Why This Role Stands Out
This hybrid Information Systems Security Officer role offers a fantastic opportunity to grow your expertise in cybersecurity engineering and system accreditation, directly impacting critical security programs with a reputable company. You'll thrive here if you're a proactive professional with a knack for risk management and compliance, eager to contribute to a secure technological future.
Quick Overview
Job Description
The Opportunity The ISSO, working closely with the customer's ISSO, directly supports efforts to plan, coordinate and implement the information security program and system accreditation lifecycle. Responsible for enterprise and system-level cybersecurity engineering tasks. Identifies security risks and integrates required security controls as set forth by policy. Ensures security compliance of information technology applications. Responsible for monitoring security policies and procedures, coordinating internal security audits and security exercises, delivering required security training and participating in coordination meetings.
Key Responsibilities (Principal Duties and Accountabilities *Essential Functions)
- Primary liaison to customer ISSO to support the system accreditation process and Authorization to Operate (ATO) efforts, audits, and reaccreditation cycles; Utilizes customer's security governance tool for the system authorization and ATO lifecycle
- Working closely with engineers, utilizes vulnerability scanning tools and reports to track and remediate findings
- Evaluates and validates physical security to ensure support of systems security requirements
- Tracks and manages Plans of Action and Milestones (POA&M's) that are out of compliance
- Supports NIST RMF implementation and documentation including annual security control review
- Coordinates and assists with internal security audits
- Develops and maintains security documentation such as the System Security Plan, system boundary diagram, inventory of hardware and software, ports and protocols, etc.
- Develops, coordinates and tests incident response plans, contingency plans and security tabletops/exercises
- Documents system parameters and ensure all security documents are kept current
- Asses proposed changes to information systems; identifies risks and impacts; Performs Security Impact Analysis (SIA) and submits change control requests for system enhancements to the ATO package
- Participates in new technology enhancements and implementations and its implication on the system boundary
- Assists in testing system function pre and post security control implementations
- Delivers annual compliance training as mandated by policy and regulatory standard
- Oversees user account provisioning, permission review, and access enforcement for system integrity
- Develops and maintains Memorandum of Understanding (MOUs) and Interconnection Service Agreements (ISAs) with internal organizations and external entities to support secure information system interconnections and data sharing
- Participating in special projects as required
Similar jobs
- IN
IT Security Specialist III
NewInnova
Plano, TX🇺🇸$73 - $78/hrHybrid14 hours agoAgileTechnology - MT
Cybersecurity Analyst
NewMKS2 Technologies
Aiea, Hawaii🇺🇸On-site49 minutes agoTechnology - BA
EDAT- Journeyman Cyber Security Engineer (Microsoft) - Zero Trust- Tampa, FL
NewBarbaricum
Tampa, Florida🇺🇸On-site49 minutes agoAzureBashC#+3Technology - AS
Security & Identity Engineer
NewApex Systems
Miramar, FL🇺🇸$60 - $90/hrRemote14 hours agoAdministrative - TJ
Penetration Tester with Security Clearance
The Judge Group
Beltsville, MD🇺🇸On-site6 weeks agoGCPAWSActive Directory+5Technology - AS
Senior AI Security Engineer
NewApex Systems
Miami, FL🇺🇸$80 - $90/hrOn-site14 hours agoAPI GatewayEncryptionSplunkTechnology