
Information System Security Officer
Posted Sep 15

Posted Sep 15
This is a fully remote position, open to applicants in Virginia, +1 more state.
• Assist a federal agency in ensuring adherence to FISMA, NIST, DISA STIG, FIPS, and NIPS regulations.
• Execute, supervise, consistently monitor, and sustain security configurations, practices, and protocols for client information systems.
• Direct security authorization processes and protocols.
• Propose security best practices and system configuration benchmarks.
• Oversee cybersecurity posture and analysis, which includes vulnerability management, incident response assistance, and Risk Management Framework activities.
• Upload security control evidence into the Governance, Risk, and Compliance (GRC) application.
• Draft System Security Plans, POA&Ms, Risk Assessments, PIAs, and related documentation.
• Assist with FBI security Assessment & Authorization activities to achieve and retain Authorization to Operate (ATO).
• Execute necessary information-system vulnerability scans.
• Coordinate with system owners for agreement on correction or mitigation actions.
• Monitor security controls to ensure continued authorization to operate.
• Develop security A&A documentation for CODIS and maintain project system security procedures for the Information System Security Manager (ISSM).
• Analyze system audit trails and report incidents related to information-system security.
• Ensure users possess necessary clearances, authorizations, and need-to-know before access is granted.
• Manage information-security audits conducted by federal departments/agencies and external auditors.
• Initiate protective and corrective actions when security incidents or vulnerabilities are identified.
• Collaborate with government managers and contractors regarding security obligations.
• Engage in Change Control Boards (CCBs) and provide advice on security implications of proposed modifications and software requirements.
• Support certification tasks throughout the A&A process.
• Supervise system recovery procedures and Continuity of Operations exercises.
• Evaluate emerging network-system and enterprise-level risks and vulnerabilities.
• Counsel leadership on cybersecurity risk management, security strategy, project planning, and security architecture.
• Interface with security organizations on the security status of configuration modifications.
• Active Top-Secret clearance with the ability to obtain SCI/CI Poly if required to meet contract stipulations.
• Bachelor’s and/or Master’s degree in Computer Science, Management Information Systems, or a related technical field.
• CompTIA Security+ or (ISC)² Security Certified Practitioner (SSCP), (ISC)² CISSP, or a higher-level certification.
• Proficient understanding of Continuous Integration/Continuous Delivery (CI/CD) Pipelines.
• Familiarity with virtualization, software-defined infrastructure, and cloud computing technologies.
• Knowledge of Tenable Nessus and/or Security Center, AppDetectivePro, HP WebInspect, Network Mapper (NMAP), and/or similar tools.
• Medical – 100% company-paid premiums for employees with options for dependents.
• Dental and Vision coverage.
• Retirement Savings (401k) with up to 4% matching.
• Health Savings Account (HSA), Flexible Spending Account (FSA), and Dependent Care Flexible Spending Account (DCFSA).
• Company-funded Short/Long-term disability (with additional supplemental options).
• Company-sponsored Life and AD&D insurance (with additional supplemental options).
• Generous Paid Time Off and all 11 Federal Holidays.
• Legal and Identity Protection Services.
• Bonuses for obtaining certifications and reimbursement opportunities.
• UberOne membership.
• Company outings (sporting events, happy hours, etc.).
• Discounts on services including Pet Insurance.
• Opportunities for reimbursement and bonuses based on certification completion.
Alcoa
McKesson
Zillow
Truelogic Software
Get handpicked remote jobs straight to your inbox weekly.