD)

On-site
USD 80,000 - 105,000
Intermediate Cybersecurity Analyst
Intermediate Cybersecurity Analyst

NORTH STONE LLC • Quantico (VA)

On-site
USD 90,000 - 150,000
Medical, dental, vision
Retirement match
Paid time off
Senior IT Strategy & Enterprise Services Lead
Senior IT Strategy & Enterprise Services Lead

SPINSYS DINE LLC • Linthicum (MD)

On-site
USD 105,000 - 183,000
Medical, dental, vision insurance
401(k) with company match
Paid time off
+2
Vice President, Federal Healthcare IT
Vice President, Federal Healthcare IT

Diné Development Corporation • Scottsdale (AZ)

On-site
USD 180,000 - 280,000
Medical insurance
Dental insurance
Vision insurance
+4
Senior Program Manager
Senior Program Manager

Ddc Dine • Linthicum (MD), Northern (KY)

Hybrid
USD 90,000 - 218,000
Medical insurance
Dental insurance
Vision insurance
+6
Cloud Computing Specialist (CCS) – Subject Matter Expert (SME)
Cloud Computing Specialist (CCS) – Subject Matter Expert (SME)

DINE SOURCE LLC • Scottsdale (AZ)

On-site
USD 110,000 - 160,000
Medical insurance
Dental insurance
Vision insurance
+3