Information Systems Security Officer & Information Systems Security Engineer – Isso/Isse
Company | Expression Networks |
---|---|
Location | Washington, DC, USA |
Salary | $Not Provided – $Not Provided |
Type | Full-Time |
Degrees | Bachelor’s |
Experience Level | Senior |
Requirements
- Active Secret clearance
- Minimum 5 years of experience in FISMA compliance and NIST RMF
- DoD 8570 IAT Level II or IAM Level I certification (e.g., CompTIA Security+)
- Experience in cloud environments such as AWS & Azure
Responsibilities
- Ensure compliance with NSS security standards and proper handling of classified and Controlled Unclassified Information (CUI)
- Enforce FedRAMP High, IL6, and Zero Trust Architecture requirements
- Develop, maintain, and update: System Security Plan (SSP), Disaster Recovery Plan (DRP) / Information System Contingency Plan (ISCP), Security Assessment Report (SAR) & Risk Assessment, Plan of Action and Milestones (POA&M), Continuous Monitoring Plan, Incident Response/Contingency Plans, Installation and Configuration Guides
- Support and maintain Authority to Operate (ATO) via the NIST Risk Management Framework (RMF)
- Implement end-to-end encryption and access controls for data at rest and in transit
- Audit and secure enriched data, geospatial data, and sensitive spectrum data
- Collaborate with Cybersecurity Engineers to enforce secure infrastructure and dashboard access
- Ensure all team members complete cybersecurity training; submit proof to Contracting Officer’s Representative (COR)
- Monitor infrastructure to maintain 99.9% uptime (excluding maintenance)
- Produce monthly system monitoring and performance reports, including root-cause analysis for downtime
- Maintain a real-time, browser-based System Health Dashboard accessible to stakeholders
- Utilize Security Information Event Management (SIEM) and Software Security Tools to identify, report and remediate security vulnerabilities.
Preferred Qualifications
- Bachelor’s degree in Computer Science, IT, or a related field
- DoD 8570 IAT/IAM Level III certification (e.g., CISSP)
- Additional certifications: CEH, GIAC
- Experience using Xacta 360