Information System Security Officer
Hiring Our Heroes · Arlington, VA · 2 mo ago
Information TechnologyFull-time
Responsibilities
- Lead and conduct Pre-Security Assessment and Authorization (A&A) activities, including stakeholder identification, change request submissions, appointment memorandums, and IT Security Kickoff meetings.
- Supports the ISBO in day-to-day IT security activities.
- Affords assistance with reviews of the security posture of the system and reports any findings to the ISBO, CISO, and the AO.
- Conducts Information System Categorization by identifying information types, completing FIPS-199 assessments, and facilitating Business Impact Analyses (BIA), Privacy Threshold Analyses (PTA), and Privacy Impact Assessments (PIA).
- Develops and maintains system security documentation, including: System Administration Plan (SAM), Configuration Management Plan (CMP), IT Contingency Plan (ITCP), Information Security Continuous Monitoring (ISCM) Plan, Incident Response Plan (IRP), Security Assessment Report (SAR), System Security Plan (SSP).
- Coordinates initial and annual ITCP testing in collaboration with the OCIO Business Continuity and Disaster Recovery (BCDR) Office.
- Develops and manages inter-agency agreements and documentation such as MOUs, MOAs, ISAs, IT Security Waivers, and Risk Acceptance Memorandums.
- Documents and maintains Security Control Implementation details, ensuring updates are made according to required frequency.
- Coordinates vulnerability and compliance scans, Security Control Assessments (SCA), and tracks remediation efforts with the IT Security Test Team.
- Manages and updates Plan of Action and Milestones (POA&M) entries, submitting remediated findings for closure.
- Prepares and presents SAR to Authorizing Officials to obtain or renew ATO.
- Performs Information Security Continuous Monitoring (ISCM) activities to ensure ongoing compliance and security posture of systems.
- Develops and updates project schedule, including A&A / SCA task and milestones, task dependencies, and personnel resources.
- Carries out A&A activities and tasks and obtains ATO in line with NIST and client guidance and directives.
- Determines the baseline IT Security requirements for IT Systems, identifies system boundaries, determines information categories, assists with FIPS-199.
- Ensures that IT Systems are operated, used, maintained, and disposed of in accordance with internal security policies and practices.
- Enforces security policies and safeguards on all personnel having access to the IT System for which the ISSO has responsibility.
- Ensures users and system support personnel have the required authorization and need-to-know; have been indoctrinated; and are familiar with internal security practices before access to the IT System.
- Implements security controls based on IT System FIPS categorization.
- Documents security control implementation in the system's Security Plan using the client's GRC tool.
- Documents system's risk assessment per client directives and requirements.
- Reviews and monitors system security and audit logs.
- Develops and maintains Plan of Actions and Milestones (POA&Ms) for IT systems.
- Updates A&A documentation and artifacts on a regular basis (e.g., annually, after approved change).
Qualifications
- A minimum of five (5) years of demonstrated experience in the Information Security or IT field.
- Demonstrates a proficiency with developing, maintaining and managing SA&A packages.
- Experience with developing and managing POA&M's.
- Strong problem solving and analysis skills, self-motivated, and able to work and communicate in a team environment.
- Strong understanding of federal cybersecurity frameworks (e.g., NIST RMF, FIPS-199, FISMA).
- Experience in developing and maintaining security documentation and plans.
- Possess experience conducting CPT's.
- Experience conducting audit log reviews.
- Technical experience with conducting vulnerability management, compliance scanning, and providing mitigation techniques.
- Excellent communication and coordination skills with technical and non-technical stakeholders.
- Able to manage multiple systems and projects simultaneously in a dynamic environment.
- Excellent communication (written and verbal) skills.
- Certification: A minimum of at least one (1) certification that meet DOD 8570 IAT Level II (e.g., Security+, GSEC, CASP) requirements or any equivalent or more advanced.
Location and Hours
Location: Primary location is at Zermount HQ (Arlington, VA) and the Client Site (Washington, D.C.). Remote work is authorized. Onsite work at the primary location may be occasionally required. Hours of Operation (Business Hours): 8:00 am ET - 5:30 pm ET.