Information Systems Security Officer

Business Operational Concepts, LLC

• $100K — $130K *
Information Technology
5 - 7 years of experience
Job Overview by Ladders

Qualifications

  • Bachelor's degree or equivalent IT-related experience
  • 5+ years of hands-on ISSO or equivalent experience in a federal environment
  • Experience maintaining security documentation such as SSPs, SARs, and ATOs
  • Proficient in continuous monitoring, vulnerability management, and risk assessments
  • Knowledge of privacy compliance processes like PTAs and PIAs

Responsibilities

  • Advise IT management and senior staff on security and privacy for information systems
  • Support various agency systems and cloud environments while adhering to federal policies
  • Coordinate system categorization, define boundaries, and manage interconnection agreements
  • Assist with implementing NIST Cybersecurity Framework 2.0 and related governance activities
  • Update cybersecurity processes and artifacts to align with NIST CSF 2.0
  • Support privacy compliance initiatives and non-functional requirement remediation
  • Maintain cybersecurity documentation for status reporting and compliance checks

Benefits

  • Full-time employment in a reputable organization
  • Opportunities for professional development and training
  • Occasional travel for project requirements
  • Potential exposure to diverse cybersecurity challenges and federal environments
Full Job Description
Job Title

Information Systems Security Officer

Location

Washington, DC 20002 US (Primary)

Category

Information Technology

Job Type

Full Time

Career Level

Professional

Education

Refer to Job Requirements: Qualifications

Travel

Occasional

Salary Range

$100,000 - $130,000

Security Clearance Required

None

Salary Grade

Job Description

JOB SUMMARY:

Business Operational Concepts (BOC) is currently seeking a seeking an Information System Security Officer (ISSO) to work with our federal client. The ideal candidate will support cybersecurity, governance, risk management, compliance, engineering, automation, and program management activities for the federal client.

The ISSO will support agency information systems and cybersecurity processes in accordance with federal cybersecurity requirements and will assist with implementation of the NIST Cybersecurity Framework (CSF) 2.0, Risk Management Framework activities, system authorization, continuous monitoring, vulnerability management, privacy compliance, and related cybersecurity activities.

DUTIES AND RESPONSIBILITIES:
  • Serve as an advisor to IT management, system owners, business process owners, and senior management on matters related to the security and privacy of assigned information systems.
  • Support applicable agency systems, cloud environments, on-premises infrastructure, hybrid systems, SaaS platforms, identity services, endpoint platforms, vulnerability management tools, logging and monitoring platforms, and security governance processes.
  • Coordinate with stakeholders to categorize systems, define system boundaries, establish interconnection agreements, and support adherence to applicable federal policies, including Zero Trust principles where applicable.
  • Support cybersecurity governance, risk management, compliance, engineering, automation, and program activities associated with implementation of NIST Cybersecurity Framework 2.0.
  • Develop and/or update cybersecurity processes and artifacts in alignment with NIST CSF 2.0.
  • Support Privacy Threshold Analyses (PTAs), Privacy Impact Assessments (PIAs), and other privacy compliance activities.
  • Support identification, tracking, remediation, and closure of Non-Functional Requirements (NFRs) and security findings.
  • Support transition from a static three-year system authorization model to an ongoing authorization and Continuous Monitoring model.
  • Support the agency's use of the Caveonix platform for governance, risk, compliance, and continuous monitoring activities.
  • Assess and support Authority to Operate (ATO) packages for assigned systems.
  • Develop and maintain required system authorization artifacts, including:
    • System Security Plans (SSPs)
    • Security Assessment Reports (SARs)
    • Plans of Action and Milestones (POA&Ms)
    • Security Impact Analyses (SIAs)
  • Support Continuous Monitoring activities, including security control validation, vulnerability management, risk assessments, evidence collection, cybersecurity metrics, and reporting.
  • Support applicable federal and agency cybersecurity, security, privacy, and AI requirements.
  • Support cybersecurity activities associated with the agency's cloud environment, including Azure and Microsoft 365, as required.
  • Support cybersecurity activities associated with changes to infrastructure and security posture.
  • Provide ongoing cybersecurity subject-matter support, including support for annual FISMA audit activities.
  • Maintain required cybersecurity documentation and provide status and supporting information as required by program management and the Government.


Job Requirements

QUALIFICATIONS:

Required (Minimum) Qualifications - Education, Certification, Experience, and Skills
  • A Bachelor's degree or equivalent work experience in an IT-related field.
  • A minimum of five (5) years of hands-on experience performing ISSO or equivalent functions in a federal environment.
  • Demonstrated experience developing and maintaining:
    • SSPs
    • SARs
    • POA&Ms
    • SIAs
    • ATO documentation
  • Experience with:
    • Continuous Monitoring
    • Vulnerability Management
    • Risk Assessments
    • Privacy compliance activities, including PTA and PIA support.

Preferred Qualifications - Education, Certification, Experience, Skills, Knowledge, and Abilities
  • Required Certification
    • CompTIA Security+
  • Preferred Certifications
    • The following certifications are preferred but are not required:
    • (ISC)² Certified Information Systems Security Professional (CISSP)
    • Certified Information Security Manager (CISM)
    • Certified Information Systems Auditor (CISA)

Similar Jobs

More Jobs at Business Operational Concepts, LLC

More Information Technology Jobs

Find similar Information Systems Security Officer jobs: