DescriptionIn support of this mission, we have an immediate opportunity for an
Information System Security Officer (ISSO). In this role you will independently own the security posture of a portfolio of DHS Intelligence Enterprise systems, including Cross Domain Solutions and cloud-hosted systems, in accordance with ICD 503 and DHS 4300C. You will maintain ATO packages, manage POA&Ms and change control, and serve as a SCIF Information Security Compliance Representative (ISCR). This position is on-site in a Government SCIF in Washington, DC.
Duties include but not limited to:
- Create and maintain ATO packages for assigned systems in the GRC tool and monitor their compliance.
- Perform self-assessments of assigned on-premise and cloud systems against the A&A SOP.
- Manage POA&Ms, waivers, and risk exceptions; provide weekly or bi-weekly activity reports.
- Perform audit log reviews at least weekly, respond to NOSC alerts, and ensure periodic scanning.
- Coordinate system changes through IATT requests and serve on the Configuration Management Board when designated.
- Facilitate annual contingency plan tests and submit quarterly CPEM reporting.
- Deliver ISSO reports (incident response, POA&M, ConMon metrics) to ISSMs and system owners.
- Serve as SCIF ISCR and mentor junior ISSOs.
Requirements- BS degree in Information Technology, Cybersecurity, Information Systems, or Computer Science OR minimum of 6 years' experience in IT or cybersecurity.
- Minimum of 3 years' experience as an ISSO or in RMF package ownership.
- Active TS/SCI clearance and U.S. citizenship; willingness to undergo a DHS counterintelligence-scope polygraph.
- Knowledge of the Risk Management Framework (RMF), NIST SP 800-37, NIST SP 800-53, and ICD 503.
- Knowledge of Cross Domain Solution engineering and governance, including NCDSMO mandates and Raise the Bar requirements.
- Knowledge of hybrid classified/unclassified, on-premise and cloud environments, DevSecOps, and agile methodologies.
- Skill in securing Linux and Windows operating systems and cloud technologies.
- Skill in managing change control and authorization impacts.
- Ability to independently manage a portfolio of systems.
- Proficient in Microsoft Office Suite to include Teams or similar workplace chat and videoconferencing tools.
- Excellent written and oral communications skills.
Desired
- CGRC (formerly CAP), CompTIA Security+, or CySA+ certification.
- Experience with RSA Archer, eMASS, or a similar GRC tool.