ISSO II
$96,000–$105,000 year
HybridArlington, Virginia, United States
Job Summary
Proactively create, monitor, and update Plan of Action and Milestones (POA&Ms) to ensure security weaknesses are resolved on schedule. Develop Waivers or Risk Acceptance Memos to manage system risks and conduct annual assessments per the DHS Information Security Performance Plan. Review security authorization documents, perform system self-assessments, and test contingency plans at least annually. Monitor Information Security Vulnerability Management and patch management, while providing audit support for Financial, A-123, FISMA, and DHS systems throughout pre, during, and post phases. Ensure security requirements are integrated into development cycles for Waterfall, Agile, and DevOps environments, and coordinate with Privacy, Records, and Information Governance Divisions for compliance documentation.
Required Qualifications
- DHS Public Trust EOD
- US Citizen
- Applies extensive knowledge of a variety of the IA field's concepts, practices, and procedures to ensure the secure integration and operation of all systems
- Extensive specialized knowledge of financial audit standards, classified system IA requirements and Privacy Act requirements
- Specialized knowledge and experience with the implementation of the NIST Special Publication (SP) 800 family of publications, particularly those associated with the Risk Management Framework
- Specialized knowledge and experience with evaluating system, network, or infrastructure security controls against requirements such as FISMA, FIPS, and NIST guidelines
- Knowledge and experience with the vulnerability scanning execution, assessment, and analysis
- Knowledge and experience with the operating system and network knowledge (i.e., Local Area Networks [LAN] and Wide Area Networks [WAN])
- Knowledge and experience with application security, database security, and network security
- Knowledge and experience with the information security and assurance principles (e.g., Defense-in-depth) and associated supporting technologies
- Ability to assess and weigh current and evolving security threats in an operational environment
- Experience leading a team of ISSOs
- No degree and (9) years overall experience which (7) years must be Cybersecurity/FISMA-related
- Bachelor's Degree and (5) years of cybersecurity/FISMA-related experience
- Master's Degree and 6 years of Cybersecurity/FISMA-related experience
- Certified Information Systems Security Professional (CISSP)
- CompTIA Advanced Security Practitioner (CASP)
- Certified Information Systems Auditor (CISA)
- Certified Ethical Hacker (CEH)
- Certified Information Security Manager (CISM)
- Systems Security Certified Practitioner (SSCP)
- GIAC Security Leadership Certification (GSLC)
Desired Qualifications
- Current experience providing ISSO support to DHS
- Experience supporting systems hosted in Cloud environments
- Experience supporting systems in Agile and DevOps environments
Hiring someone like this?
Get your role in front of qualified candidates on Sorce.