user avatar

Information System Security Officer (ISSO) - L3

Prism, Inc.

Posted today

Job Requirements

Lorton, VA
Top Secret/SCI Polygraph Unspecified
Career Level not specified
Salary not specified
Join Premium to unlock estimated salaries

Job Description

ABOUT PRISM
PRISM is devoted to modernization and innovation within the world of technology, security, and IT enterprise solutions. We are recognized for meeting performance requirements and exceeding customer expectations since 1994. Our culture is founded on relationships, opportunity, and success. Offering comprehensive benefit plans including medical, dental, vision, and 401K along with our people - first approach sustains our reputation as a premier employer.

PRISM is seeking an Information System Security Officer (ISSO) in Lorton, VA to support cybersecurity, compliance, and risk management for classified DoD information systems. In this role, you will partner with the ISSM, system administrators, and program stakeholders to maintain Risk Management Framework (RMF) compliance, manage authorization packages, and execute continuous monitoring across JSIG, SAP, and SCI environments.

KEY RESPONSIBILTIES:
ISSM Support & Core Security Authorities:
Assist the ISSM in meeting their duties and responsibilities, and assume ISSM responsibilities in the ISSM's absence.
Ensure systems are operated, maintained, and disposed of in accordance with security policies and procedures outlined in the security authorization package.
Verify that all users possess the requisite security clearances, authorization, and need-to-know, and are aware of their security responsibilities prior to being granted access to the system.
Report all security-related incidents to the ISSM.
Conduct periodic reviews of information systems to verify continued compliance with the security authorization package.
Serve as a member of the Configuration Control Board (CCB) when designated by the ISSM.
Coordinate any changes or modifications to system hardware, software, or firmware with the ISSM and Authorizing Official/Designated Authorizing Official (AO/DAO) prior to implementation.
Formally notify the ISSM and AO/DAO when changes occur that might affect the system's security authorization.
Monitor system recovery processes to confirm security features and procedures are properly restored and functioning correctly.
Maintain an equivalent IAM Level 2 certification based on the DoD 8140 standard.
Participate in joint agile backlog planning, providing feedback to the software development and infrastructure teams on high- and medium-risk items that require Information System Owner approval.
Cybersecurity Compliance & RMF Support:
Support the implementation and maintenance of cybersecurity requirements in accordance with JSIG, RMF, and applicable DoD policies.
Develop, maintain, and update RMF documentation including:
System Security Plans (SSPs)
Security Control Traceability Matrices (SCTMs)
Plans of Action and Milestones (POA&Ms)
Security Assessment Reports (SARs)
Continuous Monitoring Plans
Ensure security controls are implemented and maintained in accordance with approved security baselines.
Support security authorization efforts throughout the RMF lifecycle.
Continuous Monitoring & Vulnerability Management:
Conduct continuous monitoring activities to maintain system authorization.
Conduct and analyze vulnerability scan results from security tools such as ACAS and SPLUNK.
Track remediation efforts and validate closure of identified vulnerabilities.
Assist with risk assessments and development of mitigation strategies.
Monitor system changes for security impact and support configuration management activities.
Security Operations:
Coordinate and support security audits, inspections, and assessments.
Maintain security-related records, reports, and artifacts required for compliance reviews.
Investigate and document cybersecurity incidents and assist with incident response activities.
Ensure audit records are collected, reviewed, retained, and documented in accordance with security requirements, including any identified anomalies.
Verify proper implementation of system hardening standards and security configurations.
Work with information system security engineers to ensure secure system configurations.
Review proposed system changes and evaluate security implications.
Validate compliance with approved configuration baselines.
Support enforcement of least privilege and separation of duties principles.
Provide security guidance to system users and administrators.
Documentation & Reporting:
Maintain accurate cybersecurity documentation and records, ensuring all IS security-related documentation is current and accessible to properly authorized individuals.
Prepare reports and briefings for program leadership, ISSM, and government representatives.
Support internal and external cybersecurity assessments.
Develop and maintain the Body of Evidence required for audits and authorization activities.

REQUIRED QUALIFICATIONS:(SKILLS/EDUCATION):
Bachelor's degree in Cybersecurity, Information Technology, Computer Science, Information Systems (related degree field) and 5+ years of cybersecurity, information assurance, or information systems security experience. OR 10+ years of relevant experience.
Experience supporting SAP, SCI, or other classified environments.
Working Knowledge of JSIG requirements, NIST SP 800-53, DoD RMF process, STIG implementation and compliance, Vulnerability management process.
Strong understanding of cybersecurity principles and risk management practices.
Experience supporting security assessments and authorization packages.
Knowledge of cloud security requirements within DoD environments.
Active TS/SCI clearance required.
Current DoD 8570/8140 compliant certification such as: CISA, CASP+, CISSP, CISM.
Must be within driving distance of Lorton, VA OR willing to relocate there (Relocation Assistance Package Available)
Must be willing to work onsite (This role may include the need to work outside of core hours on high priority investigations and may also include on-call responsibilities)
Strong written and verbal communication skills with excellent attention to detail and documentation accuracy.
Ability to work independently and collaboratively in a mission-focused environment.
Must be willing and able to travel frequently.

DESIRED QUALIFICATIONS:
Experience with Windows, Linux, and virtualized environments.
Familiarity with Cross Domain Solutions (CDS).
Experience with ACAS, Splunk, Tenable, Trellix ePO or similar cybersecurity tools.
Excellent analytical and problem-solving skills.
Ability to work independently and collaboratively in a mission-focused environment.
Strong attention to detail and documentation accuracy.
You are an excellent communicator in writing and speaking.
You have the ability to work independently but also value teamwork.
Your problem-solving skills are excellent.
You are Looking for a job where performance appraisals occur regularly, and you look forward to advancing your career.
You seek a community of virtue-centered co-workers and clients.

REQUIRED SECURITY CLEARANCE:
Active Top Secret SCI

PRISM is an Equal Opportunity/Affirmative Action employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability, or veteran status, or any other protected class.
group id: PRISMVA
Find Prism, Inc. on Social Media
Recruiters
user avatar
About Us
PRISM is devoted to modernization and innovation within the world of technology, security, and IT enterprise solutions. For over 25 years, PRISM has provided IT Professional services to Defense, Homeland Security, Civilian, Healthcare, and Commercial customers. Named as one of the top-performing technology companies in the greater D.C. area allows our employees to feel confident in our tradition of excellence. Ranked among the top 10 best companies for Veterans, we pride ourselves on our commitment to hiring and supporting U.S military Veterans and their families. PRISM’s support continues with our employees by creating a fun and trusted community. Offering Comprehensive Benefit plans along with a spirit of Family, Success, and Opportunities ensures “IT relationships that work.” Check out our website at www.prisminc.com to learn more about the exciting opportunities at PRISM Inc!

Prism, Inc. Jobs


Job Category
IT - Security
Clearance Level
Top Secret/SCI
Employer
Prism, Inc.