CGS Federal (Contact Government Services) · 4 months ago
Information Systems Security Officer (ISSO)
CGS Federal is seeking an Information Systems Security Officer (ISSO) to support the Department of Commerce systems and achieve their Authorization to Operate (ATO). The role involves conducting security assessments and managing cybersecurity risks while ensuring compliance with NIST standards.
ConsultingInformation TechnologyLegalProfessional ServicesProject ManagementSoftware
Responsibilities
Review systems to identify potential security weaknesses and recommend improvements to amend vulnerabilities, implement changes, and document upgrades
Maintain responsibility for managing cybersecurity risk from an organizational perspective
Identify organizational risks, prioritize those risks, and maintain a risk registry for escalating and presenting those risks to senior leadership
Provide security guidance and IS validation using the National Institute of Standards and Technology (NIST) RMF, DoC, and local security policies
Providing configuration management (CM) recommendations for information system security software, hardware, and firmware and coordinating changes and modifications with the ISSM, Security Control Assessor (SCA), and Authorizing Official (AO)
Maintain vulnerability scanning tool compliance, such as HBSS or ACAS, and patch management, such as IAVM to ensure IT staff pushes patches to all systems in an effort to maintain compliance with all applicable directives, manage system changes, and assess the security impact of those changes
Support security authorization activities, including transitioning from the legacy Information Assurance Certification and Accreditation Process (DIACAP) to compliance with the DoC RMF
Provide subject matter expertise for cyber security and trusted system technology
Apply advanced technical knowledge and analysis of specialized functional areas in task requirements to develop solutions to complex problems
Research, write, review, disposition feedback, and finalize recommendations regarding cyber security policy, assessment and authorization assessments (A&As), security test and evaluation reports, and security engineering practices and processes
Conduct research and write risk assessment reports to include risk thresholds, evaluation, and scoring
Support analysis of the findings and provide expert technical guidance for mitigation strategies, including implementation advice on the cyber security risk findings, and other complex problems
Qualification
Required
Bachelor's Degree
A minimum of five (5) years experience as an Information Assurance (IA) Analyst, ISSE, ISSO, or similar role in ATO package development, including generating security documentation for requirements, security control assessment, STIG and IAVA compliance, Standard Operating Procedures, test results, etc
eMASS experience
Professional security certification such as: CCNA Security, CySA+, GICSP, GSEC, CompTIA Security+ CE, SSCP, or higher
Strong desktop publishing skills using Microsoft Word and Excel
Experience with industry writing styles such as grammar, sentence form, and structure
Ability to multi-task in a deadline-oriented environment
Preferred
CISSP, CASP, or a similar certificate is preferred
Master's Degree in Cybersecurity or related field
Strong initiative, detail orientation, organizational skills, and aptitude for analytical thinking
Demonstrated ability to work well independently and as a part of a team
Excellent work ethic and a high commitment to quality
Benefits
Health, Dental, and Vision
Life Insurance
401k
Flexible Spending Account (Health, Dependent Care, and Commuter)
Paid Time Off and Observance of State/Federal Holidays
Company
CGS Federal (Contact Government Services)
Contact Government Services strives to simplify and enhance government bureaucracy through the optimization of human, technical, and financial resources.