Information Security Officer (ISSO)
Core
Develop, implement, and maintain security policies, procedures, and protocols to ensure compliance with federal, state, and local regulations and cybersecurity frameworks.
Role type
Senior Information Security Officer (ISSO)
Builds
Security policies, compliance documentation, incident response plans, and security awareness training programs
Domain
Defense/Contracting, Information Security, Compliance
Deliverable
production ML models | product features | dashboards & analysis | research | client delivery | infrastructure | physical/clinical work
Required skills
Risk management, security controls implementation, vulnerability management, incident handling, compliance process management, security policy development, audit coordination, forensic investigation, security awareness training design, security tool management, regulatory reporting
Preferred skills
CISSP, CISM, GSLC, CEH, CompTIA Security+, SecurityX (CASP+)
Technologies
Firewalls, intrusion detection systems, antivirus software, vulnerability management platforms, endpoint protection, security monitoring tools, access control systems
Responsibilities
Develop and maintain security policies, procedures, and protocols; Conduct regular audits and assessments to verify adherence to security policies; Identify, assess, document, and prioritize information security risks; Build, apply, and monitor risk mitigation measures and security controls; Coordinate vulnerability assessments, security reviews, and penetration testing; Develop and maintain an incident response plan; Coordinate and manage security incidents and breaches; Perform forensic investigations and root cause analysis; Design, coordinate, and deliver security awareness and training programs; Monitor information systems for security incidents and vulnerabilities; Implement and manage security tools and technologies; Ensure systems are patched and updated on a regular basis; Work with cross-functional teams to integrate security requirements and controls; Serve as the primary point of contact for information security matters; Prepare and present regular security status updates, risk assessments, and incident reports to leadership; Develop, maintain, and continuously improve security documentation; Coordinate the preparation and submission of required security documentation and reports to auditors and regulatory agencies; Maintain detailed records of assessments, audits, authorizations, findings, and remediation efforts; Track corrective actions to ensure timely resolution of vulnerabilities and compliance gaps; Support internal and external audits by providing evidence, documentation, and subject matter expertise