Information Systems Security Officer (ISSO)

Dynamic Solutions Technology LLC

$110K — $130K *
Information Technology
5 - 7 years of experience
Job Overview by Ladders

Qualifications

  • Bachelor's degree with a focus on technical education and cybersecurity certification required.
  • Security+ certification or equivalent based on applicable DoD requirements is mandatory; higher-level certifications preferred.
  • At least 6 years of experience in information systems security or cybersecurity required.
  • Minimum 5 years of direct RMF experience is essential.
  • Proven track record in developing and maintaining critical security documentation such as SSPs and SARs is necessary.
  • Experience leading ConMon and vulnerability management activities is necessary.
  • Familiarity with NIST standards and Federal cybersecurity frameworks is important.

Responsibilities

  • Implement and improve the Risk Management Framework (RMF) for government information systems.
  • Develop and maintain security authorization artifacts and documentation.
  • Assist in system categorization, security control implementation, and ATO preparation.
  • Support continuous monitoring, vulnerability assessments, and security audits.
  • Analyze security data to identify weaknesses and recommend corrective measures.
  • Manage remediation activities for POA&M items and escalate critical issues.
  • Collaborate with various stakeholders to rectify security deficiencies.
  • Conduct quality assurance checks on RMF documentation to ensure compliance.

Benefits

  • Hybrid remote work model with minimum in-office requirement.
  • Opportunity to engage in various cybersecurity projects and frameworks.
  • Collaboration with federal customers and cybersecurity stakeholders.
  • Focus on continuous professional development through certification support.
  • Involvement in governance meetings and technical reviews promoting career growth.
Full Job Description
Information Systems Security Officer (ISSO) to support the government customer located in Washington, DC. This is an exempt hybrid remote position. (A minimum of TWO days per week reporting to site; additional support as needed on a case-by-case basis)

MUST BE A U.S. CITIZEN

Responsibilities:
  • Support the implementation, maintenance, and continuous improvement of the Risk Management Framework (RMF) for assigned Federal information systems.
  • Develop, review, update, and maintain RMF and authorization artifacts, including System Security Plans (SSPs), Security Assessment Reports (SARs), POA&Ms, control narratives, risk assessments, and supporting evidence.
  • Assist with system categorization, security control implementation, control assessments, authorization activities, and preparation of ATO documentation.
  • Support Continuous Monitoring (ConMon), vulnerability management, configuration reviews, security assessments, audits, inspections, and cybersecurity remediation activities.
  • Monitor system security posture and analyze security, vulnerability, configuration, and compliance data to identify deficiencies and recommend corrective actions.
  • Maintain and track POA&M items, risks, vulnerabilities, findings, and security issues; coordinate remediation activities and escalate overdue or high-risk issues.
  • Coordinate with System Owners, common-control providers, system administrators, cloud-service personnel, and other cybersecurity stakeholders to obtain evidence and resolve security deficiencies.
  • Conduct quality-control reviews of RMF deliverables and security documentation to ensure accuracy, completeness, consistency, and compliance with applicable Federal cybersecurity requirements.
  • Participate in technical reviews, cybersecurity working groups, governance meetings, and incident-response coordination activities, providing technical input and status updates.
  • Maintain working proficiency with applicable cybersecurity tools and platforms, including CSAM, ServiceNow, Splunk, Tenable/Nessus, Qualys, Microsoft Defender, Intune, BigFix, Azure, Microsoft 365, Entra ID, Okta, Palo Alto Panorama, and Zscaler, as required by the task order.

Education, Certifications, and Experience:
  • Bachelor's-level technical education and a cybersecurity certification meeting the applicable contract and Federal qualification requirements are required.
  • Security+ or an equivalent certification meeting applicable DoD 8140/8570 requirements is required, with higher-level certifications such as CISSP, CAP, CISM, CASP+, CCSP, or GIAC certifications preferred based on assigned duties.
  • Minimum of 6 years of progressively responsible experience in information systems security, cybersecurity, information assurance, or a related discipline
  • Minimum of 5 years of hands-on experience supporting the Risk Management Framework (RMF), including security control implementation, assessment, authorization, continuous monitoring, POA&M management, and security documentation.
  • Demonstrated experience developing, reviewing, maintaining, and submitting System Security Plans (SSPs), Security Assessment Reports (SARs), Plans of Action and Milestones (POA&Ms), risk assessments, security control documentation, and other authorization-package artifacts.
  • Experience leading Continuous Monitoring (ConMon), vulnerability management, security assessments, audits, inspections, and cybersecurity remediation activities.
  • Experience with Federal cybersecurity standards and frameworks, including NIST SP 800-53, NIST RMF, FISMA, and applicable Federal and DoD cybersecurity policies.
  • Working knowledge of enterprise cybersecurity technologies and platforms, including CSAM, Splunk, ServiceNow, Tenable/Nessus or Qualys, Microsoft Defender, Microsoft Intune, BigFix, Microsoft Azure, Microsoft 365, Microsoft Entra ID, Okta, Palo Alto Panorama, and Zscaler, with specific tools subject to task-order requirements.

Similar Jobs

More Jobs at Dynamic Solutions Technology LLC

More Information Technology Jobs

Find similar Information Systems Security Officer (ISSO) jobs: