Job Requirements
Ashburn, VA
Public Trust Polygraph Unspecified
Career Level not specified
$120,000 - $144,000
Job Description
ISSO Jr
On site in Ashburn, VA - Monday through Friday, 8:30am to 5:00pm
The Information Systems Security Officer (ISSO) supports the overall information security posture of assigned Major Applications (MAs) and General Support Systems (GSSs) for a large federal agency. You will serve as the subject-matter expert and principal point of contact for all system security requirements on assigned FISMA systems, providing expert guidance and leadership in implementing, maintaining and enforcing information security policies, standards and methodologies in accordance with federal regulations and agency requirements.
Responsibilities:
Requirements:
Preferred: CISSP and/or CISM certification.
Compensation: $120,000 - $144,000 per year
#cjpost
On site in Ashburn, VA - Monday through Friday, 8:30am to 5:00pm
The Information Systems Security Officer (ISSO) supports the overall information security posture of assigned Major Applications (MAs) and General Support Systems (GSSs) for a large federal agency. You will serve as the subject-matter expert and principal point of contact for all system security requirements on assigned FISMA systems, providing expert guidance and leadership in implementing, maintaining and enforcing information security policies, standards and methodologies in accordance with federal regulations and agency requirements.
Responsibilities:
- Serve as the subject-matter expert and principal point of contact for security requirements on assigned FISMA systems (MAs, GSSs and sub-systems/applications).
- Complete and maintain system authorization packages - System Security Plans, Interconnection Security Agreements, Contingency Plans, POA&Ms, waivers and exceptions - in the agency's FISMA system management tool, supporting the NIST Risk Management Framework (RMF).
- Ensure assigned systems are operated, maintained and disposed of in accordance with NIST SP 800-37 Rev. 2 and agency security policy and handbooks.
- Perform periodic security management activities and monthly audit log reviews for assigned systems, identifying and documenting security anomalies.
- Work with system administrators, security engineers and system owners to document and track system weaknesses as POA&Ms; recommend and track corrective actions through remediation.
- Support risk acceptance and waiver requests, system access request reviews, and endorsement or rejection determinations with documented justification.
- Investigate and report security incidents to agency security leadership and ensure protective or corrective measures are initiated when an incident or vulnerability is discovered.
- Review Privacy Threshold Analyses (PTAs) and Privacy Impact Assessments (PIAs) and provide documented security feedback to system and business owners.
- Lead, prepare materials for and participate in meetings supporting assessment and authorization, vulnerability/POA&M reviews, and internal and external audits.
- Support the transition to and maintenance of an Ongoing Authorization (OA) program for assigned systems.
- Provide audit support and liaison between auditors (e.g., OIG and annual independent audits) and agency cybersecurity staff, including artifact collection and responses across FISMA, FISCAM and OMB Circular A-123 areas.
Requirements:
- Bachelor's degree in Computer Science or a related field, or equivalent experience.
- Minimum 3 years of information security experience on programs of comparable scope and complexity.
- Solid knowledge of FISMA, NIST and the Risk Management Framework (RMF) methodology.
- Experience with security authorization processes (Certification & Accreditation and Authorization to Operate) and the ability to develop the associated documentation.
- Strong understanding of security tools, hardware/software security implementation, communication protocols and encryption techniques.
- Proven ability to analyze security vulnerabilities, deliver comprehensive assessments and develop effective remediation instructions.
- Excellent written and verbal communication skills, with the ability to present complex security information clearly to technical and executive audiences.
- Ability to work on site in Ashburn, VA (no telework).
- US Citizenship (no dual citizenship) and the ability to pass a federal background investigation in order to be granted access to sensitive information.
Preferred: CISSP and/or CISM certification.
Compensation: $120,000 - $144,000 per year
#cjpost
group id: 10238000