Information Systems Security Officer - Xpect Solutions
Overview
Lead compliance and security operations for government information systems. Navigate the full NIST Risk Management Framework and ensure adherence to NIST 800-53 controls and DHS 4300A requirements. Partner with Government Security Assurance Management teams to protect critical systems and maintain compliance posture.
What You'll Do16
- 1Risk Management Framework & Authorization
- 2Ensure systems comply with NIST 800-53 security controls and DHS 4300A requirements
- 3Prepare comprehensive security documentation and collect security artifacts in advance of assessments
- 4Conduct self-assessments and support Security Control Assessment activities
- 5Evaluate effectiveness of proposed solutions to audit findings and perform root cause analysis
- 6Develop security control implementation statements and review supporting procedures
- 7Review and update the System Security Plan and support security documentation
- 8Perform security impact analysis of proposed configuration changes and review implications with ITPMs
- 9Support all Authorization to Operate and continuous authorization activities
- 10Plan of Action and Milestones management to track system weaknesses to resolution
- 11Monitor and manage continuous monitoring including vulnerability scans and patch management
- 12Audit log monitoring and event management for security incidents and anomalous activity
- 13Ensure security awareness and training for all system users annually
- 14Prioritize security-related tasks in agile development environments
- 15Provide 24x7 on-call support for security incidents and escalations
- 16Enforce Zero Trust cybersecurity principles and support zero trust network architecture adoption
Requirements11
- 1Public Trust Level 6C
- 2Bachelor's Degree in Physics Mathematics Information Technology Computer Science Business or related discipline
- 3Minimum 5 years of professional experience in cybersecurity information assurance or related technical roles
- 4Demonstrable expertise in NIST RMF NIST 800-53 NIST 800-37 and DHS 4300A requirements
- 5Knowledge of federal and/or state government information security practices
- 6Excellent written and oral communication skills
- 7Ability to work on-site in Crystal City Virginia one day per week
- 8CISSP CCSK GCIH or other advanced cybersecurity certification preferred
- 9Experience with FedRAMP FISMA or other federal compliance frameworks
- 10Hands-on experience with vulnerability assessment tools such as Nessus WebInspect Qualys
- 11Experience in Zero Trust architecture design and implementation
Salary Insight
Salary not disclosed in listing
Location
Required Skills
Similar open positions
Explore active roles that match your skills and interests.
TSTC
VerifiedInformation Systems Security Officer
TSTC seeks a contingent full-time Information Systems Security Officer to support a new contract at Customs & Border Patrol. The ISSO will create revise document and maintain security policies while developing and implementing security plans to protect sensitive data. Review client information security systems and recommend improvements. This role differs by focusing on federal agency collaboration and compliance with NIST standards.
02 CACI, INC.-FEDERAL
VerifiedInformation System Security Manager
Lead and oversee Risk Management Framework lifecycle activities for classified DoD systems supporting SAP SCI NSA missions. Manage system authorizations and cybersecurity compliance while serving as senior cybersecurity authority. Ensure systems remain secure compliant and fully authorized to operate.
OCT Consulting, LLC
VerifiedIT Security Vulnerability Specialist - OCT Consulting
OCT Consulting seeks an Associate IT Security Vulnerability Specialist to lead vulnerability remediation for federal clients. This hybrid role requires 3 days weekly presence in Suitland MD. The ideal candidate will drive efficiency in vulnerability management while articulating risk to leadership. You will conduct assessments monitor tools develop policies and participate in incident response. Experience with NIST RMF and security frameworks is essential.
Inadev
VerifiedInformation System Security Officer (ISSO), RMF & NIST
Own the security posture and authorization of a federal system as ISSO at Inadev. Manage the RMF lifecycle, maintain ATO documentation, and ensure continuous compliance with NIST 800-53 and FedRAMP. You will track findings, coordinate with DevSecOps, and report risks to stakeholders. This contract role offers a hybrid schedule in DC and Reston, VA, working with a vibrant team. You bring 5+ years of ISSO experience and a CISSP or equivalent certification.
1805 KBR Wyle Services, LLC
VerifiedSenior Information System Security Officer (ISSO)
Lead cybersecurity approval and compliance processes while supporting system owners and project managers. Review technical architectures and integrate security requirements throughout the system lifecycle. Ensure cybersecurity compliance and provide guidance to engineers and non-technical partners.
GD Information Technology, Inc.
VerifiedInformation Systems Security Manager (ISSM) - RMF & XACTA
Information Systems Security Management (ISSM), you will own the RMF workflow and A&A process for a premier cyber security risk management platform supporting DoD and Intelligence Community customers. You will ensure operational IT capabilities deliver timeliness, accuracy, and security of information across multiple fabrics and centers. Your days involve coordinating with stakeholders, managing system vulnerabilities, and maintaining compliance with NIST standards. This role stands out because you'll directly impact national security while working with leading-edge tools like XACTA 360 and STIGs. You will be the go-to expert for all security authorizations, guiding systems from concept to Authority to Operate (ATO).