Information System Security Officer / ISSO
Core
Perform Certification & Accreditation (C&A) and System Assessment & Authorization (SA&A) within the NIST RMF to ensure federal compliance and maintain Authorization to Operate (ATO) for assigned information systems.
Role type
Information System Security Officer (ISSO)
Builds
Security authorizations and compliance documentation for federal information systems
Domain
US Federal Government / Cybersecurity
Deliverable
client delivery
Required skills
NIST SP 800-37 Risk Management Framework, Vulnerability scanning (Nessus, Foundstone, WebInspect, Hailstorm), Configuration management, Security control compliance evaluation, Audit trail management, GRC tool documentation, System lifecycle security requirements
Preferred skills
Active Public Trust clearance, US Federal Government project experience
Technologies
Nessus, Foundstone, WebInspect, Hailstorm, GRC tools
Responsibilities
Prepare C&A and SA&A documentation, coordinate and conduct vulnerability scans, manage emerging risks, coordinate with Cybersecurity Units for ATO, perform annual compliance assessments, serve on Configuration Control Board, establish audit trails, develop Standard Operating Procedures, analyze scan results for leadership
Seniority
Mid-level, hands-on IC