
Information System Security Officer – ISSO
Posted Aug 14

Posted Aug 14
This is a fully remote position, open to applicants in United States.
• Act as the primary contact for all system security issues related to assigned Program Management Organizations.
• Spearhead cybersecurity engineering initiatives with direct assistance to the Compliance Branch Lead.
• Carry out comprehensive Risk Management Framework activities for Authority to Operate decisions, encompassing system categorization, security control selection and implementation, self-assessments, development of POA&M, and ongoing monitoring.
• Create and uphold System Security Plans that include control baselines, inheritance, Business Impact Analyses, implementation statements, technical and system descriptions, as well as hardware and software inventories.
• Formulate and sustain Configuration Management Plans.
• Perform Security Impact Analyses, grant approval for Change Requests, and document the security implications of configuration modifications.
• Design and evaluate Contingency Plans and Incident Response Plans.
• Execute annual risk assessments and assist with security and vulnerability evaluations.
• Provide guidance to system owners and senior executives regarding cybersecurity issues.
• Create remediation work plans to address assessment and audit findings.
• Maintain lists of hardware and software inventories and conduct FISMA Scorecard Analyses.
• Ensure appropriate access controls are in place for system access.
• Monitor and recommend technologies, processes, and practices that safeguard networks, devices, programs, and data.
• Investigate and keep up to date with cybersecurity tools, techniques, countermeasures, trends, vulnerabilities, data protection, network and device security, and encryption.
• U.S. Citizenship is required.
• DHS EOD suitability or current DHS EOD is preferred.
• A BS/BA degree along with 7 years of relevant experience in information security.
• Over 7 years of experience in information security is required.
• Proven expertise in RMF, information security processes, audits, tools, implementation, FISMA, NIST, and IT security.
• Experience in developing System Security Plans, POA&Ms, and Configuration Management Plans.
• Familiarity with NIST SP 800-37, NIST SP 800-53, and DHS 4300 Series requirements.
• One of the following IAT Level III certifications is desired: CISSP, CISM, or CompTIA CASP+.
• Prior experience with DHS is desirable.
• Experience with CSAM, RegScale, eMASS, or similar GRC tools is preferred.
• Experience supporting emergency operations or disaster response missions is preferred.
• Knowledge of cloud security and FedRAMP authorization processes is preferred.
• Experience with continuous monitoring is preferred.
• Flexible time off benefit.
• Robust learning resources.
• Learning and development opportunities.
• Healthcare benefits.
• Wellness benefits.
• Financial benefits.
• Retirement benefits.
• Family support benefits.
• Continuing education benefits.
• Time off benefits.
VALCE Talent Solutions
DigitalOcean
XBOX
WSGR
Get handpicked remote jobs straight to your inbox weekly.