Information System Security Officer

3 weeks ago


Fairfax Station, United States Tiber Creek Consulting Full time

**Information System Security Officer (ISSO) / Information Assurance (IA) AnalystFairfax, VA / Telework**

Tiber Creek Consulting, Inc. is seeking an experienced ISSO / IA Analyst to serve as an information security subject matter expert (SME) as part of a growing cybersecurity operations team in Fairfax VA / Telework. You will support federal agency ATO processes for DHS and DoD, responsible for assessing and ensuring operational, technical, and privacy information security compliance for federal and commercial clients. Federal ISSO Experience Required. DHS ISSO Experience Strongly Preferred. Candidates must be US citizens clearable for DHS EOD Suitability clearance and/or DoD Secret clearance, due to federal contract requirements.

You will support executing full Security Assessment and Authorization (SA&A) life cycle and risk management functions, measuring risk, implementing system and ATO related documentation, providing technical and security control related guidance, recommendations on remediation solutions, oversight and guidance related to NIST RMF and ATO processes to project team members, proposing intuitive ways to solve complex cybersecurity compliance challenges, navigating Plan of Action and Milestones (POA&M) process, maintaining communication with federal client stakeholders and federal client information security team members, establishing and performing NIST RMF and ATO related continuous monitoring strategies and solutions, managing NIST RMF and ATO related project plans, testing system technical security configuration settings and developing reports.

The successful candidate demonstrates subject matter expertise in security control, NIST RMF, and ATO related processes; leverages knowledge of Plan of Action and Milestones (POA&M) management and continuous monitoring objectives; provides guidance on system technical security configurations and solutions to meet ATO requirements; reviews various system scan results for compliance with industry standards, and assists with developing and reviewing compliance reports that clearly identify security findings and proposed remediation strategies. We offer generous medical, dental, and disability insurance benefits, flexible spending, 401(k), ample vacation/leave time, training/skills building opportunities and a great work environment.

Apply To:Certifications:Security+ certification is required. CISA, CASP, or CISSP preferred.Experience:5+ years related work experience. Federal ISSO Experience Required. DHS ISSO Experience Strongly Preferred.Clearance:Candidates must be US citizens who are clearable for a DHS EOD Suitability clearance and/or DoD Secret clearance, due to federal contract requirements.Related Experience Should Include:

* Strong understanding of federal information security related processes, frameworks, standards, and regulations.

* Strong security system analysis skills and understanding of Cyber and IT security risks, threats and prevention measures.

* Experience in documenting ATO related artifacts to include but not limited to System Security Plans (SSP), Ports, Protocols, Services; Remediation Consolidation Plans (RCP), Plan of Action and Milestones (POA&M), Information System Contingency Plan (ISCP), Incident Response Plan (IRP), Continuous Monitoring Strategies/Plans, Information System Vulnerability Management (ISVM), OIG formatted security control implementation statements, Risk Acceptance Letters, Waivers, Interconnection Security Agreements (ISA), Memorandum of Understanding (MOU), Memorandum of Agreement (MOA), Security Assessment Reports (SAR), etc.

* Experience in proposing and providing guidance in compliant technologies, architectures, and solutions.

* Experience in working with software and system engineers in an ISSO role.

* Experience with cloud security approaches and cloud architectures. Preferred experience with Azure and AWS to include understanding FedRAMP and Security Control Inheritance, developing Shared/Customer Responsibility Matrices.

* Experience with Federal Governance, Risk Management, and Compliance or ATO related tools and content is preferred such as: eMASS, Xacta/IACS, CSAM, Continuum, SCAP/STIG, USGCB, Nessus/Tenable, etc.

* Experience supporting customers in either Federal Government and/or other industry specific Cybersecurity Compliance and Regulatory standards/frameworks.

* Experience with a variety of cybersecurity compliance standards, policies, regulations and frameworks such as: NIST RMF, FISMA, NIST SP800-53r4, FedRAMP, NIST SP800-171r1, Cybersecurity Maturity Model Certification (CMMC), NIST CSF, FIPS, NIST SP800-60, PCI-DSS, HIPAA, SOC 2, ISO27001, DHS 4300A, other Federal agency specific policies and tailoring criteria.

* Knowledgeable of Cybersecurity/IA solutions/architectures such as PKI, VPN, Enterprise Firewalls, IPS, IDS, SCAP, STIG, Nessus, ACAS, SIEM, HIDS, NIDS, MFA, EDR, FIM, CMDB, Vulnerability Scanners, AV solutions, data at rest encryption solutions, data in transit encryption solutions, penetration testing tools, etc.

* In-depth understanding of networking and network security; cloud security, network monitoring solutions/approaches.

* Experience in writing and designing information security policies, procedures, standards, guides, plans, etc.

* Must be able to multi-task and support a cross-matrixed team efficiently by working through many client projects and support internal team functions.

* Must have ability to solve complex information security related challenges and propose strategic/pragmatic approaches to the team and clients.

Job Duties:

* Support a federal NIST RMF/ATO project for a system developed by Tiber Creek and hosted in a cloud environment/architecture.

* Generate and design a variety of documentation and navigating associated processes such as System Security Plans (SSP), Plan of Actions and Milestones (POA&M), Interconnection Security Agreements (ISA), Information System Vulnerability Management (ISVM), Continuous Monitoring Strategies, Security Operation Center (SOC) strategies, Information System Contingency Plans (ISCP), Incident Response Plans (IRP), Configuration Management Processes, etc.

* Support a variety of federal and commercial clients as a Information System Security Officer (ISSO), to include security and system architecture design and input.

* Support Incident Response (IR) actions and reporting.

* Write/develop security and risk reports and related documentation.

* Consult clients on various mitigation and remediation solutions/methods.

* Navigate and manage Federal ATO processes and POA&M remediation processes.

* Provide Subject Matter Expertise (SME) input to System Engineers, Project Managers, Software Engineers to implement compliant configurations and solutions, including methods to implement NIST RMF and ATO compliant strategies/solutions for a Cloud System (AWS/Azure) in development for federal clients being provided in a Software as a Service (SaaS) model.

* Perform enterprise-wide risk analysis and vulnerability assessments and management.

* Provide SME support for automating cybersecurity operations via technology solutions and strategies.

Physical Demands and Work Environment:

* Some local and long distance travel may be required.

* Usual office working conditions and standard office equipment. Required to sit for long periods of time using a personal computer. Some light physical effort required.

* Reasonable accommodations may be made to enable individuals with disabilities to perform the essential functions of this position.

* Full time remote/telework is an option and may be required during the current COVID-19 pandemic.

Minimum Qualifiers:

* Unable to work with 3rd party candidates or agencies.



  • Fairfax Station, United States Mission Essential Intelligence Solutions Full time

    Description: The Mission Essential Group, LLC (MEG), is a premier service provider of information management solutions for complex, mission-critical needs. MEG has earned a reputation as an innovator and pioneer. Headquartered in Fairfax, VA, MEG employs professionals in offices located throughout the United States and around the world. MEG offers a...


  • Fairfax, United States ECS Full time

    ECS is seeking an Information System Security Officer to work hybrid in our Fairfax, VA office. Please Note: This position is contingent upon contract award. Job Description: ECS is seeking talented professionals who love a challenge to join us in building the next-generation Continuous Diagnostics and Mitigation (CDM) Cyber data solution. The CDM Program...


  • Fairfax Station, Virginia, United States CGI Full time

    Information Systems Security Manager (ISSM) Category: Cyber Security Main location: United States, Virginia, Fairfax Position ID:J Employment Type: Full Time Position Description: This is an exciting full-time opportunity to work in a fast-paced environment with a team of passionate technologists. We take an innovative approach to supporting our...


  • Fairfax, United States ZTI Solutions, LLC Full time

    **About the Job** **US Citizen - Secret Clearance Required** - Information Systems Security Officer (ISS0) $120,000-195,000 - Fairfax, VA. **Summary**: **Certification and Accreditation Consultant Activities**: - Learn and understand the infrastructure to include security device configurations and Zone guidelines as outlined in DISA’s Enclave Test and...


  • Fairfax, United States Gemini Ind., Inc Full time

    POSITION DESCRIPTION Gemini Industries Inc. provides technical, management and operations services to support National Security projects. We provide rapid response to the critical needs of our customers and those they serve. We perform analyses and develop operations plans to anticipate and prepare for the future. And we deliver advanced technology to...


  • Fairfax, United States Azure Summit Technology Full time

    **Are you in?** Do you work well in a team environment and on your own as an individual contributor? Do you know how to set the bar high and achieve goals for yourself and bring others along with you? Do you work hard and play hard? Do you want to help the company succeed and build your skill set and further your career at the same time? Azure Summit...


  • Fairfax, United States Azure Summit Technology Full time

    **Are you in?** Do you work well in a team environment and on your own as an individual contributor? Do you know how to set the bar high and achieve goals for yourself and bring others along with you? Do you work hard and play hard? Do you want to help the company succeed and build your skill set and further your career at the same time? Azure Summit...


  • Fairfax, United States Tiber Creek Consulting Full time

    **Information System Security Officer (ISSO) / Information Assurance (IA) AnalystFairfax, VA / Telework** Tiber Creek Consulting, Inc. is seeking an experienced ISSO / IA Analyst to serve as an information security subject matter expert (SME) as part of a growing cybersecurity operations team in Fairfax VA / Telework. You will support federal agency ATO...


  • Fairfax, United States Tiber Creek Consulting Full time

    **Information System Security Officer (ISSO) / Information Assurance (IA) AnalystFairfax, VA / Telework** Tiber Creek Consulting, Inc. is seeking an experienced ISSO / IA Analyst to serve as an information security subject matter expert (SME) as part of a growing cybersecurity operations team in Fairfax VA / Telework. You will support federal agency ATO...


  • Fairfax Station, United States Redtracetech Full time

    **RedTrace Technologies Inc** **Information Systems Security Officer - ISSO (TS required, eligible for SCI)** **Fairfax, VA - Full Time** Apply: Information Systems Security Officer - ISSO (TS required, eligible for SCI) * Required fields First name* Last name* Email address* Location Phone number* Resume* or Attach resume as .pdf, .doc, .docx, .odt, .txt,...


  • Fairfax, United States Virginia Jobs Full time

    Title: College Information Security Officer Agency: Northern VA Community College Location: Fairfax County - 059 FLSA: Exempt Hiring Range: Commensurate with Experience (up to $175,000 max) Full Time or Part Time: Full Time Additional Detail Job Description: General Description: The College Information Security Officer (ISO) is responsible for the...


  • Fairfax, United States Mission Essential Full time

    You will need to login before you can apply for a job. Information Systems Security Engineer with Security Clearance DESCRIPTION Position Description: The Mission Essential Group, LLC (MEG) is a premier service provider of information management solutions for complex, mission–critical needs. MEG has earned a reputation as an innovator and pioneer....


  • Fairfax, United States Security Assurance Management Full time

    Job DescriptionJob DescriptionDCJS Registered OnlyWe are currently hiring for unarmed Security in Fairfax, VA Must have a Current DCJS Security Officer LicenseMinimum 2 years of Security Officer ExperienceMust be a Self-Motivator with Good work EthicsMust be able to work with minimal supervisionMust be able to work any scheduleAbility to effectively...


  • Fairfax, United States Security Assurance Management Full time

    Job DescriptionJob DescriptionDCJS Registered OnlyWe are currently hiring for unarmed Security in Fairfax, VA Must have a Current DCJS Security Officer LicenseMinimum 2 years of Security Officer ExperienceMust be a Self-Motivator with Good work EthicsMust be able to work with minimal supervisionMust be able to work any scheduleAbility to effectively...


  • Fairfax Station, United States Addison Group Full time

    Position: Computer and Information Systems Administrator Location: Fairfax, VA - Fully Onsite 5 Days A Week Are you looking for a growth opportunity for a reputable company with a positive work environment? Our client is looking for a Computer and Information Systems Administrator to join their team. Please contact us today to discuss this opportunity! ...


  • Fairfax Station, United States Tevora Full time

    Information Security Associate at Tevora Irvine, CA If you haven't heard of Tevora, it's because we've done our job! Tevora is a tight-knit community of professionals with a shared passion for our craft. Every day, we combine in-depth knowledge of cybersecurity, technology, and compliance to help create more secure digital environments. To Tevorans, every...


  • Fairfax, United States CGI Group, Inc. Full time

    Information Systems Security Manager (ISSM) Position Description This is an exciting full-time opportunity to work in a fast-paced environment with a team of passionate technologists. We take an innovative approach to supporting our client, working side-by-side in an agile environment using emerging technologies. As a solution builder, you will be working...


  • Fairfax, United States TEEL Construction, Inc Full time

    **OVERALL RESPONSIBILITIES**: The Computer and Information Systems (CIS) Manager will plan, coordinate, and direct computer-related activities by determining the technology needs of the company and making hardware - and software-related decisions to meet those needs. SUPERVISORY RESPONSIBILITIES - Coordinates and monitors the company MSP - Prioritizes and...


  • College Station, United States Transportation Security Administration Full time

    Summary Transportation Security Officers are responsible for providing security and protection of travelers across all transportation sectors in a courteous and professional manner. Their duties may also extend to securing high-profile events, important figures and/or anything that includes or impacts our transportation systems. Learn more about the...


  • Fairfax, United States Arcetyp LLC Full time

    Job Description Job Description Salary: Arcetyp LLC is a growing small business that provides a broad range of consulting services to US Federal Government, US Military, and Commercial clients. Services include Management & IT Consulting, Program & Project Management, and Professional & Admin Services. We are recruiting to fill a position to lead business...