Technical ISSO

NR Labs

Maryland

On-site

USD 110,000 - 160,000

Full time

8 days ago

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

NR Labs is seeking an IT security professional to provide technical leadership on security controls for vendor solutions. You will act as ISSO for systems, perform pre-assessment analyses, and ensure architecture compliance with NIST and agency standards.

You will lead encryption, authentication, and session management reviews, coordinate with vendors, and develop security documentation throughout the SDLC. Strong communication and collaboration with stakeholders are essential.

Qualifications

  • Six years of experience in the IT security field.
  • Two years supporting A&A (NIST 800-53) and compliance activities.
  • Four years hands-on experience as a System Architect or Security Engineer.
  • Bachelor's degree in Computer Science or related field.
  • Security+, CISSP, CISM, CISA, or equivalent security certification.
  • Technical expertise with Nessus Tenable Security and Invicti reports.
  • Experience reviewing 3rd party security assessment reports.
  • Knowledge of NIST Policies, RMF, FISMA and related standards.
  • Strong written and oral communication skills.

Responsibilities

  • Perform detailed architecture and technical design reviews on the full stack for vendor solutions.
  • Assess and document encryption standards for encryption at rest and in transit.
  • Assess and document authentication mechanisms for all points in the system.
  • Assess and document session management and control for all layers of the system.
  • Lead vendor screen-sharing sessions and document security-relevant findings for the CISO.
  • Serve as the ISSO for assigned systems to ensure compliance with FISMA and agency policies.
  • Oversee vendor relationships and ensure compliance with security/privacy requirements.
  • Support IT security activities to meet project deadlines and integrate security in the SDLC.
  • Develop and maintain security documentation (SSP, PIA, CONPLAN, POA&M, etc.).
  • Research IT security architectures to provide security recommendations.

Skills

IT security
A&A/NIST 800-53
System architecture
Security certification
Communication skills
Vendor management
Security governance

Education

Bachelor's degree in Computer Science or related field

Tools

Nessus Tenable
Invicti

Job description

About the Role: The candidate will provide technical expertise on Security control implementations and development of Information Security procedures for systems and applications. Although you will be the ISSO for these systems after they are authorized for use, candidates will also be required to perform pre-assessment activities, including a detailed analysis of the technology stacks comprising the vendor solutions. This position requires a fundamental understanding of engineering-compliant architectures and solutions. You will be part of a team working to assess vendor systems for technical compliance with NIST and agency standards.

Role Description:

  • Perform detailed architecture and technical design reviews on the full stack for vendor solutions (examples of some areas requiring detailed analysis):
  • Assess and document encryption standards for encryption at rest and in transit (what cipher sets are used? What type of encryption? etc)
  • Assess and document authentication mechanisms for all points in the system (Is MFA implemented at all authentication points? Is the MFA solution approved and compliant with NIST and agency standards?)
  • Assess and document session management and control for all layers of the system
  • Schedule and lead screen-sharing sessions with the vendors to gain a full understanding of the technology stack, document all security-relevant information required for the architecture review and create a full report for presentation to the CISO
  • Serves as the IT security POC (ISSO) for assigned systems to ensure agency information systems comply with FISMA OMB and agency Policies.
  • Oversee and manage relationships for assigned systems that may be contractor owned and contractor operated, ensuring vendors comply with agency security and privacy requirements.
  • Assist stakeholders with IT security-related activities to ensure project deadlines are met.
  • Ensure security activities are implemented throughout the SDLC from beginning to end.
  • Ensure all systems are operated, maintained, and disposed of IAW documented security policies and procedures, including but not limited to Assessment & Authorization (A&A).
  • Support the development and maintenance of all security documentation such as the System Security Plan, Privacy Impact Assessment, Configuration Management Plan, Contingency Plan, Contingency Plan Test Report, POA&M, annual FISMA assessment, and incident reports.
  • Research assigned IT security systems to provide insight into IT security architectures and IT security recommendations for assigned systems.
  • Report and respond to security incidents.
  • Assess vulnerabilities to ascertain if additional safeguards are needed and ensure systems are patched, and security hardened at all levels of the “stack,” and monitor to see that vulnerabilities are remediated as appropriate.
  • Promote Information Security Awareness and provide training.

Required Qualifications & Education:

  • Six (6) years of experience in the IT security field
  • Two (2) years of experience supporting A&A (NIST 800-53) and compliance activities
  • Four (4) years of hands-on technical experience as a System Architect or Security Engineer
  • Bachelor’s degree in Computer Science or a related field or an additional two years of industry experience.
  • Security+, CISSP, CISM, CISA, or equivalent Security certification.
  • Technical expertise with Nessus Tenable Security and Invicti reports.
  • Experience in reviewing 3rd party security assessment reports
  • Have detailed knowledge and experience with NIST Policies, Governance, Security Planning and Architecture, FISMA Compliance, RMF, Incident Analysis, and General Security Best Practices.
  • Ability to communicate, written and oral, to technical and non-technical stakeholders.
  • Possess strong written and oral communication skills to support customers, internal stakeholders, peers, and public audiences.

Desired Qualifications:

  • Direct experience with NIST 800-171 is preferred
  • Strong communication skills to interact with senior managers, junior staff, and business unit (non-technical) customers.

Clearance and Location Requirements:

  • Able to be cleared for a Public Trust clearance.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

ISSO - Information Systems Security Officer
ISSO - Information Systems Security Officer

Anavationllc • Huntsville (AL)

On-site
USD 95,000 - 150,000
Information Systems Security Officer (Technical ISSO / RMF Assessor)
Information Systems Security Officer (Technical ISSO / RMF Assessor)

Peraton • Herndon (VA)

On-site
USD 120,000 - 180,000
Senior ISSO Supporting Federal Government Agency
Senior ISSO Supporting Federal Government Agency

SiloSmashers • Washington

On-site
USD 120,000 - 160,000
Senior ISSO
Senior ISSO

Agile Defense, LLC • Washington

On-site
USD 120,000 - 180,000
Information Systems Security Officer – Hybrid
Information Systems Security Officer – Hybrid

Jobtailor • Washington

On-site
USD 110,000 - 160,000
Senior Information Security Analyst
Senior Information Security Analyst

Wood River Federal • San Antonio (TX)

On-site
USD 100,000 - 150,000
Senior Information System Security Officer (ISSO)
Senior Information System Security Officer (ISSO)

Unity Compass • Alexandria (VA)

Hybrid
USD 90,000 - 175,000
ISSO 3 - Information Sytems Security Officer
ISSO 3 - Information Sytems Security Officer

InisCore Technologies • Fort Meade (MD)

On-site
USD 120,000 - 150,000
Information Security Analyst
Information Security Analyst

SANMINA-SCI TECHNOLOGY INDIA PRIVATE LIMITED • Huntsville (AL)

On-site
USD 95,000 - 140,000
Information System Security Officer / ISSO
Information System Security Officer / ISSO

NXTKEY CORPORATION • Washington

On-site
USD 80,000 - 120,000