Jobs · Information Technology · Virginia

Information Systems Security Officer (ISSO)

NTT DATA North America · Arlington, VA · 1 wk ago
Information Technology$110k–$184k/yrFull-time

NTT DATA is seeking an Information Systems Security Officer (ISSO) to join our team in Arlington, Virginia.

About the role

The ISSO ensures the secure operation of assigned information systems in compliance with organizational policies, agency requirements, and federal cybersecurity standards such as NIST, FISMA, FedRAMP, and RMF. The ISSO supports authorization and assessment activities, maintains continuous monitoring programs, and responds to incidents to safeguard the confidentiality, integrity, and availability of systems and data. Serving as the principal advisor to the Information System Owner (ISO) and the Chief Information Security Officer (CISO), the ISSO provides subject matter expertise on all security matters related to assigned systems, including supporting development and maintenance of security documentation, coordinating with technical staff and external partners, and ensuring security controls remain effective throughout the system lifecycle. The ISSO plays a central role in authorization activities (RMF Steps 1–6) to ensure information systems remain compliant, resilient, and aligned with federal and agency policy.

Responsibilities

  • Ensure assigned systems comply with NIST, FISMA, FedRAMP, and agency frameworks, regulations, and guidance.
  • Conduct risk assessments and support the development of mitigation plans.
  • Assist in creation and validation of System Security and Privacy Plans (SSPPs).
  • Validate security controls implementation in accordance with RMF requirements.
  • Support the Assessment and Authorization (A&A) process.
  • Prepare and maintain SSPs, SARs, POA&Ms, ISCPs, IRPs, CMPs, and related artifacts.
  • Track and manage POA&Ms to address vulnerabilities and deficiencies.
  • Generate system security status reports and metrics for leadership and auditors.
  • Ensure documentation is accurate, current, and aligned with agency requirements.
  • Conduct system log reviews, monitor system activity for abnormal behavior or potential compromise.
  • Review, analyze, and report on vulnerability and compliance scan results.
  • Ensure continuous monitoring of implemented security controls.
  • Participate in incident response activities, including investigation, reporting, and after-action documentation.
  • Collaborate with ISOs, ISSMs, system administrators, engineers, and other stakeholders.
  • Serve as a liaison with auditors, assessors, and external agencies during reviews.
  • Provide security training and awareness to system owners and users as needed.
  • Support contingency planning, testing, and disaster recovery activities.
  • Contribute to the development and review of cybersecurity policies and procedures.
  • Ensure systems are operated, maintained, and disposed of in compliance with policy.
  • Support supply chain risk management requirements and validate use of third-party software.
  • Provide advice on security requirements and architecture during design, development, and deployment for on-premises, hybrid, and cloud systems.
  • Ensure controls remain effective through operations, sustainment, and system disposal.
  • Review, recommend, and validate configuration and change management requests for assigned systems.
  • Participate in Configuration Control Boards (CCBs).
  • Review and assess the security impact of proposed system changes.
  • Ensure security reviews are documented and follow established policy.
  • Maintain positive working relationships with technical teams and stakeholders.
  • Support development of BIAs, PIAs, ISAs, and MOUs/A as required.
  • Maintain current information in the DEA Assessment & Authorization (A&A) tool (e.g., JCAM).
  • Participate in security audits, assessments, and exercises.
  • Report incidents, risks, and issues to ISSMs, CISOs, and other stakeholders.
  • Complete required annual training and certifications.
  • Support other duties as assigned by ISSMs or the CISO.

Requirements

  • Master’s degree in Information Technology, Cybersecurity, Data Science, Information Systems, or Computer Science. Education Equivalency: One-and-one-half (1.5) years of additional experience can substitute for one (1) year of a typical degree program.
  • Minimum 10 years of experience in Information Technology (IT) and/or Information Security (IS).
  • Active Secret or higher security clearance holder and must be eligible for a Top-Secret clearance if requested.

Preferred Qualifications

  • DCWF Role 612 - Security Control Assessor / 722 – Information Systems Security Manager intermediate & advanced certifications.
  • ISC2: CISSP, CISSP-ISSMP, CGRC/CAP.
  • CompTIA: CySA+, Security+, CASP+, Cloud+, Pentest+.
  • EC-Council: CCISO.
  • SANS: GCIA, GCIH, GICSP, GSNA, GCSA, GSEC, GMON, or GSLC.
  • M.S. in Artificial Intelligence Cybersecurity.
  • M.S. in Information Security with AI Engineering.
  • Graduate Certificates in Cyber-AI.
  • Cloud Architecture experience to include: Virtualization, multi-tenant systems, and platform deployment (AWS, Azure, GCP).

Pay

The starting pay range for this role is $110,179 - $183,631. Actual compensation will depend on a number of factors, including the candidate’s relevant experience, technical skills, and other qualifications. This position may also be eligible for incentive compensation based on individual and/or company performance. If the position is temporary, it will not be eligible for incentive compensation.

Benefits

  • Medical, dental, and vision insurance with employer contribution.
  • Flexible spending or health savings account.
  • Life and AD&D insurance.
  • Short and long term disability coverage.
  • Paid time off.
  • Employee assistance program.
  • Participation in a 401k program with company match.
  • Additional voluntary or legally-required benefits.

Similar jobs