Koniag Government Services

ISSO/Control Evaluator

Koniag Government Services$110K — $130K *
Information Technology
5 - 7 years of experience
Job Overview by Ladders

Qualifications

  • Bachelor's degree in Cybersecurity, IT, Computer Science, or related field (or equivalent experience).
  • 5+ years of experience in information security, with 3+ years as an ISSO or security control assessor.
  • Deep knowledge of NIST security frameworks and federal information security policy.
  • Experience with risk management frameworks, particularly in federal settings.
  • Proficiency in developing security documentation such as SSPs and SARs.

Responsibilities

  • Develop expertise in assigned information systems, including architecture and data flows.
  • Build and maintain relations with system owners and program offices to advocate for operational cybersecurity needs.
  • Create and update cybersecurity documentation like SSPs and CMPs for compliance.
  • Conduct security control assessments and ensure alignment with NIST guidelines.
  • Support continuous monitoring activities and participate in change control processes.

Benefits

  • Health, dental, and vision insurance.
  • 401K plan with company matching.
  • Flexible spending accounts.
  • Three weeks of paid time off.
  • Paid holidays.
Full Job Description
Koniag Data Solutions, a Koniag Government Services company, is seeking an experienced Information System Security Officer (ISSO) / Control Evaluator to support a comprehensive enterprise cybersecurity services engagement for a federal civilian agency. This position requires the ability to obtain and maintain a government background investigation commensurate with a Moderate Risk designation (Minimum Background Investigation or higher) and applicable system access authorizations prior to performing work. Work will be performed primarily at the client's facility located in Washington, DC, with potential for hybrid/remote arrangements as approved.

We offer competitive compensation and an extraordinary benefits package including health, dental and vision insurance, 401K with company matching, flexible spending accounts, paid holidays, three weeks paid time off, and more.

This role sits within the Information Security Division (ISD) and supports the agency's Risk Management Framework (RMF) program, FISMA compliance obligations, continuous monitoring activities, and security controls assessment and evaluation functions across a diverse portfolio of on-premises, cloud-hosted, and hybrid information systems.

The ideal candidate is a technically proficient and operationally experienced cybersecurity professional with a deep understanding of NIST security frameworks, federal information security policy, security assessment methodologies, and the practical application of security controls across complex, multi-technology enterprise environments. This individual must possess the ability to develop and maintain in-depth technical knowledge of assigned systems, build trusted relationships with system owners and stakeholders, and independently execute a broad range of ISSO responsibilities with minimal Government direction.

The ISSO / Control Evaluator is responsible for providing comprehensive information system security officer support and security controls assessment and evaluation services across an assigned portfolio of federal information systems. This individual develops and sustains in-depth technical, operational, and working-level expertise about each assigned system, advocates for system owner needs as they align to cybersecurity and privacy requirements, and ensures each system maintains its authorization to operate in accordance with federal and agency security policies and standards.

This role requires active participation in the agency's enterprise change control processes, continuous monitoring activities, Ongoing Authorization (OA) programs, and audit support functions, as well as contributions to automation, visualization, and data structure efforts that provide real-time visibility into control status and security posture across the enterprise.

Principal responsibilities will include but are not limited to:

ISSO Core Responsibilities
  • Develop and sustain in-depth technical, operational, and working-level expertise about all assigned information systems, including thorough knowledge of system architecture, assets, data flows, operational environment, management hierarchy, and how each system fits into the broader enterprise IT ecosystem.
  • Establish and maintain a professional rapport and trusted working relationship with system owners, program offices, and technical support personnel for all assigned systems, understanding their operational needs and advocating for those needs as they align to cybersecurity and privacy requirements.
  • Read, absorb, and maintain current familiarity with all available system documentation for assigned systems, including System Security Plans (SSPs), topology diagrams, architecture diagrams, and data flow documentation.
  • Establish access to and gain increasing proficiency with the operational tools, administrative consoles, and enterprise cybersecurity platforms used to manage and monitor assigned systems, extracting meaningful data to produce continuously updated control status visualizations and dashboards.
  • Ensure assigned systems are onboarded into enterprise tools and reporting mechanisms, including the agency's Governance, Risk, and Compliance (GRC) tool, in accordance with established procedures and timelines.
  • Actively participate in the weekly Enterprise Change Control Board (ECCB) process, ensuring security impacts of proposed changes are evaluated and documented for all assigned systems.
  • Maintain current awareness of all active Acceptance of Risk (AOR) documents for assigned systems, ensuring resubmission for approval before expiration.
  • Maintain knowledge management services for all accreditation-related artifacts, including appointment orders, Authority to Operate (ATO) documentation, AORs, Memoranda of Understanding/Agreement, and Data Sharing Agreements, ensuring all documents are organized and accessible in the designated central repository.

Documentation Support
  • Create, update, revise, and maintain cybersecurity and privacy documentation for all assigned systems across the enterprise, ensuring all documentation is aligned to applicable agency implementation procedures and reviewed for acceptance by the Office of the CIO.
  • Develop and maintain the following documentation types, among others:
    • System Security Plans (SSPs) with detailed, technology-specific control implementation descriptions for all technologies within the system boundary
    • Configuration Management Plans (CMPs)
    • Information System Contingency Plans (ISCPs) and Contingency Plan Test Reports (ISCP-TRs)
    • E-authentication Risk Assessments (ERAs)
    • User recertification documentation
    • Architecture, topology, and data flow diagrams (OV-1 and SV-1 equivalent)
  • Ensure all control implementation descriptions are written to a level of detail that demonstrates how each control is specifically implemented across all technologies within the system boundary, avoiding high-level generalizations or simple restatement of NIST control language.
  • Address all Government comments, edits, and questions on documentation within 10 business days of receipt, and escalate stakeholder unresponsiveness to the Government POC after 10 business days without response.
  • Ensure selected policy and procedure documents are delivered in both Adobe and Word formats and are Section 508 accessibility remediated as directed.

Controls Assessment and Evaluation Support
  • Provide security and privacy controls assessment and continuous monitoring assessment support for all assigned systems, including testing and validation of NIST SP 800-53 controls, documentation of NIST SP 800-53A Determine If Statements (DISs), and mapping of vulnerabilities to applicable controls.
  • Develop draft Security and Risk Assessment Plans (SAPs) for delivery not less than 10 business days prior to beginning an assessment, and draft Security and Risk Assessment Reports (SARs) and Plan of Action and Milestones (POAMs) within 30 business days from point-in-time assessment kick-off.
  • Conduct technical control assessments across all technology types within the system boundary (e.g., Windows, UNIX, Cisco, F5 Load Balancer), including sampling across in-scope devices, users, and services, ensuring assessments are comprehensive to the scope identified in the SAP and 100% aligned to the GRC tool.
  • Develop and deliver Annual Assessment Reports (AARs) per in-scope system within 120 business days from point-in-time annual assessment kick-off, and multi-year assessment reports in accordance with applicable timelines.
  • Incorporate all Government feedback into revised deliverables within 5 business days of receipt of comments, ensuring final deliverables are comprehensive, peer-reviewed, and aligned to agency templates.
  • Develop assessment reports that include visual representation against the NIST Cybersecurity Framework (CSF) and are comprehensive to the scope identified in the SAP.

Ongoing Authorization (OA) Evaluation Support
  • For systems approved for Ongoing Authorization (OA), develop and submit an OA Playbook to the agency for approval, including a documented testing methodology for each OA core control covering Test Strategy, Test Design, Test Execution, Results Evaluation, and Visualization.
  • Conduct OA Positive Testing monthly in accordance with agency implementation procedures, documenting all results in the agency GRC tool.
  • Conduct OA Negative Testing annually in accordance with agency implementation procedures, coordinating with penetration testing resources as necessary to execute negative test scenarios.
  • Perform OA testing comprehensively across the technology stack of each target system, documenting results in detail within the GRC tool in a clear and concise manner.

FISMA Reporting Support
  • Collect, compile, validate, and submit FISMA reporting metrics for all assigned systems and programs, leveraging automation to the greatest degree possible to ensure accuracy and completeness of collected data.
  • Contribute to the consolidated FISMA metrics reports, ensuring data is mathematically accurate and representative of the total agency FISMA inventory, delivered for Government review not later than 10 business days prior to submission due dates.
  • Support the development and maintenance of dynamically updatable FISMA metrics visualizations and dashboards that pull data directly or indirectly from collected metrics.

Audit Support
  • Support and facilitate internal and external audits of assigned FISMA systems, including audits conducted by the Inspector General (IG), General Accountability Office (GAO), and internal auditors.
  • Facilitate audit meetings and walkthroughs, coordinate with relevant support personnel, supply auditors with requested artifacts, and respond to follow-up questions in accordance with auditors' schedules and timelines.
  • Ensure SOC reports are received from program offices for audit purposes as required, and that all audit artifacts are delivered on time, reviewable by the Government, and minimizing repeated requests from auditors.

High Value Asset (HVA) Assessment Support
  • Complete CISA's on-demand High Value Assets Assessment 3.0 (HVA 3.0) Training and provide course completion certificate to the Information System Security Manager (ISSM).
  • Develop, maintain, and regularly update the agency HVA inventory list at least annually, and incorporate HVA activities into broader IT and information security and privacy management planning activities.
  • Identify, categorize, and prioritize HVAs, implement and validate required security controls, identify HVA connections and dependencies, and support timely remediation of HVA assessment findings in accordance with established plans, milestones, and timelines.

FedRAMP Continuous Monitoring (CONMON) Support
  • Facilitate monthly FedRAMP CONMON meetings with applicable stakeholders for assigned systems, maintaining a general understanding of each system to provide appropriate guidance and comments to Cloud Service Providers (CSPs).
  • Review vulnerability, penetration test, and ad hoc reporting from CSPs, ensuring vendor actions pose no security risks to the enterprise, and review and approve major changes when required by the vendor.

Automation, Visualization, and Data Structures Support
  • Design, construct, automate, and maintain visualizations (dashboards) and underlying data structures that reflect the status or effectiveness of security controls, monitoring status, capabilities, and metrics for assigned systems.
  • Intake continuous feeds from enterprise cybersecurity tools (typically in .csv format), using scripting or other automation techniques to construct visualizations that reflect the status or effectiveness of monitored capabilities.
  • Build, maintain, and document the underlying data structures supporting all visualizations, including all Extract-Transform-Load (ETL) requirements, data intake, and data normalization processes.
  • Make approved visualizations available via the agency intranet portal, ensuring they are updated automatically on a continual basis or refreshed on at least a weekly schedule as appropriate.

Enterprise Risk Management (ERM) Support
  • Maintain cybersecurity and privacy risk registers for assigned systems, ensuring they are updated monthly and available via online visualization and internal web portal.
  • Leverage the Factor Analysis of Information Risk (FAIR) methodology to assist in quantifying risk, and support the integration of cybersecurity and privacy risks into the agency ERM Risk Register as directed.
  • Evaluate major risks related to cybersecurity, privacy, theft of information, and sensitive information protection (both internal and external threats), and collaborate on building out risk register entries with associated controls and planned mitigations.

Security & Compliance
  • Ensure all ISSO activities comply with applicable Federal security requirements, including FISMA, NIST SP 800-53 Rev 5, NIST SP 800-53A Rev 5, NIST SP 800-37 Rev 2, FIPS 199, FIPS 200, OMB Circular A-130, HSPD-12, and all referenced agency policies and implementation procedures.
  • Comply with annual cybersecurity awareness training requirements and maintain all required certifications as current and unexpired throughout the period of performance.
  • Ensure all work products are Section 508 accessibility compliant where required, and that all documentation is government-owned and free of proprietary or company-specific markings.


Education and Experience:

Required:
  • Bachelor's degree in Cybersecurity, Information Technology, Computer Science, Information Systems, or a related field from an accredited college or university. Equivalent combination of education and directly relevant work experience may be considered in lieu of a degree.
  • Minimum of 5 years of experience in information security, with at least 3 years of dedicated experience serving as an ISSO, security control assessor, or equivalent role supporting federal information systems under the NIST RMF.
  • Demonstrated experience developing, maintaining, and submitting System Security Plans (SSPs), Security Assessment Plans (SAPs), Security Assessment Reports (SARs), and Plans of Action and Milestones (POAMs) in a fe

About Koniag Government Services

Koniag Government Services Careers

Join the dynamic team at Koniag Government Services, a leader in providing innovative solutions to government clients. This esteemed company offers a plethora of job opportunities that pave the way for professional growth and career advancement in a diverse and inclusive environment.

Explore Career Opportunities

Koniag Government Services is actively hiring and offers a range of positions that cater to various skills and experiences. Whether you're a seasoned professional or a recent graduate, Koniag Government Services provides a platform to enhance your career through meaningful work in a supportive culture.

Innovation and Leadership

At the forefront of innovation, Koniag Government Services encourages its team to lead with creativity and strategic thinking. The company is committed to leadership development and diversity training, ensuring that all team members have the opportunity to excel and contribute to industry-leading projects.

Professional Growth and Development

Koniag Government Services is dedicated to the professional development of its employees. With comprehensive benefits, competitive employment packages, and opportunities for advancement, the company supports its team in achieving their career goals. Networking within the company and industry is encouraged, fostering a community of learning and mutual growth.

Internship Programs

For those starting their career journey, Koniag Government Services offers internship programs that provide real-world experience and a pathway to full-time employment. Interns gain valuable industry knowledge and develop essential skills under the guidance of experienced mentors.

Commitment to Diversity and Inclusion

Diversity is at the core of Koniag Government Services' values. The company is committed to creating an inclusive environment where diverse voices are heard and valued. Diversity training is integral, equipping the team with the tools to thrive in a multicultural setting.

Applying for a Position

To apply for a position at Koniag Government Services, candidates should prepare a resume that highlights relevant experience and skills. The interview process is designed to assess fit both for the role and the company culture, ensuring alignment with the team’s values and objectives.

Stay Connected with Koniag Government Services Careers

Explore the various job opportunities and embark on a path of professional growth and innovation. Koniag Government Services is not just a workplace but a community where careers flourish in an environment of respect, integrity, and continuous learning.

Search Koniag Government Services Jobs

Discover the exciting career opportunities available at Koniag Government Services. Search for open positions that match your skills and interests, and join a team that values curiosity, creativity, and collaboration.

Keep Up to Date

Stay informed with the latest career tips, industry insights, and company updates directly from Koniag Government Services. Engage with content that can transform your professional journey and lead to rewarding opportunities.

Job Alert Emails

Personalize your subscription to receive job alerts and insider tips tailored to your preferences from Koniag Government Services. See what exciting and rewarding opportunities await in the field of government services.
Learn more about Koniag Government Services
Size
501 employees
Industry

Similar Jobs

More Jobs at Koniag Government Services

More Information Technology Jobs

Find similar ISSO/Control Evaluator jobs: