Job SummaryInformation Systems Security Officer II
Aptive is seeking an Information Systems Security Officer (ISSO) to provide cybersecurity, risk management, and compliance support for the ICE Health Service Corps (IHSC) Health Information Technology Unit (HITU). This role helps ensure IHSC IT systems meet DHS, ICE, and federal security standards while enabling mission operations, and will lead the establishment of Authority to Operate (ATO) for four or more systems.
The ISSO supports security governance, authorization, and continuous monitoring across the enterprise, maintaining security documentation and advising leadership on cybersecurity risks and mitigation strategies. All cybersecurity activities are performed in an advisory, compliance-monitoring, and validation capacity in coordination with Government system owners and authorized vendors.
The ideal candidate understands federal cybersecurity frameworks and system authorization processes and can communicate security concepts to both technical and non-technical audiences. This role provides cybersecurity oversight, coordination, and compliance support and does not perform system configuration, implementation, or operational control functions.
Primary Responsibilities
- Support cybersecurity risk management activities, including system security planning and control implementation coordination.
- Support Authority to Operate (ATO) processes for multiple systems, including documentation, coordination, and tracking.
- Support continuous monitoring, vulnerability management, and remediation tracking.
- Provide security guidance and validation support during system design and enhancement activities.
- Collaborate with system owners, project managers, and technical teams to address security requirements.
- Support incident response coordination and security reporting activities.
- Ensure compliance with federal standards such as NIST, FISMA, and DHS security policies.
- Maintain security documentation, risk registers, and audit artifacts.
- Advise leadership on cybersecurity risks and mitigation strategies.
Minimum Qualifications
- Minimum of 3-5 years of experience supporting federal cybersecurity or IT security programs.
- Knowledge of federal cybersecurity frameworks and compliance requirements.
- Experience supporting government IT security programs.
- Strong understanding of risk management and system authorization (ATO) processes.
- Ability to communicate security concepts to technical and non-technical audiences.
- Strong documentation and coordination skills.
- Ability to obtain and maintain a DHS/ICE fitness determination (public trust) and execute a DHS Non-Disclosure Agreement.
- Legal authorization to work in the U.S.
Desired Qualifications
- Relevant industry-recognized certification (e.g., CISSP, CISM, or equivalent) preferred.
- Experience supporting DHS, ICE, or other federal IT security programs.
- Experience leading or supporting ATO efforts for multiple systems concurrently.
- Familiarity with NIST RMF, FISMA, and DHS/ICE cybersecurity policy and the ICE Cybersecurity Contract Language Catalog.
- Experience with POA&M management, SSP development, and continuous monitoring tools.