DescriptionThe ISSO is responsible for verifying, managing, and maintaining the security posture of the organization's systems by adhering to Federal security standards and frameworks. They oversee cybersecurity measures, monitor threats, and ensure compliance with regulatory requirements. The ISSO serves as the key point of contact for all security-related matters and collaborates with various teams, system administrators, and security professionals to protect sensitive data, implement effective security measures, and maintain system integrity.
- Develop, implement, maintain, and enforce the organization's information security policies, procedures, and guidelines in compliance with Federal standards.
- Conduct regular security and risk assessments, vulnerability scans, and risk analyses to identify and mitigate potential security threats and vulnerabilities.
- Ensure compliance with Federal regulations, such as FISMA, NIST, and other relevant security frameworks.
- Monitor and respond to security incidents and breaches, unauthorized access, and cyber threats. This includes conducting investigations and reporting the findings to the appropriate authorities.
- Coordinate with system administrators and other teams to apply security patches and updates.
- Investigate security incidents and coordinate responses to mitigate risks.
- Provide security training and awareness programs for employees and contractors to promote a culture of security within the organization.
- Collaborate with IT and other departments to ensure the secure configuration and operation of all information systems and networks.
- Maintain and update the System Security Plan (SSP) and other required documentation for Federal customers.
- Maintain and update security documentation and records for audits and compliance reviews.
- Coordinate and participate in security audits and assessments conducted by external agencies or customers.
- Stay abreast of the latest security trends, technologies, and best practices to continuously improve the organization's security posture.
- Recommend improvements to security policies and procedures based on emerging threats.
Requirements- Must be a U.S. citizen and have the ability to obtain and maintain a Secret security clearance.
- Bachelor's degree in Cybersecurity, Information Technology, Computer Science, or a related field.
- 5+ years of relevant cybersecurity experience, with a focus on Federal systems and risk management
- Strong understanding of Federal security standards and frameworks, such as FISMA, NIST, and RMF.
- Experience with security tools such as SIEM, vulnerability scanners, access control methods, and incident response.
- Familiarity with security technologies, including firewalls, intrusion detection/prevention systems, encryption, and endpoint protection.
- Excellent communication and interpersonal skills, with the ability to effectively communicate security concepts to non-technical stakeholders.
- Security+ and Certified Information Systems Security Professional (CISSP) or equivalent certification.
- Experience with implementing and managing security controls in cloud environments.
- Knowledge of Federal security compliance requirements and the ability to interpret and apply them to the organization's operations.
- Proven track record of successfully managing and securing information systems for Federal customers.
- Ability to work independently and manage multiple tasks and priorities in a fast-paced environment.
- Strong analytical and problem-solving skills, with keen attention to detail.
Desired Qualifications- Certified Information Security Manager (CISM) or Certified Information Systems Auditor (CISA) is a plus.
- Knowledge of cloud security (AWS, Azure, etc.) is a plus.