Performs ISSO duties under the guidance of the Information System Security Manager (ISSM) on assigned government-authorized systems. Knowledgeable in information technology and security. Responsibilities include: authoring and maintaining documentation supporting the Assessment & Authorization (A&A) of assigned systems in accordance with the Risk Management Framework (RMF) under the DAAG (Formerly DAAPM) and NISPOM; performing security control assessments as part of the systems’ Continuous Monitoring Plan; overseeing configuration management of assigned systems; works with IT organization to develop device and system hardening guides following DISA and NIST guidelines; auditing systems to ensure security posture integrity; conducting periodic hardware/software inventory assessments; identifying system security controls shortcomings and developing POA&Ms; remediate control deficiencies; conducts, documents and reports annual self-assessments; maintaining operational information security posture for a system, program, or enclave; investigating security incidents such as data spills, data integrity, and malicious events; authoring and delivering security education training to range of audience levels.
Stand Out From the Crowd
Upload your resume and get instant feedback on how well it matches this job.
Job Type
Full-time
Career Level
Mid Level