Information Systems Security Officer (ISSO)
CGS Federal (Contact Government Services) · Massachusetts, United States · 1 mo ago
Information Technology$92k–$125k/yrFull-time
About the role
The Information Systems Security Officer (ISSO) will support the Department of Commerce systems through full life-cycle Assessment and Authorization (A&A) management under the RMF process. The role involves conducting security assessments, overseeing information system security, and providing guidance and validation using NIST RMF and DoC policies.
Responsibilities
- Conduct security assessments and information system security oversight activities in accordance with NIST 800.53.
- Maintain responsibility for managing cybersecurity risk from an organizational perspective.
- Identify organizational risks, prioritize them, and maintain a risk registry for senior leadership.
- Provide security guidance and IS validation using the National Institute of Standards and Technology (NIST) RMF, DoC, and local security policies.
- Maintain vulnerability scanning tool compliance and patch management to ensure IT staff pushes patches to all systems.
- Support security authorization activities, including transitioning from DIACAP to DoC RMF.
- Provide subject matter expertise for cyber security and trusted system technology.
- Apply advanced technical knowledge and analysis of specialized functional areas to develop solutions to complex problems.
- Research, write, review, disposition feedback, and finalize recommendations regarding cyber security policy, assessment and authorization assessments, security test and evaluation reports, and security engineering practices and processes.
- Conduct research and write risk assessment reports, including risk thresholds, evaluation, and scoring.
- Support analysis of findings and provide expert technical guidance for mitigation strategies, including implementation advice on cyber security risk findings.
Requirements
- Bachelor’s Degree.
- A minimum of five (5) years experience as an Information Assurance (IA) Analyst, ISSE, ISSO, or similar role in ATO package development, including generating security documentation for requirements, security control assessment, STIG and IAVA compliance, Standard Operating Procedures, test results, etc.
- eMASS experience.
- Professional security certification such as: CCNA Security, CySA+, GICSP, GSEC, CompTIA Security+ CE, SSCP, or higher.
- Strong desktop publishing skills using Microsoft Word and Excel.
- Experience with industry writing styles such as grammar, sentence form, and structure.
- Ability to multi-task in a deadline-oriented environment.
Qualifications
- Master's Degree in Cybersecurity or related field is preferred.
- CISSP, CASP, or a similar certificate is preferred.
- Strong initiative, detail orientation, organizational skills, and aptitude for analytical thinking.
- Demonstrated ability to work well independently and as a part of a team.
- Excellent work ethic and a high commitment to quality.