Information System Security Officer (ISSO)

Tria Federal

$95K — $115K *
Information Technology
Less than 5 years of experience
Job Overview by Ladders

Qualifications

  • DHS Public Trust clearance required
  • 3-5 years of experience in Cybersecurity
  • Familiarity with CSAM and NIST RMF frameworks
  • Proven knowledge of obtaining and maintaining system ATO
  • Strong ability in risk assessment and management of cyber risks
  • Excellent communication skills for technical and non-technical audiences
  • Relevant security certifications such as Security+ or CISSP

Responsibilities

  • Conduct security assessments and secure Authorization to Operate (ATO) according to NIST guidelines
  • Maintain ongoing ATO status for assigned systems
  • Continuously update documentation for Security Authorization to reflect the current system status
  • Select and tailor baseline security controls using CSAM GRC Tool
  • Document all NIST 800-53 Security Controls in System Security Plans (SSP)
  • Perform initial and annual risk assessments for assigned systems
  • Develop comprehensive supporting artifacts for Security A&A processes

Benefits

  • Opportunity to work in a dynamic team environment
  • Access to professional development resources and training
  • Engagement with cutting-edge cybersecurity technologies
  • Exposure to a variety of security frameworks and compliance standards
  • Potential for career advancement within the organization
Full Job Description
Job Description:

Tria Federal (Tria) is seeking a motivated and detail-oriented Information System Security Officer (ISSO) to join our team. The ISSO research, develops, implements, tests, and reviews an organization's information security to protect information and prevent unauthorized access. Emphasis on knowledge of infrastructure devices (i.e. firewalls, routers, switches)

Requirements:
  • DHS Public Trust
  • 3-5 years Cybersecurity experience
  • Working knowledge and experience with CSAM and the NIST RMF
  • Solid knowledge of the process to obtain a system ATO and requirements to maintain the ATO
  • Experience working with system stakeholders to assess and manage system cybersecurity risk
  • Ability to synthesize complex IT system information and communicate system status and requirements in written products and verbal presentations
  • Ability to write clear, concise and effective security control implementation statements
  • Familiarity with configuration settings and vulnerability management analysis of infrastructure devices
  • Ability to draft a complete ATO package, to include the SSP
  • Ability to work independently, and efficiently, with minimal direct supervision, and within given timelines
  • Security+ Certification
  • CSAM GRC Tool
  • DHS Experience

Qualifications:
  • BS in Computer Science, Information Technology, or related field
  • CISSP, Security+, CGRC (formerly CAP), CISM

Responsibilities:
  • Conduct initial Security Assessment and obtain system Authorization to Operate (ATO), in line with NIST SP 800-37 Rev. 2.
  • Maintain the Security Authorization or ATO of assigned system(s)
  • Continuously update all Security Authorization documentation to maintain assigned system's ATO or system go-live dates.
  • Select the baseline security controls for the IT system, using the CSAM Governance, Risk, and Compliance (GRC) Tool, and tailor controls where appropriate.
  • Document all relevant NIST 800-53 Security Controls for assigned IT systems in the System Security Plan (SSP).
  • Perform and document initial and annual risk self-assessments of all systems assigned
  • Develop and document all supporting Security A&A artifacts (i.e., PTA, SSP, ITCP, BIA, CMP, MOU, ISA).
  • Produce Security Authorization package for Authorizing Official (AO) signature including ATO
  • Track the deployment of software to the environment that is not part of the base image.
  • Conduct security impact analyses of proposed changes, provide recommendations.
  • Ability to analyze configuration settings, implementation of STIGs, and conducting manual checklists.
  • Generate and manage Plan of Action & Milestones (POA&Ms), with meaningful milestones, and clear/concise implementation statements for each non-compliant control for assigned IT Systems.


Similar Jobs

More Information Technology Jobs

Find similar Information System Security Officer (ISSO) jobs: