Our client, a prestigious Federal contractor, is seeking an Information System Security Officer (ISSO) and/or Alternate Information System Security Officer (AISSO) for one or more major federal IT information systems as a member of the customer directorate-s Security Team. Overall, you will be responsible for utilizing the NIST Risk Management Framework (RMF) and related Continuous Monitoring activities to maximize the security of their assigned system(s) and ensure compliance with Federal Information Security Management Act (FISMA) requirements and customer policies and processes.
The position is Hybrid, and the candidate will need to be in the DMV area and available to come onsite 2-3 days per week in Ashburn, VA. Our client is looking to onboard as a 6-month contract to hire.
Responsibilities
- Participate in program planning, prepare Authority to Test (ATT) and Significant Change (SC) documentation, and push these initiatives to completion.
- Review Nessus, WebInspect, and DBProtect security scans, communicate vulnerabilities to technical stakeholders, and track them to remediation.
- Proactively report security status and concerns to management and make recommendations as appropriate.
- Assist directorate with yearly audit responses and security-related data calls to upper management and DHS OCIO.
- Develop and update standard government security documentation such as System Security Plans, Contingency Plans, Interconnection Security Agreements, Risk Acceptances/Waivers, Privacy Threshold Analyses, Privacy Impact Assessments, Interconnection Security Agreements, waiver requests, and other ad-hoc documentation as needed.
- Review and approve/deny relevant system Change Requests as needed.
- Perform system audit log reviews in accordance with established policy requirements using Security Information and Event Management (SIEM) tools such as Splunk, Kibana, etc.
- Must be US Citizen due to government requirements with the ability to obtain and maintain a DHS Public Trust.
- BS or equivalent work experience in the Information Assurance / Cybersecurity field.
- 9+ years of overall IT security experience and 2+ years of experience as a primary ISSO or security compliance lead for an IT system.
- Possess one of the following: CISSP, CCSP, or CEH certifications.
- Has led annual Contingency Plan Tests in either tabletop form or as actual fail-over tests.
- Experience creating, tracking, and updating security policies and/or procedures.
- Expertise in using Splunk or other SIEM tools.
- Security experience with cloud systems hosted by Amazon Web Services (AWS).
- Experience leading an IT security team.
- Experience with DoD STIG system configuration standards.
- Has significant security experience with systems primarily supported by Linux OS (on premises) or Amazon Web Services (AWS).
- Prior experience supporting the federal government in an IT environment.
- Experience creating, tracking, and updating Interconnection Security Agreements (ISAs), risk acceptance memorandums, and policy waiver requests.
Home Based / Remote, VA
1
Monday, April 7, 2025
Contract/Temp to Hire
6 months CTH
Tuesday, February 25, 2025
Know someone who would be a good fit? We pay for referrals!