Why This Role Stands Out
This hybrid Information System Security Officer role at Business Operational Concepts offers a fantastic opportunity to grow your cybersecurity expertise while supporting critical federal initiatives, with excellent compensation and a commitment to advancement. You'll thrive here if you're adept at NIST CSF, RMF, and vulnerability management, eager to contribute to a reputable company with a positive work environment. Apply now to advance your career in a dynamic and supportive setting.
Quick Overview
Job Description
Description
Business Operational Concepts (BOC) is a recognized leader in providing Technical and Program Management Services, Information Technology, and Support.
BOC has enabled their Government and Commercial clients to achieve their organizational initiatives through the application of high quality, innovative, and cost-effective professional services and solutions. We provide a positive working environment, with opportunities for advancement in our growing Federal sector workforce.
We offer an excellent compensation package which includes a generous salary, insurance (medical, dental, etc.), paid leave, 401k plan and more. We are committed to the diversity we bring to the marketplace and believe customer satisfaction comes first.
JOB SUMMARY
Business Operational Concepts (BOC) is currently seeking a seeking an Information System Security Officer (ISSO) to work with our federal client. The ideal candidate will support cybersecurity, governance, risk management, compliance, engineering, automation, and program management activities for the federal client.
The ISSO will support agency information systems and cybersecurity processes in accordance with federal cybersecurity requirements and will assist with implementation of the NIST Cybersecurity Framework (CSF) 2.0, Risk Management Framework activities, system authorization, continuous monitoring, vulnerability management, privacy compliance, and related cybersecurity activities.
DUTIES AND RESPONSIBILITIES
- Serve as an advisor to IT management, system owners, business process owners, and senior management on matters related to the security and privacy of assigned information systems.
- Support applicable agency systems, cloud environments, on-premises infrastructure, hybrid systems, SaaS platforms, identity services, endpoint platforms, vulnerability management tools, logging and monitoring platforms, and security governance processes.
- Coordinate with stakeholders to categorize systems, define system boundaries, establish interconnection agreements, and support adherence to applicable federal policies, including Zero Trust principles where applicable.
- Support cybersecurity governance, risk management, compliance, engineering, automation, and program activities associated with implementation of NIST Cybersecurity Framework 2.0.
- Develop and/or update cybersecurity processes and artifacts in alignment with NIST CSF 2.0.
- Support Privacy Threshold Analyses (PTAs), Privacy Impact Assessments (PIAs), and other privacy compliance activities.
- Support identification, tracking, remediation, and closure of Non-Functional Requirements (NFRs) and security findings.
- Support transition from a static three-year system authorization model to an ongoing authorization and Continuous Monitoring model.
- Support the agency's use of the Caveonix platform for governance, risk, compliance, and continuous monitoring activities.
- Assess and support Authority to Operate (ATO) packages for assigned systems.
- Develop and maintain required system authorization artifacts, including:
- System Security Plans (SSPs)
- Security Assessment Reports (SARs)
- Plans of Action and Milestones (POA&Ms)
- Security Impact Analyses (SIAs)
- Support Continuous Monitoring activities, including security control validation, vulnerability management, risk assessments, evidence collection, cybersecurity metrics, and reporting.
- Support applicable federal and agency cybersecurity, security, privacy, and AI requirements.
- Support cybersecurity activities associated with the agency's cloud environment, including Azure and Microsoft 365, as required.
- Support cybersecurity activities associated with changes to infrastructure and security posture.
- Provide ongoing cybersecurity subject-matter support, including support for annual FISMA audit activities.
- Maintain required cybersecurity documentation and provide status and supporting information as required by program management and the Government.
Requirements
QUALIFICATIONS:
Required (Minimum) Qualifications Education, Certification, Experience, and Skills
- A Bachelor's degree or equivalent work experience in an IT-related field.
- A minimum of five (5) years of hands-on experience performing ISSO or equivalent functions in a federal environment.
- Demonstrated experience developing and maintaining:
- SSPs
- SARs
- POA&Ms
- SIAs
- ATO documentation
- Experience with:
- Continuous Monitoring
- Vulnerability Management
- Risk Assessments
- Privacy compliance activities, including PTA and PIA support.
Preferred Qualifications Education, Certification, Experience, Skills, Knowledge, and Abilities
- Required Certification
- CompTIA Security+
- Preferred Certifications
- The following certifications are preferred but are not required:
- (ISC) Certified Information Systems Security Professional (CISSP)
- Certified Information Security Manager (CISM)
- Certified Information Systems Auditor (CISA)
Similar jobs
- NO
Information Systems Security Engineer (ISSE) - U.S. Navy Programs
NewNoblis
Philadelphia, PA🇺🇸$78.9k - $123.3k/yrOn-site13 hours agoTechnology - HA
Specialist, Cyber Intelligence (ISSO)
Harris Corporation
Colorado Springs, CO🇺🇸$80.5k - $149.5k/yrHybrid3 days agoTechnology - TS
Cyber Mission Analyst with Security Clearance
NewTwo Six Technologies
Arlington, VA🇺🇸On-site13 hours agoTechnology - FS
Senior Cyber Control Systems Engineer with Security Clearance
NewFive Stones Research Corporation
Schriever AFB, CO🇺🇸$135k - $175k/yrHybrid13 hours agoTechnology - EG
Information Security Analyst - Exposure Management Lead
NewEliassen Group
Cincinnati, OH🇺🇸$85 - $95/hrOn-site13 hours agoTechnology - TA
Information Systems Security Officer (ISSO) with Security Clearance
NewTrue Anomaly. Inc.
Denver, CO🇺🇸$115k - $160k/yrOn-site13 hours agoTechnology