
Information System Security Officer – ISSO
Posted 16 hours ago

Posted 16 hours ago
This is a fully remote position, open to applicants in United States.
• Act as the primary contact for all matters concerning systems security.
• Oversee cybersecurity engineering initiatives for designated Program Management Organizations.
• Provide direct assistance to the Compliance Branch Lead.
• Lead efforts for systems' Authority to Operate (ATO).
• Ensure the security posture aligns with FISMA, DHS 4300 Series, NIST, and DHS and Component Directives.
• Implement comprehensive Risk Management Framework (RMF) activities for ATO decisions.
• Conduct system categorization, selection and implementation of security controls, self-assessments, development of Plans of Action and Milestones (POA&M), and continuous monitoring.
• Create and maintain System Security Plans (SSPs), which include control baselines, inheritance, Business Impact Analyses, implementation statements, technical and system descriptions, and inventories of hardware and software.
• Develop and uphold Configuration Management Plans.
• Perform Security Impact Analyses, authorize Change Requests, and document security impacts from configuration changes.
• Formulate and test Contingency Plans and Incident Response Plans.
• Carry out annual risk assessments and assist with security and vulnerability assessments.
• Counsel system owners and senior executives on cybersecurity issues.
• Create remediation work plans for findings from assessments and audits.
• Maintain up-to-date Hardware and Software Inventory Lists.
• Conduct FISMA Scorecard Analysis.
• Ensure appropriate access controls for system access.
• Monitor and recommend technologies, processes, and practices to safeguard networks, devices, programs, and data.
• Research and stay proficient in tools, techniques, countermeasures, and trends related to computer and network vulnerabilities, data hiding, network and device security, and encryption.
• Must be a U.S. Citizen.
• DHS Entry on Duty (EOD) suitability or current DHS EOD is preferred.
• A Bachelor’s degree plus 8 years of relevant experience in information security.
• At least 7 years of experience in information security is required.
• Proven expertise in RMF, Information Security processes, audits, tools, implementation, FISMA, NIST, and IT security.
• Experience in developing System Security Plans, POA&Ms, and Configuration Management Plans.
• Familiarity with NIST SP 800-37, NIST SP 800-53, and DHS 4300 Series requirements.
• One of the following Information Assurance Technician (IAT) Level III certifications is preferred: CISSP, CISM, or CompTIA Advanced Security Practitioner (CASP+).
• Prior experience with DHS is preferred.
• Experience with CSAM, RegScale, eMASS, or similar Governance, Risk, and Compliance (GRC) tools is preferred.
• Background in supporting emergency operations or disaster response missions is preferred.
• Knowledge of cloud security and FedRAMP authorization processes is preferred.
• Experience with continuous monitoring is preferred.
• Flexible time off benefit.
• Comprehensive learning resources.
• Opportunities for learning and development.
• Healthcare benefits.
• Wellness benefits.
• Financial benefits.
• Retirement benefits.
• Family support benefits.
• Continuing education benefits.
• Generous time off benefits.
Sony Interactive Entertainment
Squads
Neo4j
PingWind Inc. (SDVOSB)
Get handpicked remote jobs straight to your inbox weekly.