Job Requirements
Washington, DC
Secret Polygraph not specified
Mid Level Career (5+ yrs experience)
Salary not specified
Join Premium to unlock estimated salaries
Job Description
Job Description
Overview of Role:
The ISSO will serve as the Security Documentation and Security Impact Analysis Specialist on the DFC ISSO Support Services contract. This role demands strong technical writing capability, meticulous version control discipline, deep familiarity with DFC OIT document templates, and a thorough understanding of how system changes affect security posture and authorization boundary integrity.
Roles and Responsibilities:
• RMF & A&A Management: Drive the end-to-end NIST RMF lifecycle for assigned systems. Develop, review, and maintain critical Assessment and Authorization documentation, including System Security Plans and Security Assessment Reports.
• Continuous Monitoring: Execute Information Security Continuous Monitoring (ISCM) strategies, analyze system audit logs, and generate operational security health reports for leadership.
• Vulnerability & POA&M Management: Coordinate vulnerability scanning and penetration testing. Actively manage the Plan of Action and Milestones lifecycle to ensure timely remediation of security weaknesses.
• Security Engineering Support: Integrate security into the System Development Life Cycle (SDLC) by evaluating control implementations and enforcing secure baselines (e.g., DISA STIGs, CIS Benchmarks).
• Incident & Contingency Operations: Support the detection and containment of security incidents. Assist in drafting, testing, and updating Incident Response Plans and Contingency Plans.
• Compliance Enforcement: Validate user access requirements, enforce agency-specific security policies, and ensure completion of role-based security training.
• Minimum 3–5 years of direct experience in federal ISSO duties, cybersecurity documentation, or information assurance support for FISMA Moderate or higher programs
• No problems, only solutions!
Educational and Certification Requirement:
• Bachelor's degree in Cybersecurity, Information Technology, Computer Science, or a related field
• Security+; CAP or comparable RMF certification preferred
Overview of Role:
The ISSO will serve as the Security Documentation and Security Impact Analysis Specialist on the DFC ISSO Support Services contract. This role demands strong technical writing capability, meticulous version control discipline, deep familiarity with DFC OIT document templates, and a thorough understanding of how system changes affect security posture and authorization boundary integrity.
Roles and Responsibilities:
• RMF & A&A Management: Drive the end-to-end NIST RMF lifecycle for assigned systems. Develop, review, and maintain critical Assessment and Authorization documentation, including System Security Plans and Security Assessment Reports.
• Continuous Monitoring: Execute Information Security Continuous Monitoring (ISCM) strategies, analyze system audit logs, and generate operational security health reports for leadership.
• Vulnerability & POA&M Management: Coordinate vulnerability scanning and penetration testing. Actively manage the Plan of Action and Milestones lifecycle to ensure timely remediation of security weaknesses.
• Security Engineering Support: Integrate security into the System Development Life Cycle (SDLC) by evaluating control implementations and enforcing secure baselines (e.g., DISA STIGs, CIS Benchmarks).
• Incident & Contingency Operations: Support the detection and containment of security incidents. Assist in drafting, testing, and updating Incident Response Plans and Contingency Plans.
• Compliance Enforcement: Validate user access requirements, enforce agency-specific security policies, and ensure completion of role-based security training.
• Minimum 3–5 years of direct experience in federal ISSO duties, cybersecurity documentation, or information assurance support for FISMA Moderate or higher programs
• No problems, only solutions!
Educational and Certification Requirement:
• Bachelor's degree in Cybersecurity, Information Technology, Computer Science, or a related field
• Security+; CAP or comparable RMF certification preferred
group id: 91021658