Dynsoltech logo

Information Systems Security Officer (ISSO)

Dynsoltech
Posted 4 hours ago
United StatesHybridEngineering & Development
Is this job info correct?

Dynamic Solutions Technology, LLC, a premier strategic services firm that meets IT and Service needs for commercial and government clients, is seeking a full-time Information Systems Security Officer (ISSO) to support the government customer located in Washington, DC. This is an exempt hybrid remote position. (A minimum of TWO days per week reporting to site; additional support as needed on a case-by-case basis)

MUST BE A U.S. CITIZEN

Responsibilities:

  • Support the implementation, maintenance, and continuous improvement of the Risk Management Framework (RMF) for assigned Federal information systems.
  • Develop, review, update, and maintain RMF and authorization artifacts, including System Security Plans (SSPs), Security Assessment Reports (SARs), POA&Ms, control narratives, risk assessments, and supporting evidence.
  • Assist with system categorization, security control implementation, control assessments, authorization activities, and preparation of ATO documentation.
  • Support Continuous Monitoring (ConMon), vulnerability management, configuration reviews, security assessments, audits, inspections, and cybersecurity remediation activities.
  • Monitor system security posture and analyze security, vulnerability, configuration, and compliance data to identify deficiencies and recommend corrective actions.
  • Maintain and track POA&M items, risks, vulnerabilities, findings, and security issues; coordinate remediation activities and escalate overdue or high-risk issues.
  • Coordinate with System Owners, common-control providers, system administrators, cloud-service personnel, and other cybersecurity stakeholders to obtain evidence and resolve security deficiencies.
  • Conduct quality-control reviews of RMF deliverables and security documentation to ensure accuracy, completeness, consistency, and compliance with applicable Federal cybersecurity requirements.
  • Participate in technical reviews, cybersecurity working groups, governance meetings, and incident-response coordination activities, providing technical input and status updates.
  • Maintain working proficiency with applicable cybersecurity tools and platforms, including CSAM, ServiceNow, Splunk, Tenable/Nessus, Qualys, Microsoft Defender, Intune, BigFix, Azure, Microsoft 365, Entra ID, Okta, Palo Alto Panorama, and Zscaler, as required by the task order.
Education, Certifications, and Experience:
  • Bachelor's-level technical education and a cybersecurity certification meeting the applicable contract and Federal qualification requirements are required.
  • Security+ or an equivalent certification meeting applicable DoD 8140/8570 requirements is required, with higher-level certifications such as CISSP, CAP, CISM, CASP+, CCSP, or GIAC certifications preferred based on assigned duties.
  • Minimum of 6 years of progressively responsible experience in information systems security, cybersecurity, information assurance, or a related discipline
  • Minimum of 5 years of hands-on experience supporting the Risk Management Framework (RMF), including security control implementation, assessment, authorization, continuous monitoring, POA&M management, and security documentation.
  • Demonstrated experience developing, reviewing, maintaining, and submitting System Security Plans (SSPs), Security Assessment Reports (SARs), Plans of Action and Milestones (POA&Ms), risk assessments, security control documentation, and other authorization-package artifacts.
  • Experience leading Continuous Monitoring (ConMon), vulnerability management, security assessments, audits, inspections, and cybersecurity remediation activities.
  • Experience with Federal cybersecurity standards and frameworks, including NIST SP 800-53, NIST RMF, FISMA, and applicable Federal and DoD cybersecurity policies.
  • Working knowledge of enterprise cybersecurity technologies and platforms, including CSAM, Splunk, ServiceNow, Tenable/Nessus or Qualys, Microsoft Defender, Microsoft Intune, BigFix, Microsoft Azure, Microsoft 365, Microsoft Entra ID, Okta, Palo Alto Panorama, and Zscaler, with specific tools subject to task-order requirements.

Similar jobs