Information Systems Security Officer; ISSO
Listed on 2026-05-31
-
IT/Tech
Cybersecurity, Information Security
Employment Type:
Full‑Time
Department:
Information Technology
Location:
Herbert Hoover Building, Washington, DC.
CGS is seeking an Information Systems Security Officer (ISSO) with DIACAP and/or RMF experience to support Department of Commerce systems and help achieve Authorization to Operate (ATO). This role manages the full life‑cycle Assessment and Authorization (A&A) through all six steps of the RMF process in collaboration with the Government ISSM. The position involves security assessment, oversight, and documentation based on NIST 800‑53.
Responsibilities- Conduct security assessments and provide information system security oversight in accordance with NIST 800‑53 and RMF requirements.
- Review systems to identify potential security weaknesses and recommend improvements.
- Maintain responsibility for managing cybersecurity risk from an organizational perspective, identifying, prioritizing, and maintaining a risk registry for senior leadership.
- Provide security guidance and validation using NIST RMF, DoC, and local security policies.
- Recommend configuration management (CM) for system software, hardware, firmware, and coordinate changes with ISSM, Security Control Assessor (SCA), and Authorizing Official (AO).
- Ensure compliance of vulnerability scanning tools (HBSS or ACAS) and patch management (IAVM), and push patches to all systems to meet directives and assess security impact.
- Support security authorization activities, including transitioning from DIACAP to DoC RMF compliance.
- Provide subject matter expertise for cyber security and trusted system technology.
- Apply advanced technical knowledge and analysis in specialized functional areas to develop solutions for complex problems.
- Research, write, review, and finalize recommendations for cyber security policy, assessment and authorization assessments (A&A), security test and evaluation reports, and security engineering practices.
- Conduct risk assessment reports including risk thresholds, evaluation, and scoring.
- Support analysis of findings and provide expert technical guidance for mitigation strategies and implementations.
- Bachelor’s Degree.
- Minimum of five (5) years experience as an IA Analyst, ISSE, ISSO, or similar role in ATO package development, including generating security documentation for requirements, security control assessment, STIG and IAVA compliance, SOPs, test results, etc.
- eMASS experience.
- Professional security certification such as CCNA Security, CySA+, GICSP, GSEC, CompTIA Security+ CE, SSCP, or higher.
- Strong desktop publishing skills using Microsoft Word and Excel.
- Experience with industry writing styles (grammar, sentence form, structure).
- Ability to multi‑task in a deadline‑oriented environment.
- CISSP, CASP, or similar certificate.
- Master’s Degree in Cybersecurity or related field.
- Strong initiative, detail orientation, organizational skills, and aptitude for analytical thinking.
- Demonstrated ability to work well independently and as part of a team.
- Excellent work ethic and high commitment to quality.
Contact Government Services, LLC is an Equal Opportunity Employer. Applicants will be considered without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability, or status as a protected veteran.
#J-18808-Ljbffr(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).