
Information Systems Security Officer – ISSO
CGS Federal (Contact Government Services)
full-time
Posted on:
Location Type: Hybrid
Location: Baltimore • Maryland • United States
Visit company websiteExplore more
Salary
💰 $92,213 - $125,147 per year
Tech Stack
About the role
- Conduct security assessment, and information system security oversight activities in accordance with NIST 800.53 that support systems from the perspective RMF requirements.
- Review systems to identify potential security weaknesses and recommend improvements to amend vulnerabilities, implement changes, and document upgrades.
- Maintain responsibility for managing cybersecurity risk from an organizational perspective.
- Identify organizational risks, prioritize those risks, and maintain a risk registry for escalating and presenting those risks to senior leadership.
- Provide security guidance and IS validation using the National Institute of Standards and Technology (NIST) RMF, DoC, and local security policies.
- Provide configuration management (CM) recommendations for information system security software, hardware, and firmware and coordinating changes and modifications with the ISSM, Security Control Assessor (SCA), and Authorizing Official (AO).
- Maintain vulnerability scanning tool compliance, such as HBSS or ACAS, and patch management, such as IAVM to ensure IT staff pushes patches to all systems in an effort to maintain compliance with all applicable directives, manage system changes, and assess the security impact of those changes.
- Support security authorization activities, including transitioning from the legacy Information Assurance Certification and Accreditation Process (DIACAP) to compliance with the DoC RMF.
Requirements
- Bachelor’s Degree.
- A minimum of five (5) years experience as an Information Assurance (IA) Analyst, ISSE, ISSO, or similar role in ATO package development, including generating security documentation for requirements, security control assessment, STIG and IAVA compliance, Standard Operating Procedures, test results, etc.
- eMASS experience.
- Professional security certification such as: CCNA Security, CySA+, GICSP, GSEC, CompTIA Security+ CE, SSCP, or higher.
- Strong desktop publishing skills using Microsoft Word and Excel.
- Experience with industry writing styles such as grammar, sentence form, and structure.
- Ability to multi-task in a deadline-oriented environment.
Benefits
- Health, Dental, and Vision
- Life Insurance
- 401k
- Flexible Spending Account (Health, Dependent Care, and Commuter)
- Paid Time Off and Observance of State/Federal Holidays
Applicant Tracking System Keywords
Tip: use these terms in your resume and cover letter to boost ATS matches.
Hard Skills & Tools
security assessmentinformation system security oversightNIST 800.53risk management framework (RMF)vulnerability scanningconfiguration management (CM)security control assessmentSTIG complianceIAVA complianceeMASS
Soft Skills
organizational risk managementcommunicationmulti-taskingdeadline-oriented
Certifications
CCNA SecurityCySA+GICSPGSECCompTIA Security+ CESSCP