Quick Overview
Seniority
Mid Senior
Work mode
Hybrid
Location
Washington, DC, United States
Posted
4 weeks ago
Penetration Testing
Job Description
Job Description Overview of Role
The ISSO will serve as the Security Documentation and Security Impact Analysis Specialist on the DFC ISSO Support Services contract. This role demands strong technical writing capability, meticulous version control discipline, deep familiarity with DFC OIT document templates, and a thorough understanding of how system changes affect security posture and authorization boundary integrity.
Roles and Responsibilities
- RMF & A&A Management: Drive the end-to-end NIST RMF lifecycle for assigned systems. Develop, review, and maintain critical Assessment and Authorization documentation, including System Security Plans and Security Assessment Reports.
- Continuous Monitoring: Execute Information Security Continuous Monitoring (ISCM) strategies, analyze system audit logs, and generate operational security health reports for leadership.
- Vulnerability & POA&M Management: Coordinate vulnerability scanning and penetration testing. Actively manage the Plan of Action and Milestones lifecycle to ensure timely remediation of security weaknesses.
- Security Engineering Support: Integrate security into the System Development Life Cycle (SDLC) by evaluating control implementations and enforcing secure baselines (e.g., DISA STIGs, CIS Benchmarks).
- Incident & Contingency Operations: Support the detection and containment of security incidents. Assist in drafting, testing, and updating Incident Response Plans and Contingency Plans.
- Compliance Enforcement: Validate user access requirements, enforce agency-specific security policies, and ensure completion of role-based security training.
- Minimum 3–5 years of direct experience in federal ISSO duties, cybersecurity documentation, or information assurance support for FISMA Moderate or higher programs
- No problems, only solutions!
Educational and Certification Requirement: • Bachelor's degree in Cybersecurity, Information Technology, Computer Science, or a related field
- Security+; CAP or comparable RMF certification preferred
Similar jobs
- PE
Cyber Splunk Software Engineer with Security Clearance
Peraton
Annapolis Junction, MD🇺🇸$135k - $216k/yrHybrid1 week agoAWSSplunkAzure+4Technology - PE
Director of Information Assurance with Security Clearance
Peraton
Reston, VA🇺🇸$176k - $282k/yrHybrid3 weeks agoComplianceHTTPSRisk Assessment+2 - PE
Jr Cyber Software Engineer with Security Clearance
Peraton
San Diego, CA🇺🇸$80k - $128k/yrHybrid3 weeks agoShellC++Go+3Technology - PE
SITEC - Cyber Defense Incident Responder (SR)- Fort Bragg, NC with Security Clearance
Peraton
Fort Bragg, NC🇺🇸$80k - $128k/yrHybrid5 weeks agoHTTPSPowerShellPythonTechnology - PE
Cyber Case Management - Mid-level Process Assurance Analyst / Ac with Security Clearance
Peraton
Washington, DC🇺🇸$86k - $138k/yrOn-site5 weeks agoHTTPSLESSTechnology - PE
SITEC - Cyber Defense Incident Responder - MacDill AFB with Security Clearance
Peraton
Macdill AFB, FL🇺🇸$66k - $106k/yrHybrid5 weeks agoHTTPSPowerShellPythonTechnology