Document and track system weaknesses and recommend corrective actions.
Support risk acceptance and waiver requests with documented justifications.
Investigate and report security incidents, initiating corrective measures as needed.
Review Privacy Threshold Analyses and provide security feedback to system owners.
Lead and participate in meetings for system assessment and authorization processes.
Provide audit support and liaise with auditors, collecting artifacts and formulating responses.
Benefits
Comprehensive health insurance options.
Retirement savings plans with company matching.
Professional development and training opportunities.
Flexible work arrangements.
Paid time off and holidays.
Full Job Description
The Information Systems Security Officer (ISSO) supports the overall information security posture of assigned Major Applications (MAs) and General Support Systems (GSSs) within the customer environment. This individual serves as the subject-matter expert and principal point of contact for all system security requirements on assigned FISMA systems, providing expert-level guidance and leadership in implementing, maintaining, and enforcing information security policies, standards, and methodologies in accordance with federal regulations and agency requirements.
Serve as the subject-matter expert and principal point of contact for security requirements on assigned FISMA systems (MAs, GSSs, and sub-systems/applications).
Complete and maintain system authorization packages (System Security Plans, Interconnection Security Agreements, Contingency Plans, POA&Ms, waivers, and exceptions) in the DHS FISMA system management tool supporting the NIST Risk Management Framework (RMF).
Ensure assigned systems are operated, maintained, and disposed of in accordance with NIST SP 800-37 Rev. 2, DHS 4300A Policy and Handbook, and agency Handbook 1400-05D.
Perform periodic security management activities and monthly audit log reviews for assigned FISMA systems, identifying and documenting security anomalies.
Obtain input from system administrators, security engineers, and system owners to document and track system weaknesses as POA&Ms; recommend and track corrective actions to remediation.
Support risk acceptance and waiver requests, system access request reviews, and endorsement/rejection determinations with documented justification.
Investigate and report security incidents to the Director, SOD and CSD ISSM, and ensure protective or corrective measures are initiated upon discovery of a security incident or vulnerability.
Review Privacy Threshold Analyses (PTAs) and Privacy Impact Assessments (PIAs) and provide documented security feedback to system/business owners.
Lead, prepare materials for, and participate in meetings supporting system assessment and authorization, vulnerability/POA&M reviews, and internal and external audits.
Support the DHS Ongoing Authorization (OA) Program transition and maintenance activities for assigned systems.
Provide audit support and liaison services between auditors (e.g., OIG, annual IPA/KPMG audit) and agency CSD, including collection of artifacts and formulation of responses across FISMA, FISCAM, and OMB Circular A-123 areas.
Minimum Qualifications
Bachelor's Degree in Computer Science or a related field or equivalent experience.
Minimum 3 years of information security experience on programs/contracts of comparable scope and complexity.
Certified Information Systems Security Professional (CISSP), or Certified Information Security Manager (CISM) preferred.
US Citizenship / no dual
Other Job Specific Skills
Solid knowledge of FISMA, NIST, and the Risk Management Framework (RMF) methodology.
Experience with security authorization processes (Certification & Accreditation and Authorization to Operate) and the ability to develop associated documentation.
Strong understanding of security tools, hardware/software security implementation, communication protocols, and encryption techniques.
Proven ability to analyze security vulnerabilities, deliver comprehensive assessments, and develop effective remediation instructions.
Excellent written and verbal communication skills, with the ability to present complex security information clearly to technical and executive audiences.
Compensation Ranges
Compensation ranges for ASM Research positions vary depending on multiple factors; including but not limited to, location, skill set, level of education, certifications, client requirements, contract-specific affordability, government clearance and investigation level, and years of experience. The compensation displayed for this role is a general guideline based on these factors and is unique to each role. Monetary compensation is one component of ASM's overall compensation and benefits package for employees.