Information System Security Officer

2 weeks ago


Fairfax Station, United States Tiber Creek Consulting Full time

**Information System Security Officer (ISSO) / Information Assurance (IA) AnalystFairfax, VA / Telework**

Tiber Creek Consulting, Inc. is seeking an experienced ISSO / IA Analyst to serve as an information security subject matter expert (SME) as part of a growing cybersecurity operations team in Fairfax VA / Telework. You will support federal agency ATO processes for DHS and DoD, responsible for assessing and ensuring operational, technical, and privacy information security compliance for federal and commercial clients. Federal ISSO Experience Required. DHS ISSO Experience Strongly Preferred. Candidates must be US citizens clearable for DHS EOD Suitability clearance and/or DoD Secret clearance, due to federal contract requirements.

You will support executing full Security Assessment and Authorization (SA&A) life cycle and risk management functions, measuring risk, implementing system and ATO related documentation, providing technical and security control related guidance, recommendations on remediation solutions, oversight and guidance related to NIST RMF and ATO processes to project team members, proposing intuitive ways to solve complex cybersecurity compliance challenges, navigating Plan of Action and Milestones (POA&M) process, maintaining communication with federal client stakeholders and federal client information security team members, establishing and performing NIST RMF and ATO related continuous monitoring strategies and solutions, managing NIST RMF and ATO related project plans, testing system technical security configuration settings and developing reports.

The successful candidate demonstrates subject matter expertise in security control, NIST RMF, and ATO related processes; leverages knowledge of Plan of Action and Milestones (POA&M) management and continuous monitoring objectives; provides guidance on system technical security configurations and solutions to meet ATO requirements; reviews various system scan results for compliance with industry standards, and assists with developing and reviewing compliance reports that clearly identify security findings and proposed remediation strategies. We offer generous medical, dental, and disability insurance benefits, flexible spending, 401(k), ample vacation/leave time, training/skills building opportunities and a great work environment.

Apply To:Certifications:Security+ certification is required. CISA, CASP, or CISSP preferred.Experience:5+ years related work experience. Federal ISSO Experience Required. DHS ISSO Experience Strongly Preferred.Clearance:Candidates must be US citizens who are clearable for a DHS EOD Suitability clearance and/or DoD Secret clearance, due to federal contract requirements.Related Experience Should Include:

* Strong understanding of federal information security related processes, frameworks, standards, and regulations.

* Strong security system analysis skills and understanding of Cyber and IT security risks, threats and prevention measures.

* Experience in documenting ATO related artifacts to include but not limited to System Security Plans (SSP), Ports, Protocols, Services; Remediation Consolidation Plans (RCP), Plan of Action and Milestones (POA&M), Information System Contingency Plan (ISCP), Incident Response Plan (IRP), Continuous Monitoring Strategies/Plans, Information System Vulnerability Management (ISVM), OIG formatted security control implementation statements, Risk Acceptance Letters, Waivers, Interconnection Security Agreements (ISA), Memorandum of Understanding (MOU), Memorandum of Agreement (MOA), Security Assessment Reports (SAR), etc.

* Experience in proposing and providing guidance in compliant technologies, architectures, and solutions.

* Experience in working with software and system engineers in an ISSO role.

* Experience with cloud security approaches and cloud architectures. Preferred experience with Azure and AWS to include understanding FedRAMP and Security Control Inheritance, developing Shared/Customer Responsibility Matrices.

* Experience with Federal Governance, Risk Management, and Compliance or ATO related tools and content is preferred such as: eMASS, Xacta/IACS, CSAM, Continuum, SCAP/STIG, USGCB, Nessus/Tenable, etc.

* Experience supporting customers in either Federal Government and/or other industry specific Cybersecurity Compliance and Regulatory standards/frameworks.

* Experience with a variety of cybersecurity compliance standards, policies, regulations and frameworks such as: NIST RMF, FISMA, NIST SP800-53r4, FedRAMP, NIST SP800-171r1, Cybersecurity Maturity Model Certification (CMMC), NIST CSF, FIPS, NIST SP800-60, PCI-DSS, HIPAA, SOC 2, ISO27001, DHS 4300A, other Federal agency specific policies and tailoring criteria.

* Knowledgeable of Cybersecurity/IA solutions/architectures such as PKI, VPN, Enterprise Firewalls, IPS, IDS, SCAP, STIG, Nessus, ACAS, SIEM, HIDS, NIDS, MFA, EDR, FIM, CMDB, Vulnerability Scanners, AV solutions, data at rest encryption solutions, data in transit encryption solutions, penetration testing tools, etc.

* In-depth understanding of networking and network security; cloud security, network monitoring solutions/approaches.

* Experience in writing and designing information security policies, procedures, standards, guides, plans, etc.

* Must be able to multi-task and support a cross-matrixed team efficiently by working through many client projects and support internal team functions.

* Must have ability to solve complex information security related challenges and propose strategic/pragmatic approaches to the team and clients.

Job Duties:

* Support a federal NIST RMF/ATO project for a system developed by Tiber Creek and hosted in a cloud environment/architecture.

* Generate and design a variety of documentation and navigating associated processes such as System Security Plans (SSP), Plan of Actions and Milestones (POA&M), Interconnection Security Agreements (ISA), Information System Vulnerability Management (ISVM), Continuous Monitoring Strategies, Security Operation Center (SOC) strategies, Information System Contingency Plans (ISCP), Incident Response Plans (IRP), Configuration Management Processes, etc.

* Support a variety of federal and commercial clients as a Information System Security Officer (ISSO), to include security and system architecture design and input.

* Support Incident Response (IR) actions and reporting.

* Write/develop security and risk reports and related documentation.

* Consult clients on various mitigation and remediation solutions/methods.

* Navigate and manage Federal ATO processes and POA&M remediation processes.

* Provide Subject Matter Expertise (SME) input to System Engineers, Project Managers, Software Engineers to implement compliant configurations and solutions, including methods to implement NIST RMF and ATO compliant strategies/solutions for a Cloud System (AWS/Azure) in development for federal clients being provided in a Software as a Service (SaaS) model.

* Perform enterprise-wide risk analysis and vulnerability assessments and management.

* Provide SME support for automating cybersecurity operations via technology solutions and strategies.

Physical Demands and Work Environment:

* Some local and long distance travel may be required.

* Usual office working conditions and standard office equipment. Required to sit for long periods of time using a personal computer. Some light physical effort required.

* Reasonable accommodations may be made to enable individuals with disabilities to perform the essential functions of this position.

* Full time remote/telework is an option and may be required during the current COVID-19 pandemic.

Minimum Qualifiers:

* Unable to work with 3rd party candidates or agencies.



  • Fairfax, United States Azure Summit Technology Full time

    **Are you in?** Do you work well in a team environment and on your own as an individual contributor? Do you know how to set the bar high and achieve goals for yourself and bring others along with you? Do you work hard and play hard? Do you want to help the company succeed and build your skill set and further your career at the same time? Azure Summit...


  • Fairfax, United States Tiber Creek Consulting Full time

    **Information System Security Officer (ISSO) / Information Assurance (IA) AnalystFairfax, VA / Telework** Tiber Creek Consulting, Inc. is seeking an experienced ISSO / IA Analyst to serve as an information security subject matter expert (SME) as part of a growing cybersecurity operations team in Fairfax VA / Telework. You will support federal agency ATO...


  • Fairfax Station, United States Redtracetech Full time

    **RedTrace Technologies Inc** **Information Systems Security Officer - ISSO (TS required, eligible for SCI)** **Fairfax, VA - Full Time** Apply: Information Systems Security Officer - ISSO (TS required, eligible for SCI) * Required fields First name* Last name* Email address* Location Phone number* Resume* or Attach resume as .pdf, .doc, .docx, .odt, .txt,...


  • Fairfax, United States Virginia Jobs Full time

    Title: College Information Security Officer Agency: Northern VA Community College Location: Fairfax County - 059 FLSA: Exempt Hiring Range: Commensurate with Experience (up to $175,000 max) Full Time or Part Time: Full Time Additional Detail Job Description: General Description: The College Information Security Officer (ISO) is responsible for the...


  • Fairfax, United States Security Assurance Management Full time

    Job DescriptionJob DescriptionDCJS Registered OnlyWe are currently hiring for unarmed Security in Fairfax, VA Must have a Current DCJS Security Officer LicenseMinimum 2 years of Security Officer ExperienceMust be a Self-Motivator with Good work EthicsMust be able to work with minimal supervisionMust be able to work any scheduleAbility to effectively...


  • College Station, United States Transportation Security Administration Full time

    Summary Transportation Security Officers are responsible for providing security and protection of travelers across all transportation sectors in a courteous and professional manner. Their duties may also extend to securing high-profile events, important figures and/or anything that includes or impacts our transportation systems. Learn more about the...


  • Fairfax, United States CGI Group, Inc. Full time

    Information Systems Security Manager (ISSM) Position Description This is an exciting full-time opportunity to work in a fast-paced environment with a team of passionate technologists. We take an innovative approach to supporting our client, working side-by-side in an agile environment using emerging technologies. As a solution builder, you will be working...


  • Fairfax, United States Kavaliro Full time

    Senior Information Systems Security Engineer (ISSE) Kavaliro is seeking a Senior Information Systems Security Engineer (ISSE) to directly support the Secretary of the Air Force/Concept Development Management Office (SAF/CDM), Mission Architecture Innovation directorate (CDMM). The ISSE will be responsible for conducting technical security engineering...


  • Fairfax, United States Arcetyp LLC Full time

    Job Description Job Description Salary: Arcetyp LLC is a growing small business that provides a broad range of consulting services to US Federal Government, US Military, and Commercial clients. Services include Management & IT Consulting, Program & Project Management, and Professional & Admin Services. We are recruiting to fill a position to lead business...


  • Fairfax, United States Arcetyp LLC Full time

    Job DescriptionJob DescriptionSalary: Arcetyp LLC is a growing small business that provides a broad range of consulting services to US Federal Government, US Military, and Commercial clients.  Services include Management & IT Consulting, Program & Project Management, and Professional & Admin Services. We are recruiting to fill a position to lead business...


  • Fairfax, United States TRICORPS SECURITY Full time

    TriCorps is seeking highly qualified armed security officers to work in a school setting in Fairfax, VA area. We have part-time openings available. **Requirements**: - Valid Armed Security License - Valid Driver's License - Must be reliable, have a positive attitude, and uphold ethical behavior. - Provide assistance to employees and visitors in a courteous...

  • Security Officer

    7 days ago


    College Station, United States Signal Security Full time

    Post Location: College Station, TXSchedule: Part Time, 3rd Shift 10P-6AM, Sunday thru SaturdayPay Rate: $14.00 per hourRequirements: 18 years of age, must pass background and drug screen, must have level II guard card by start date.Benefits:•Tuition Assistance for PT/FT/Immediate Family Members (Bellevue University – online)•Paid training•Flexible...


  • Fairfax, United States ZTI Solutions, LLC Full time $150,000 - $220,000

    Job Description:Senior Information Systems Security Manager (ISSM), Fairfax, VA.Summary:Provide senior-level security certification and accreditation consulting related to the maintenance, upgrade, and technology insertion for a DoD-approved classified network with multiple sites. Specifically, maintain, update, and create new policies/procedures/SOPs and...


  • Marine Corps Air Station Cherry Point, United States Lockheed Martin Full time

    Description:Lockheed Martin is a Cyber Security pioneer, partner, innovator, and builder. Our amazing employees are on a mission to make a difference in the world and every single day we use our unique skills and experiences to create, design and build solutions to some of the worlds’ hardest engineering problems. Do you want to be part of a culture that...


  • Fairfax, United States Tevora Full time

    Job DescriptionJob DescriptionInformation Security Consultant - System and Organization Controls (SOC 1 / SOC 2) Compliance at TevoraFairfax, VAIf you haven't heard of Tevora, it's because we've done our job!Tevora is a tight-knit community of professionals with a shared passion for our craft. Every day, we combine in-depth knowledge of...


  • Fairfax, United States Sentry Force Security LLC Full time

    Job DescriptionJob DescriptionWe are seeking reliable and experienced Unarmed Security Officers to become an integral part of our team. These unarmed security officers will patrol and secure assigned premises as well as identify risks to staff and patrons. Full time and part time positions available. The pay range for this position is...


  • Fairfax, United States Sentry Force Security LLC Full time

    Job DescriptionJob DescriptionWe are seeking reliable and experienced Armed Security Officers to become an integral part of our team. These armed security officers will patrol and secure assigned premises as well as identify risks to staff and patrons. Full time and part time positions available. The pay range for this position is...


  • Fairfax, United States WIDELITY INC Full time

    Job DescriptionJob DescriptionFacility Security Officer (FSO) & National Security Manager Widelity is seeking an experienced security professional to join us as the Facility Security Officer (FSO) and a member of the national security team at our innovative technology company. As an FSO, your responsibilities will entail the implementation, compliance and...


  • Fairfax, United States Information Technology Engineering Corporation Full time

    Linux System Administrator Location: Fairfax, VA Required Clearance: Top Secret/SCI w/ CI Poly   U.S. Citizenship Mandatory: Due to our US federal government contract, candidates for this position are required to be a US Citizen and will be subject to a background investigation.  Job Responsibilities: The primary responsibilities of the System...


  • Fairfax, United States Addison Group Full time

    Job DescriptionJob DescriptionPosition: Computer and Information Systems AdministratorLocation: Fairfax, VA - Fully Onsite 5 Days A Week Are you looking for a growth opportunity for a reputable company with a positive work environment? Our client is looking for a Computer and Information Systems Administrator to join their team. Please contact us today to...