Job Title
Information Systems Security Officer
Location
Washington, DC 20002 US (Primary)
Category
Information Technology
Job Type
Full Time
Career Level
Professional
Education
Refer to Job Requirements: Qualifications
Travel
Occasional
Salary Range
$100,000 - $130,000
Security Clearance Required
None
Salary Grade
Job Description
JOB SUMMARY:Business Operational Concepts (BOC) is currently seeking a seeking an
Information System Security Officer (ISSO) to work with our federal client. The ideal candidate will support cybersecurity, governance, risk management, compliance, engineering, automation, and program management activities for the federal client.
The ISSO will support agency information systems and cybersecurity processes in accordance with federal cybersecurity requirements and will assist with implementation of the NIST Cybersecurity Framework (CSF) 2.0, Risk Management Framework activities, system authorization, continuous monitoring, vulnerability management, privacy compliance, and related cybersecurity activities.
DUTIES AND RESPONSIBILITIES:- Serve as an advisor to IT management, system owners, business process owners, and senior management on matters related to the security and privacy of assigned information systems.
- Support applicable agency systems, cloud environments, on-premises infrastructure, hybrid systems, SaaS platforms, identity services, endpoint platforms, vulnerability management tools, logging and monitoring platforms, and security governance processes.
- Coordinate with stakeholders to categorize systems, define system boundaries, establish interconnection agreements, and support adherence to applicable federal policies, including Zero Trust principles where applicable.
- Support cybersecurity governance, risk management, compliance, engineering, automation, and program activities associated with implementation of NIST Cybersecurity Framework 2.0.
- Develop and/or update cybersecurity processes and artifacts in alignment with NIST CSF 2.0.
- Support Privacy Threshold Analyses (PTAs), Privacy Impact Assessments (PIAs), and other privacy compliance activities.
- Support identification, tracking, remediation, and closure of Non-Functional Requirements (NFRs) and security findings.
- Support transition from a static three-year system authorization model to an ongoing authorization and Continuous Monitoring model.
- Support the agency's use of the Caveonix platform for governance, risk, compliance, and continuous monitoring activities.
- Assess and support Authority to Operate (ATO) packages for assigned systems.
- Develop and maintain required system authorization artifacts, including:
- System Security Plans (SSPs)
- Security Assessment Reports (SARs)
- Plans of Action and Milestones (POA&Ms)
- Security Impact Analyses (SIAs)
- Support Continuous Monitoring activities, including security control validation, vulnerability management, risk assessments, evidence collection, cybersecurity metrics, and reporting.
- Support applicable federal and agency cybersecurity, security, privacy, and AI requirements.
- Support cybersecurity activities associated with the agency's cloud environment, including Azure and Microsoft 365, as required.
- Support cybersecurity activities associated with changes to infrastructure and security posture.
- Provide ongoing cybersecurity subject-matter support, including support for annual FISMA audit activities.
- Maintain required cybersecurity documentation and provide status and supporting information as required by program management and the Government.
Job Requirements
QUALIFICATIONS:Required (Minimum) Qualifications - Education, Certification, Experience, and Skills- A Bachelor's degree or equivalent work experience in an IT-related field.
- A minimum of five (5) years of hands-on experience performing ISSO or equivalent functions in a federal environment.
- Demonstrated experience developing and maintaining:
- SSPs
- SARs
- POA&Ms
- SIAs
- ATO documentation
- Experience with:
- Continuous Monitoring
- Vulnerability Management
- Risk Assessments
- Privacy compliance activities, including PTA and PIA support.
Preferred Qualifications - Education, Certification, Experience, Skills, Knowledge, and Abilities- Required Certification
- Preferred Certifications
- The following certifications are preferred but are not required:
- (ISC)² Certified Information Systems Security Professional (CISSP)
- Certified Information Security Manager (CISM)
- Certified Information Systems Auditor (CISA)