Information Technology Strategies, Inc. is a government IT solutions provider servicing commercial and government initiative in various parts of the United States. We are currently seeking a Information System Security Officer to work for our company. Summary: Client Agency is the Department of commerce Ensure security policies and procedures are implemented. Identifying corrective actions/mitigation strategies to achieve/sustain RMF compliance. Review of virus detection software to ensure compliance. Review and analyze system implementation plans. Advising system owners and stakeholders on new deployments and advanced cyber security techniquesDesign, implement, and maintain secure cloud architectures within Azure Government Secret classified environments. Enforce zero trust principles, role-based access control (RBAC), and identity federation (e.g.,Azure AD B2B/B2C with CAC/PIV). Configure and manage security controls such as Microsoft Defender for Cloud, Key Vault, Azure Policy, NSGs, and Private Endpoints. Automate compliance and security operations using PowerShell, Terraform, or ARM templates. Integrate SIEM/SOAR tools (e.g., Microsoft Sentinel for IL6) for continuous monitoring, logging, and incident response. Conduct vulnerability assessments and implement remediations aligned to NIST 800-53, DoD STIGs, and JSIG. Collaborate with mission owners, compliance teams, and developers to ensure secure DevSecOps pipelines. Support Authority to Operate (ATO) processes by generating security documentation, control evidence, and supporting audits. Navigate federal systems through the authorization process to achieve and maintain Authority to Operate (ATO). Work with the ISSO, Program and DOC ITD IA teams to maintain the necessary security authorizations. Develop comprehensive System Security Plans (SSPs) documenting all implemented NIST 800-53 controls. Coordinate security assessments with third-party assessors. Manage Plans of Actions & Milestones (POA&Ms) for addressing identified vulnerabilities. Ensure continuous monitoring plans meet agency requirements. Prepare authorization packages for government review. Maintain ongoing compliance through change management processes. Serve as the liaison between technical teams and authorizing officials. Translate security requirements into actionable tasks. Ensure all documentation meets the rigorous standards required for federal information systems.
Stand Out From the Crowd
Upload your resume and get instant feedback on how well it matches this job.
Job Type
Full-time
Career Level
Mid Level
Education Level
No Education Listed
Number of Employees
11-50 employees