Koniag Data Solutions, a Koniag Government Services company, is seeking an experienced
Information System Security Officer (ISSO) / Control Evaluator to support a comprehensive enterprise cybersecurity services engagement for a federal civilian agency. This position requires the ability to obtain and maintain a government background investigation commensurate with a Moderate Risk designation (Minimum Background Investigation or higher) and applicable system access authorizations prior to performing work. Work will be performed primarily at the client's facility located in Washington, DC, with potential for hybrid/remote arrangements as approved.
We offer competitive compensation and an extraordinary benefits package including health, dental and vision insurance, 401K with company matching, flexible spending accounts, paid holidays, three weeks paid time off, and more.
This role sits within the Information Security Division (ISD) and supports the agency's Risk Management Framework (RMF) program, FISMA compliance obligations, continuous monitoring activities, and security controls assessment and evaluation functions across a diverse portfolio of on-premises, cloud-hosted, and hybrid information systems.
The ideal candidate is a technically proficient and operationally experienced cybersecurity professional with a deep understanding of NIST security frameworks, federal information security policy, security assessment methodologies, and the practical application of security controls across complex, multi-technology enterprise environments. This individual must possess the ability to develop and maintain in-depth technical knowledge of assigned systems, build trusted relationships with system owners and stakeholders, and independently execute a broad range of ISSO responsibilities with minimal Government direction.
The ISSO / Control Evaluator is responsible for providing comprehensive information system security officer support and security controls assessment and evaluation services across an assigned portfolio of federal information systems. This individual develops and sustains in-depth technical, operational, and working-level expertise about each assigned system, advocates for system owner needs as they align to cybersecurity and privacy requirements, and ensures each system maintains its authorization to operate in accordance with federal and agency security policies and standards.
This role requires active participation in the agency's enterprise change control processes, continuous monitoring activities, Ongoing Authorization (OA) programs, and audit support functions, as well as contributions to automation, visualization, and data structure efforts that provide real-time visibility into control status and security posture across the enterprise.
Principal responsibilities will include but are not limited to:
ISSO Core Responsibilities- Develop and sustain in-depth technical, operational, and working-level expertise about all assigned information systems, including thorough knowledge of system architecture, assets, data flows, operational environment, management hierarchy, and how each system fits into the broader enterprise IT ecosystem.
- Establish and maintain a professional rapport and trusted working relationship with system owners, program offices, and technical support personnel for all assigned systems, understanding their operational needs and advocating for those needs as they align to cybersecurity and privacy requirements.
- Read, absorb, and maintain current familiarity with all available system documentation for assigned systems, including System Security Plans (SSPs), topology diagrams, architecture diagrams, and data flow documentation.
- Establish access to and gain increasing proficiency with the operational tools, administrative consoles, and enterprise cybersecurity platforms used to manage and monitor assigned systems, extracting meaningful data to produce continuously updated control status visualizations and dashboards.
- Ensure assigned systems are onboarded into enterprise tools and reporting mechanisms, including the agency's Governance, Risk, and Compliance (GRC) tool, in accordance with established procedures and timelines.
- Actively participate in the weekly Enterprise Change Control Board (ECCB) process, ensuring security impacts of proposed changes are evaluated and documented for all assigned systems.
- Maintain current awareness of all active Acceptance of Risk (AOR) documents for assigned systems, ensuring resubmission for approval before expiration.
- Maintain knowledge management services for all accreditation-related artifacts, including appointment orders, Authority to Operate (ATO) documentation, AORs, Memoranda of Understanding/Agreement, and Data Sharing Agreements, ensuring all documents are organized and accessible in the designated central repository.
Documentation Support- Create, update, revise, and maintain cybersecurity and privacy documentation for all assigned systems across the enterprise, ensuring all documentation is aligned to applicable agency implementation procedures and reviewed for acceptance by the Office of the CIO.
- Develop and maintain the following documentation types, among others:
- System Security Plans (SSPs) with detailed, technology-specific control implementation descriptions for all technologies within the system boundary
- Configuration Management Plans (CMPs)
- Information System Contingency Plans (ISCPs) and Contingency Plan Test Reports (ISCP-TRs)
- E-authentication Risk Assessments (ERAs)
- User recertification documentation
- Architecture, topology, and data flow diagrams (OV-1 and SV-1 equivalent)
- Ensure all control implementation descriptions are written to a level of detail that demonstrates how each control is specifically implemented across all technologies within the system boundary, avoiding high-level generalizations or simple restatement of NIST control language.
- Address all Government comments, edits, and questions on documentation within 10 business days of receipt, and escalate stakeholder unresponsiveness to the Government POC after 10 business days without response.
- Ensure selected policy and procedure documents are delivered in both Adobe and Word formats and are Section 508 accessibility remediated as directed.
Controls Assessment and Evaluation Support- Provide security and privacy controls assessment and continuous monitoring assessment support for all assigned systems, including testing and validation of NIST SP 800-53 controls, documentation of NIST SP 800-53A Determine If Statements (DISs), and mapping of vulnerabilities to applicable controls.
- Develop draft Security and Risk Assessment Plans (SAPs) for delivery not less than 10 business days prior to beginning an assessment, and draft Security and Risk Assessment Reports (SARs) and Plan of Action and Milestones (POAMs) within 30 business days from point-in-time assessment kick-off.
- Conduct technical control assessments across all technology types within the system boundary (e.g., Windows, UNIX, Cisco, F5 Load Balancer), including sampling across in-scope devices, users, and services, ensuring assessments are comprehensive to the scope identified in the SAP and 100% aligned to the GRC tool.
- Develop and deliver Annual Assessment Reports (AARs) per in-scope system within 120 business days from point-in-time annual assessment kick-off, and multi-year assessment reports in accordance with applicable timelines.
- Incorporate all Government feedback into revised deliverables within 5 business days of receipt of comments, ensuring final deliverables are comprehensive, peer-reviewed, and aligned to agency templates.
- Develop assessment reports that include visual representation against the NIST Cybersecurity Framework (CSF) and are comprehensive to the scope identified in the SAP.
Ongoing Authorization (OA) Evaluation Support- For systems approved for Ongoing Authorization (OA), develop and submit an OA Playbook to the agency for approval, including a documented testing methodology for each OA core control covering Test Strategy, Test Design, Test Execution, Results Evaluation, and Visualization.
- Conduct OA Positive Testing monthly in accordance with agency implementation procedures, documenting all results in the agency GRC tool.
- Conduct OA Negative Testing annually in accordance with agency implementation procedures, coordinating with penetration testing resources as necessary to execute negative test scenarios.
- Perform OA testing comprehensively across the technology stack of each target system, documenting results in detail within the GRC tool in a clear and concise manner.
FISMA Reporting Support- Collect, compile, validate, and submit FISMA reporting metrics for all assigned systems and programs, leveraging automation to the greatest degree possible to ensure accuracy and completeness of collected data.
- Contribute to the consolidated FISMA metrics reports, ensuring data is mathematically accurate and representative of the total agency FISMA inventory, delivered for Government review not later than 10 business days prior to submission due dates.
- Support the development and maintenance of dynamically updatable FISMA metrics visualizations and dashboards that pull data directly or indirectly from collected metrics.
Audit Support- Support and facilitate internal and external audits of assigned FISMA systems, including audits conducted by the Inspector General (IG), General Accountability Office (GAO), and internal auditors.
- Facilitate audit meetings and walkthroughs, coordinate with relevant support personnel, supply auditors with requested artifacts, and respond to follow-up questions in accordance with auditors' schedules and timelines.
- Ensure SOC reports are received from program offices for audit purposes as required, and that all audit artifacts are delivered on time, reviewable by the Government, and minimizing repeated requests from auditors.
High Value Asset (HVA) Assessment Support- Complete CISA's on-demand High Value Assets Assessment 3.0 (HVA 3.0) Training and provide course completion certificate to the Information System Security Manager (ISSM).
- Develop, maintain, and regularly update the agency HVA inventory list at least annually, and incorporate HVA activities into broader IT and information security and privacy management planning activities.
- Identify, categorize, and prioritize HVAs, implement and validate required security controls, identify HVA connections and dependencies, and support timely remediation of HVA assessment findings in accordance with established plans, milestones, and timelines.
FedRAMP Continuous Monitoring (CONMON) Support- Facilitate monthly FedRAMP CONMON meetings with applicable stakeholders for assigned systems, maintaining a general understanding of each system to provide appropriate guidance and comments to Cloud Service Providers (CSPs).
- Review vulnerability, penetration test, and ad hoc reporting from CSPs, ensuring vendor actions pose no security risks to the enterprise, and review and approve major changes when required by the vendor.
Automation, Visualization, and Data Structures Support- Design, construct, automate, and maintain visualizations (dashboards) and underlying data structures that reflect the status or effectiveness of security controls, monitoring status, capabilities, and metrics for assigned systems.
- Intake continuous feeds from enterprise cybersecurity tools (typically in .csv format), using scripting or other automation techniques to construct visualizations that reflect the status or effectiveness of monitored capabilities.
- Build, maintain, and document the underlying data structures supporting all visualizations, including all Extract-Transform-Load (ETL) requirements, data intake, and data normalization processes.
- Make approved visualizations available via the agency intranet portal, ensuring they are updated automatically on a continual basis or refreshed on at least a weekly schedule as appropriate.
Enterprise Risk Management (ERM) Support- Maintain cybersecurity and privacy risk registers for assigned systems, ensuring they are updated monthly and available via online visualization and internal web portal.
- Leverage the Factor Analysis of Information Risk (FAIR) methodology to assist in quantifying risk, and support the integration of cybersecurity and privacy risks into the agency ERM Risk Register as directed.
- Evaluate major risks related to cybersecurity, privacy, theft of information, and sensitive information protection (both internal and external threats), and collaborate on building out risk register entries with associated controls and planned mitigations.
Security & Compliance- Ensure all ISSO activities comply with applicable Federal security requirements, including FISMA, NIST SP 800-53 Rev 5, NIST SP 800-53A Rev 5, NIST SP 800-37 Rev 2, FIPS 199, FIPS 200, OMB Circular A-130, HSPD-12, and all referenced agency policies and implementation procedures.
- Comply with annual cybersecurity awareness training requirements and maintain all required certifications as current and unexpired throughout the period of performance.
- Ensure all work products are Section 508 accessibility compliant where required, and that all documentation is government-owned and free of proprietary or company-specific markings.
Education and Experience:Required:- Bachelor's degree in Cybersecurity, Information Technology, Computer Science, Information Systems, or a related field from an accredited college or university. Equivalent combination of education and directly relevant work experience may be considered in lieu of a degree.
- Minimum of 5 years of experience in information security, with at least 3 years of dedicated experience serving as an ISSO, security control assessor, or equivalent role supporting federal information systems under the NIST RMF.
- Demonstrated experience developing, maintaining, and submitting System Security Plans (SSPs), Security Assessment Plans (SAPs), Security Assessment Reports (SARs), and Plans of Action and Milestones (POAMs) in a fe