Information Systems Security Officer (ISSO) (GC-2)
$160,000–$180,000 year
On-siteAnnapolis Junction, Maryland, United States
Job Summary
Implement and enforce information assurance policies, standards, and procedures throughout the system lifecycle to support the Risk Management Framework (RMF) authorization process for classified environments. Maintain day-to-day operational security for approximately 10–15 System Security Plans by preparing, reviewing, and maintaining documentation including Risk Assessment Reports, A&A packages, and System Requirements Traceability Matrices. Coordinate with system owners and cybersecurity teams to ensure security controls are implemented, documented, and maintained in accordance with regulatory requirements while evaluating security solutions and supporting configuration management activities. Legato, LLC is a small business headquartered in Columbia, MD, offering positions in Cyber, Software, and Systems engineering with aggressive compensation and upward mobility.
Required Qualifications
- Security Clearance Required: TS/SCI w/ Polygraph
- Ten (10) years of experience as an Information Systems Security Officer (ISSO) supporting programs or contracts of similar scope, type, and complexity
- Experience supporting the National Institute of Standards and Technology (NIST) Risk Management Framework (RMF) and security authorization processes
- Experience preparing and maintaining System Security Plans (SSPs), Risk Assessment Reports (RARs), Assessment and Authorization (A&A) packages, and System Requirements Traceability Matrices (SRTMs)
- Experience performing vulnerability assessments, risk analysis, continuous monitoring activities, and configuration management of security-related hardware, software, and firmware
- Experience evaluating the security impact of system changes and maintaining compliance with information assurance policies, standards, and procedures
- Experience supporting the day-to-day security operations of multiple information systems, typically managing a portfolio of approximately 10–15 System Security Plans (SSPs)
- Strong written and verbal communication skills with the ability to collaborate effectively with system owners, engineers, cybersecurity professionals, and government stakeholders
- Bachelor's degree in Computer Science or a related technical discipline from an accredited college or university
- Four (4) additional years of ISSO experience may be substituted for a bachelor's degree
- Current IAT Level II certification or higher
Desired Qualifications
- Experience with eMASS, Xacta, or similar RMF management tools
- Experience supporting classified systems
- Knowledge of Security Technical Implementation Guides (STIGs), Security Content Automation Protocol (SCAP), and vulnerability scanning tools such as ACAS, Nessus, or Tenable Security Center
- Knowledge of current security tools, hardware and software security implementation, communication protocols, and encryption technologies
- Experience supporting security control assessments, audits, and continuous monitoring activities
Hiring someone like this?
Get your role in front of qualified candidates on Sorce.