
Information System Security Officer – ISSO
Posted 16 hours ago

Posted 16 hours ago
This is a fully remote position, open to applicants in United States.
• Act as the primary liaison for all systems security-related issues.
• Oversee cybersecurity engineering initiatives for designated Program Management Organizations.
• Provide support to the Compliance Branch Lead.
• Lead the efforts for obtaining systems’ Authority to Operate (ATO).
• Implement comprehensive Risk Management Framework (RMF) activities concerning ATO decisions.
• Carry out system categorization, selection and implementation of security controls, self-assessments, development of Plans of Action and Milestones (POA&M), and ongoing monitoring.
• Create and update System Security Plans, which encompass control baselines, inheritance, Business Impact Analyses, implementation statements, technical/system descriptions, and inventories of hardware/software.
• Develop and sustain Configuration Management Plans.
• Perform Security Impact Analyses, authorize Change Requests, and record the security implications of configuration changes.
• Formulate and test Contingency Plans and Incident Response Plans.
• Conduct yearly risk assessments and assist in security and vulnerability evaluations.
• Counsel system owners and senior executives regarding cybersecurity issues.
• Create remediation action plans for findings from assessments and audits.
• Keep hardware and software inventory records.
• Execute FISMA Scorecard Analysis.
• Ensure appropriate access controls for system access.
• Monitor and recommend technologies, processes, and practices to safeguard networks, devices, programs, and data.
• Investigate and maintain expertise in cybersecurity tools, techniques, countermeasures, and trends in vulnerability, data-hiding, network, device security, and encryption.
• U.S. Citizenship is required.
• DHS Entry on Duty (EOD) suitability or current DHS EOD status is preferred.
• Bachelor's degree and 8 years of relevant experience in information security.
• A minimum of 7 years of experience in information security.
• Proven expertise in RMF, Information Security processes, audits, tools, implementation, FISMA, NIST, and IT security.
• Experience in developing System Security Plans, POA&Ms, and Configuration Management Plans.
• Familiarity with NIST SP 800-37, NIST SP 800-53, and DHS 4300 Series requirements.
• One of the following IAT Level III certifications is preferred: CISSP, CISM, or CompTIA CASP+.
• Previous experience with DHS is preferred.
• Experience with CSAM, RegScale, eMASS, or similar Governance, Risk, and Compliance (GRC) tools is preferred.
• Experience in supporting emergency operations or disaster response missions is preferred.
• Knowledge of cloud security and FedRAMP authorization processes is preferred.
• Experience with continuous monitoring is preferred.
• Flexible time off benefit.
• Comprehensive learning resources.
• Healthcare benefits.
• Wellness benefits.
• Financial benefits.
• Retirement benefits.
• Family support benefits.
• Continuing education benefits.
• Time off benefits.
• Competitive compensation.
• Opportunities for learning and development.
Sony Interactive Entertainment
Squads
Neo4j
PingWind Inc. (SDVOSB)
Get handpicked remote jobs straight to your inbox weekly.