×
Register Here to Apply for Jobs or Post Jobs. X

Information Systems Security Officer; ISSO

Job in Charlotte, Mecklenburg County, North Carolina, 28245, USA
Listing for: Contact-Government-Services,-LL
Full Time position
Listed on 2026-06-26
Job specializations:
  • IT/Tech
    Cybersecurity, Information Security, IT Consultant
Salary/Wage Range or Industry Benchmark: 92213 - 125146 USD Yearly USD 92213.00 125146.00 YEAR
Job Description & How to Apply Below
Position: Information Systems Security Officer (ISSO)

ISSO

Employment Type:

Full-Time, Experienced

Department:
Information Technology

CGS is seeking an Information Systems Security Officer (ISSO) with DIACAP and/or RMF experience who has deep expertise in security assessment documentation to support Dept. of Commerce systems and efforts to achieve their Authorization to Operate (ATO). This position is located at the client site in the Herbert Hoover building in Washington, DC. The scope of this position includes full life‑cycle Assessment and Authorization (A&A) management through all 6 Steps of the RMF process in support of the Government ISSM.

This role involves conducting security assessment and information system security oversight activities in accordance with NIST 800‑53 that support systems from the perspective of RMF requirements.

Responsibilities
  • Review systems to identify potential security weaknesses and recommend improvements to amend vulnerabilities, implement changes, and document upgrades.
  • Maintain responsibility for managing cybersecurity risk from an organizational perspective.
  • Identify organizational risks, prioritize those risks, and maintain a risk registry for escalating and presenting those risks to senior leadership.
  • Provide security guidance and IS validation using the National Institute of Standards and Technology (NIST) RMF, DoC, and local security policies.
  • Provide configuration management (CM) recommendations for information system security software, hardware, and firmware and coordinate changes and modifications with the ISSM, Security Control Assessor (SCA), and Authorizing Official (AO).
  • Maintain vulnerability scanning tool compliance, such as HBSS or ACAS, and patch management, such as IAVM to ensure IT staff pushes patches to all systems in an effort to maintain compliance with all applicable directives, manage system changes, and assess the security impact of those changes.
  • Support security authorization activities, including transitioning from the legacy Information Assurance Certification and Accreditation Process (DIACAP) to compliance with the DoC RMF.
  • Provide subject matter expertise for cyber security and trusted system technology.
  • Apply advanced technical knowledge and analysis of specialized functional areas in task requirements to develop solutions to complex problems.
  • Research, write, review, disposition feedback, and finalize recommendations regarding cyber security policy, assessment and authorization assessments (A&A), security test and evaluation reports, and security engineering practices and processes.
  • Conduct research and write risk assessment reports to include risk thresholds, evaluation, and scoring.
  • Support analysis of the findings and provide expert technical guidance for mitigation strategies, including implementation advice on the cyber security risk findings, and other complex problems.
Skills and Attributes for Success
  • Review systems to identify potential security weaknesses and recommend improvements to amend vulnerabilities, implement changes, and document upgrades.
  • Maintain responsibility for managing cybersecurity risk from an organizational perspective.
  • Identify organizational risks, prioritize those risks, and maintain a risk registry for escalating and presenting those risks to senior leadership.
  • Provide security guidance and IS validation using the National Institute of Standards and Technology (NIST) RMF, DoC, and local security policies.
  • Provide configuration management (CM) recommendations for information system security software, hardware, and firmware and coordinate changes and modifications with the ISSM, Security Control Assessor (SCA), and Authorizing Official (AO).
  • Maintain vulnerability scanning tool compliance, such as HBSS or ACAS, and patch management, such as IAVM to ensure IT staff pushes patches to all systems in an effort to maintain compliance with all applicable directives, manage system changes, and assess the security impact of those changes.
  • Support security authorization activities, including transitioning from the legacy Information Assurance Certification and Accreditation Process (DIACAP) to compliance with the DoC RMF.
  • Provide subject matter expertise for cyber security and…
To View & Apply for jobs on this site that accept applications from your location or country, tap the button below to make a Search.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
 
 
 
Search for further Jobs Here:
(Try combinations for better Results! Or enter less keywords for broader Results)
Location
Increase/decrease your Search Radius (miles)
0
200
Filters
Education Level
Experience Level (years)
Posted in last:
Salary