Information Systems Security Officer (ISSO)

Riverside Research Institute

$115K — $140K *
Information Technology
8 - 10 years of experience
Job Overview by Ladders

Qualifications

  • 8+ years of experience with a Bachelor's, 6 years with a Master's, 3 years with a PhD, or equivalent experience required
  • Hands-on experience with Risk Management Framework (RMF) and Cybersecurity/Information Technology
  • Current TS/SCI clearance is mandatory
  • Proficiency in RMF documentation and package development including POA&Ms and Security Plans
  • Familiarity with tools like XACTA and eMASS is preferred
  • Knowledge of NIST publications, DISA STIGs, and SRGs is important
  • Experience with NIST 800-53 and/or DISA standards is essential
  • Strong communication and organizational skills are key,

Responsibilities

  • Document and manage information systems through the RMF process
  • Promote innovative solutions for complex cybersecurity challenges
  • Serve as a Subject Matter Expert for A&A technologies
  • Conduct vulnerability assessments to identify security risks
  • Lead and engage in A&A status meetings with stakeholders
  • Identify and strategize for emerging cybersecurity policies
  • Update and review RMF documentation including Security Plans and Risk Assessments
  • Assess compliance against NIST and DoD security standards
  • Collaborate with team members to develop policy and process guidelines
  • Analyze impacts of changes in security controls on system environments
  • Produce evidence for compliance with security requirements
  • Facilitate meetings to communicate project status
  • Maintain reporting on system compliance and progress
  • Assist various programs with A&A tasks as needed

Benefits

  • Comprehensive health, dental, and vision insurance
  • 401(k) retirement savings plan with company match
  • Generous paid time off and holidays
  • Continuing education and professional development opportunities
  • Flexible work hours and the option for remote work
Full Job Description
Position Overview

Support role to perform tasks related to Cybersecurity and Assessment & Authorization (A&A) to obtain and maintain Authorizations to Operate (ATOs) for assigned systems. This position will be part of a team, supporting the Information Owner, and assisting the ISSM, to implement actions needed to document current/future baselines and new capabilities in the NIST/RMF-approved process

Responsibilities

  • Document and facilitate movement of multiple information systems through the RMF process and maintain authorizations through continuous monitoring and annual reviews
  • Promote solutions to complex problems (broadly defined) that require the regular use of expertise, creativity, specialized theories and knowledge
  • Serve as Subject Matter Expert (SME) on one or more technologies/skills related to A&A activities
  • Participate in risk and vulnerability assessments (as required) of information systems to identify vulnerabilities, risks, and protection needs
  • Actively lead and participate in regular A&A status meetings with government and contract personnel to facilitate progress and address potential issues of RMF system efforts
  • Participate in sessions aimed at identifying, planning, and executing strategies in response to emerging cybersecurity/RMF policies
  • Maintain awareness and knowledge of evolving security and risk management standards and communicate and apply relevant changes to existing processes
  • Develop, update, and/or review RMF documentation to include Security Plans, Implementation Plans, Plans of Action and Milestones (POA&Ms), and Risk Assessment Reports
  • Assess system compliance against NIST, DoD, and NSA security requirements to include the NIST 800-53 controls, and DISA Security Technical Implementation Guides (STIGs) and Security Requirements Guides (SRGs)
  • Analyze security controls and the impact of significant changes would introduce to the environment
  • Produce evidence as necessary to support compliance status of NIST, DoD, and NSA security compliance
  • Work with system administrators, engineers, and developers to create or update system/site policies, procedures, and process guides
  • Coordinate with other system SMEs to identify and develop authorization boundary diagrams, architecture diagrams, and hardware and software inventories
  • Evaluate potential security risks and make recommendations regarding corrective, mitigation, and recovery actions
  • Lead or attend meetings with system stakeholders to discuss status of efforts
  • Maintain reports to leadership regarding system/program status
  • Assist other BIG SAFARI programs/projects with A&A efforts (as directed


Qualifications

  • A minimum of 8 years of related experience with a Bachelor's degree, 6 years with a Master's degree, a PhD with 3 years' experience, or equivalent experience is typically required
  • Working knowledge of Cybersecurity / Information Technology, or four (4) years of hands-on experience with RMF, Cybersecurity/Information Technology
  • Must have a TS/SCI
  • Demonstrated efficiency and experience in RMF package development, including Plans of Actions and Milestones, Security Plans, Risk Assessments, architecture diagrams, hardware/software inventories, and system/site policies, procedures, and processes
  • Familiarity and/or experience with XACTA, eMASS, etc
  • Familiarity with NIST publications, DISA STIGS, and SRGs
  • Experience in assessing controls/systems using NIST 800-53 and/or DISA STIGs and SRGs
  • Excellent customer service and organization skills
  • Excellent oral and written communication skills
  • Ability to travel up to 25% (CONUS/OCONUS)


Global Comp

$115,000 - $140,000 This represents the typical compensation range for this position based on experience, location and other factors.

Similar Jobs

More Jobs at Riverside Research Institute

More Information Technology Jobs

Find similar Information Systems Security Officer (ISSO) jobs: