Senior Information Systems Security Officer

Illuminate
Dulles, VA, US
Full-time

Overview

The Information Systems Security Officer (ISSO) manages all aspects of an organization's information security system, for classified and unclassified systems, including researching, testing, training and implementing programs designed to safeguard sensitive information from any possible breaches.

The ISSO drives Authority to Operate (ATO) and / or Authority to Proceed (ATP) efforts and makes independent recommendations to the customer during the process.

ISSOs understand and execute the Risk Management Framework process. The ISSO conduct risk analyses and writes documents including Plan of Action and Milestones, System Security Plans, System Specific Policies and Procedures, Configuration Management Plans, Contingency Plans and Test Results, Business Impact Analyses, and Security Impact Analyses.

Responsibilities

  • Manages all aspects of an organization's information security system, for classified and unclassified systems, including researching, testing, training and implementing programs designed to safeguard sensitive information from any possible breaches.
  • Applies Risk Management Framework (RMF), conducts risk analysis, and produces risk assessments.
  • Spearheading Authority to Operate (ATO) and / or Authority to Proceed (ATP) efforts while making independent recommendations to Government Leads during these processes.
  • Conducts risk analysis from vulnerability and compliance scans, pen testing results, or other audit activity.
  • Creates written works to including Plan of Action and Milestones, System Security Plans, System Specific Policies and Procedures, Configuration Management Plans, Contingency Plans and Test Results, Business Impact Analyses, and Security Impact Analyses.
  • Participates in Agile Planning Events to provide technical input.

Qualifications

Required Knowledge, Skills, and Abilities :

  • Understands the Risk Management Framework (RMF), and how risk management is executed, what risk means, and how to analyze it.
  • Knowledgeable on one or more cloud computing services and technologies including but not limited to : AWS, Microsoft Azure, VMware, etc.
  • Able to clearly and concisely articulate true and accurate status updates on government IT systems security posture, and overall system health to the customer.

Required Education and Experience :

  • Must have a current SECRET clearance AND be clearable to TS / SCI.
  • Bachelor’s degree in a technical discipline and seven (7) years relevant experience OR a total of 10 years’ relevant experience
  • Executing the NIST Risk Management Framework (RMF) and applying security practices found in NIST publications. (. SP 800-53, SP 800-30, SP 800-60, FIPS 199, FIPS 140-2,
  • Documenting System Security Plans to include security control implementation statements.
  • Conducting periodic reviews of implementation statements to ensure persistent compliance with applicable government and agency level policies in addition to ISO and NIST standards.
  • Validating implementation of security controls within a cloud environment (AWS or Azure).
  • Supporting the security assessment and authorization or ATO process
  • Supporting the security assessment and authorization (or ATO) process.
  • Analyzing testing results from scans, audits, penetration tests, or other test efforts to determine risk levels.
  • Conducting Continuous Monitoring and maintaining the security posture of IT systems within on-prem, cloud, and hybrid environments.
  • Familiar with the Microsoft Office 365 Suite. (. Word, PowerPoint, SharePoint, Excel,

Preferred Education, Experience, Skills, and Abilities :

  • Cyber program experience within federal customer space
  • Familiar with Scaled Agile Frameworks (SAFe), agile development principles, and DevSecOps methodologies
  • Have managed vulnerabilities on virtualized IT systems and assets or virtual machines (. VDI and
  • SAFe Agile tool experience (., Jira, Jira Align, or ServiceNow)
  • P ossess CISSP, CCSP, AWS, MS Azure, CISA, CAP, or SAFe 6
  • 30+ days ago
Related jobs
Promoted
Peraton
Chantilly, Virginia

Bachelor's degree or higher in Computer Science, Information Technology, Engineering, Engineering Management, Management Information Systems, or related STEM degree program, or related equivalent additional experience of 4 years with no degree or 2 years with a non-STEM degree. The Space and Intelli...

Promoted
AT&T
Oakton, Virginia

AT&T’s TAC2O contract provides a team of IT specialists who perform IT Engineering, Cybersecurity; Communications Security, Systems Administration, Software Development, SharePoint Development and Administration, and Program Management services supporting sensitive technical collection and exploitat...

Peraton
McLean, Virginia

Senior Information Systems Security Officer (ISSO). Senior Information Systems Security Officer (ISSO). Information Systems Security Officer (ISSO) providing system security support for ongoing and future system development within the Customer organization. Senior Information Systems Security Office...

Maxar
Herndon, Virginia

Bachelor’s degree with in Information Systems, Cyber Security or related field . Prepare and maintain information systems Accreditation and Authorization (A&A) packages (BoE - ConOps/Customer Test Plan, SSPs SCTM) . Coordinate with team’s ISSEs and senior ISSOs to implement the Continuous Monitoring...

ST2 ManTech Advanced Systems Intl
Chantilly, Virginia

ManTech is seeking an experienced Information Systems Security Officer (ISSO) for Chantilly, VA. Certified Information Systems Security Professional (CISSP certification). Join the top Information Technology and Analytic professionals in the industry to make invaluable contributions to our national ...

KBR
Chantilly, Virginia

Senior SIGINT Systems Engineer - Acquisition. Senior SIGINT Systems Engineer. The SIGINT Systems Engineer serves as an advisor to support the Government in defining new mission requirements, performing classic Systems Engineering sub-tasks such as Requirements, Configuration Management, Integration,...

Leidos
Reston, Virginia

This role installs and maintains security scanning tools, performs security scans, reviews scan results, and supports information system security officers (ISSOs). Information Systems Security Engineer with Security Clearance. Responsibilities include collaborating with the customer security organiz...

ST2 ManTech Advanced Systems Intl
Chantilly, Virginia

Senior Personnel Security Manager. Leads the team that assesses, implements, and maintains security measures for an organization’s personnel, ensuring the protection of sensitive information and resources. They provide guidance and support to ensure compliance with security policies and procedures, ...

Zolon Tech
Springfield, Virginia

Advise senior management (, Chief Information Officer [CIO]) on risk levels and security posture. Advise senior management (, CIO) on cost/benefit analysis of information security programs, policies, processes, systems, and elements. Ability to integrate information security requirements into the ac...

Peraton
Chantilly, Virginia

Bachelor's degree or higher in Computer Science, Information Technology, Engineering, Engineering Management, Management Information Systems, or related STEM degree program, or related equivalent additional experience of 4 years with no degree and 2 years with a non-STEM degree. The Space and Intell...