Bachelor's Degree in Computer Science or related field; Advanced Degree preferred.
5+ years of information security experience, including leadership roles.
US Citizenship required; no dual citizenship allowed.
Solid knowledge of FISMA, NIST, and RMF methodology.
Experience with security authorization processes and documentation development.
Strong understanding of security tools, protocols, and encryption techniques.
Excellent communication skills for technical and executive audiences.
Responsibilities
Serve as the subject-matter expert for security requirements on assigned FISMA systems.
Complete and maintain system authorization packages in the DHS FISMA management tool.
Ensure compliance with NIST SP 800-37 Rev. 2 and agency policies.
Perform periodic security management activities and audit log reviews.
Document and track system weaknesses and recommend corrective actions.
Support risk acceptance and waiver requests with documented justifications.
Investigate and report security incidents, initiating corrective measures.
Benefits
Comprehensive benefits package including health and wellness programs.
Opportunities for professional development and certifications.
Supportive work environment with a focus on work-life balance.
Engagement in meaningful projects that impact national security.
Full Job Description
The Information Systems Security Officer (ISSO) supports the overall information security posture of assigned Major Applications (MAs) and General Support Systems (GSSs) within the customer environment. This individual serves as the subject-matter expert and principal point of contact for all system security requirements on assigned FISMA systems, providing expert-level guidance and leadership in implementing, maintaining, and enforcing information security policies, standards, and methodologies in accordance with federal regulations and agency requirements.
Serve as the subject-matter expert and principal point of contact for security requirements on assigned FISMA systems (MAs, GSSs, and sub-systems/applications).
Complete and maintain system authorization packages (System Security Plans, Interconnection Security Agreements, Contingency Plans, POA&Ms, waivers, and exceptions) in the DHS FISMA system management tool supporting the NIST Risk Management Framework (RMF).
Ensure assigned systems are operated, maintained, and disposed of in accordance with NIST SP 800-37 Rev. 2, DHS 4300A Policy and Handbook, and agency Handbook 1400-05D.
Perform periodic security management activities and monthly audit log reviews for assigned FISMA systems, identifying and documenting security anomalies.
Obtain input from system administrators, security engineers, and system owners to document and track system weaknesses as POA&Ms; recommend and track corrective actions to remediation.
Support risk acceptance and waiver requests, system access request reviews, and endorsement/rejection determinations with documented justification.
Investigate and report security incidents to the Director, SOD and CSD ISSM, and ensure protective or corrective measures are initiated upon discovery of a security incident or vulnerability.
Review Privacy Threshold Analyses (PTAs) and Privacy Impact Assessments (PIAs) and provide documented security feedback to system/business owners.
Lead, prepare materials for, and participate in meetings supporting system assessment and authorization, vulnerability/POA&M reviews, and internal and external audits.
Support the DHS Ongoing Authorization (OA) Program transition and maintenance activities for assigned systems.
Provide audit support and liaison services between auditors (e.g., OIG, annual IPA/KPMG audit) and agency CSD, including collection of artifacts and formulation of responses across FISMA, FISCAM, and OMB Circular A-123 areas.
Minimum Qualifications
Bachelor's Degree in Computer Science or a related field or equivalent experience; Advanced Degree preferred.
Minimum 5 years of information security experience, including at least 5 years in a lead ISSO or similar leadership capacity on programs/contracts of comparable scope and complexity.
US Citizenship / No Dual
Other Job Specific Skills
Solid knowledge of FISMA, NIST, and the Risk Management Framework (RMF) methodology.
Experience with security authorization processes (Certification & Accreditation and Authorization to Operate) and the ability to develop associated documentation.
Strong understanding of security tools, hardware/software security implementation, communication protocols, and encryption techniques.
Proven ability to analyze security vulnerabilities, deliver comprehensive assessments, and develop effective remediation instructions.
Excellent written and verbal communication skills, with the ability to present complex security information clearly to technical and executive audiences.
Certified Information Systems Security Professional (CISSP) Preferred
Certified Information Security Manager (CISM) Preferred
Compensation Ranges
Compensation ranges for ASM Research positions vary depending on multiple factors; including but not limited to, location, skill set, level of education, certifications, client requirements, contract-specific affordability, government clearance and investigation level, and years of experience. The compensation displayed for this role is a general guideline based on these factors and is unique to each role. Monetary compensation is one component of ASM's overall compensation and benefits package for employees.