user avatar

Information Systems Security Officer

NexTech Solutions LLC

Posted today

Job Requirements

northern, VA
Secret Polygraph Unspecified
Career Level not specified
Salary not specified
Join Premium to unlock estimated salaries

Job Description

The Opportunity

The ISSO, working closely with the customer's ISSO, directly supports efforts to plan, coordinate and implement the information security program and system accreditation lifecycle. Responsible for enterprise and system-level cybersecurity engineering tasks. Identifies security risks and integrates required security controls as set forth by policy. Ensures security compliance of information technology applications. Responsible for monitoring security policies and procedures, coordinating internal security audits and security exercises, delivering required security training and participating in coordination meetings.

Key Responsibilities (Principal Duties and Accountabilities *Essential Functions)
  • Primary liaison to customer ISSO to support the system accreditation process and Authorization to Operate (ATO) efforts, audits, and reaccreditation cycles; Utilizes customer's security governance tool for the system authorization and ATO lifecycle
  • Working closely with engineers, utilizes vulnerability scanning tools and reports to track and remediate findings
  • Evaluates and validates physical security to ensure support of systems security requirements
  • Tracks and manages Plans of Action and Milestones (POA&M's) that are out of compliance
  • Supports NIST RMF implementation and documentation including annual security control review
  • Coordinates and assists with internal security audits
  • Develops and maintains security documentation such as the System Security Plan, system boundary diagram, inventory of hardware and software, ports and protocols, etc.
  • Develops, coordinates and tests incident response plans, contingency plans and security tabletops/exercises
  • Documents system parameters and ensure all security documents are kept current
  • Asses proposed changes to information systems; identifies risks and impacts; Performs Security Impact Analysis (SIA) and submits change control requests for system enhancements to the ATO package
  • Participates in new technology enhancements and implementations and its implication on the system boundary
  • Assists in testing system function pre and post security control implementations
  • Delivers annual compliance training as mandated by policy and regulatory standard
  • Oversees user account provisioning, permission review, and access enforcement for system integrity
  • Develops and maintains Memorandum of Understanding (MOUs) and Interconnection Service Agreements (ISAs) with internal organizations and external entities to support secure information system interconnections and data sharing
  • Participating in special projects as required
group id: 91074966

Similar Jobs


Job Category
IT - Security
Clearance Level
Secret