Search

Information Systems Security Officer (ISSO)

PublishedPublished: 6/14/2022
Technology

Job Description

Job Description

Position Overview

8 Consulting is seeking an Information Systems Security Officer (ISSO) to support federal cybersecurity and information assurance activities in a hybrid environment based in Washington, DC. The position will support the security authorization and ongoing monitoring of federal information systems and will work with technical teams, system owners, cybersecurity personnel, and Government stakeholders.

The successful candidate will have experience with the Risk Management Framework, security control assessment and documentation, Continuous Monitoring, vulnerability management, POA&M activities, and audit or compliance support.

Responsibilities

  • Support the NIST Risk Management Framework lifecycle for federal information systems.
  • Develop, review, and maintain security authorization documentation, including System Security Plans, Security Assessment Plans, Security Assessment Reports, POA&Ms, and supporting security artifacts.
  • Support initial authorizations, reauthorizations, annual assessments, and ongoing authorization activities.
  • Review and document security control implementation and supporting evidence.
  • Perform Continuous Monitoring activities and support recurring security posture reporting.
  • Review vulnerability findings, coordinate remediation activities, and track findings through closure.
  • Maintain POA&M records and support risk analysis and remediation tracking.
  • Support Security Impact Analysis activities associated with system and configuration changes.
  • Assist with cybersecurity audits, assessments, inspections, and compliance reviews.
  • Coordinate with system owners, administrators, engineers, cybersecurity personnel, and assessors.
  • Maintain current and audit-ready security documentation.
  • Support incident response coordination and related cybersecurity documentation.
  • Participate in cybersecurity governance meetings and provide status, risk, and technical updates as required.

Required Qualifications

  • Experience supporting cybersecurity, information assurance, or information system security functions in a federal environment.
  • Experience with NIST RMF and NIST SP 800-53.
  • Experience supporting ATO, reauthorization, or security assessment activities.
  • Experience developing or maintaining SSPs, POA&Ms, assessment documentation, control evidence, or related authorization artifacts.
  • Knowledge of Continuous Monitoring, vulnerability management, risk management, and security compliance activities.
  • Ability to evaluate technical and compliance information and develop clear written security documentation.
  • Strong written and verbal communication skills.
  • Ability to work with technical and non-technical stakeholders.
  • U.S. Citizenship.
  • Ability to obtain and maintain required Government suitability or security eligibility.
  • Ability to work onsite in Washington, DC on a hybrid schedule.

Preferred Qualifications

  • Experience supporting FISMA Moderate information systems.
  • Experience with federal civilian agencies.
  • Experience supporting multiple information systems or concurrent authorization activities.
  • Familiarity with GRC, SIEM, vulnerability management, and IT service management platforms.
  • Experience with tools such as CSAM, ServiceNow, Splunk, Tenable, Qualys, Microsoft Defender, Azure, Microsoft 365, Intune, or similar technologies.
  • Relevant cybersecurity certifications such as Security+, CISSP, CAP/CGRC, CISM, or equivalent.

Work Environment

This position will operate in a hybrid environment with recurring onsite support in Washington, DC. Additional onsite support may be required based on operational needs.

Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...