This role serves in an Information System Security Officer (ISSO)-type capacity, supporting the system’s cybersecurity posture throughout development, deployment, operations, and sustainment. The position involves performing continuous monitoring activities in accordance with RMF and program requirements, including reviewing security logs, audit records, alerts, vulnerability results, configuration changes, and security-relevant events. The ISSO will analyze security events and log data to identify anomalous activity, potential indicators of compromise, control deficiencies, and compliance concerns, coordinating escalation and response activities as appropriate. This role requires working with system development, deployment, and operations teams to implement and maintain secure system architectures, designs, configurations, and operational procedures, while championing the cybersecurity perspective in decisions related to security controls. The position supports the development, maintenance, and execution of Continuous Monitoring (ConMon) plans, including recurring security control assessments, evidence collection, status reporting, and risk tracking. The ISSO will produce and maintain cybersecurity design documentation, system security documentation, security operating procedures, and other artifacts supporting authorization and ongoing system security, as well as the Security Control Traceability Matrix (SCTM), inheritable control sets, and control implementation statements. The role also involves leading or supporting NIST SP 800-37 Risk Management Framework (RMF) activities, coordinating with various teams to plan, implement, assess, and document security requirements and controls, and tracking security findings, vulnerabilities, control deficiencies, and remediation activities. Additionally, the ISSO will review and map evidence from applicable security requirement sources within the SCTM and RMF evidence package, support system accreditation/certification evaluation and test activities, participate actively in Agile teams, contribute to incident-response preparedness, and plan and execute project tasks supporting cybersecurity, ISSO, RMF, and continuous-monitoring activities.
Stand Out From the Crowd
Upload your resume and get instant feedback on how well it matches this job.
Job Type
Full-time
Career Level
Mid Level