×
Register Here to Apply for Jobs or Post Jobs. X

Mid-Level Information Systems Security Officer; ISSO​/Control Evaluator

Job in Washington, District of Columbia, 20022, USA
Listing for: Koniag Services, Inc.
Full Time position
Listed on 2026-07-18
Job specializations:
  • IT/Tech
    Cybersecurity, Information Security & Data Protection
Salary/Wage Range or Industry Benchmark: 90000 - 130000 USD Yearly USD 90000.00 130000.00 YEAR
Job Description & How to Apply Below
Position: Mid-Level Information Systems Security Officer (ISSO) / Control Evaluator

Mid-Level Information Systems Security Officer (ISSO) / Control Evaluator

Washington, DC, USA

Job Description

Koniag Data Solutions, LLC, a Koniag Government Services company, is seeking a Mid-Level Information Systems Security Officer (ISSO) / Control Evaluator to support KDS and our government customer in Washington, DC. This position requires the candidate to be able to obtain a Public Trust.

Koniag Data Solutions, LLC, a Koniag Government Services company, offers competitive compensation and an extraordinary benefits package including health, dental and vision insurance, 401K with company matching, flexible spending accounts, paid holidays, three weeks paid time off, and more.

Koniag Data Solutions, a Koniag Government Services company, is seeking a skilled Mid-Level Information Systems Security Officer (ISSO) / Control Evaluator to support the U.S. Small Business Administration (SBA). The ideal candidate is an experienced information security professional with a solid foundation in federal information security requirements, security control assessment, and the NIST Risk Management Framework (RMF). This individual will work closely with SBA system owners, the security authorization team, and senior cybersecurity staff to support the security authorization and continuous monitoring of SBA's information systems, ensuring compliance with applicable federal cybersecurity laws, regulations, and standards.

The Mid-Level ISSO/Control Evaluator will support the security authorization and continuous monitoring of SBA's information systems, performing security control assessments, maintaining security authorization documentation, and providing day-to-day information security support to system owners and program teams.

Principal responsibilities will include but are not limited to:
  • Serve as the Information Systems Security Officer (ISSO) for assigned SBA information systems, providing day-to-day information security support, guidance, and oversight to system owners, program teams, and IT staff responsible for the operation and maintenance of those systems.
  • Support the full NIST Risk Management Framework (RMF) lifecycle for assigned systems, including security categorization, security control selection and tailoring, security control implementation review, security control assessment, security authorization package development, and continuous monitoring activities.
  • Develop, maintain, and update security authorization documentation for assigned systems, including System Security Plans (SSPs), Security Assessment Reports (SARs), Plans of Action and Milestones (POA&Ms), Risk Assessment Reports (RARs), and other ATO package artifacts in accordance with NIST SP 800-53, NIST SP 800-53A, and SBA security requirements.
  • Conduct security control assessments and evaluations for assigned systems, applying NIST SP 800-53A assessment procedures to evaluate the design, implementation, and operational effectiveness of security controls, and documenting findings and recommendations in Security Assessment Reports (SARs).
  • Support the development and maintenance of POA&M items for assigned systems, tracking identified security weaknesses, compliance deficiencies, and audit findings, coordinating with system owners and IT teams on remediation activities, and updating POA&M status on a regular basis.
  • Perform continuous monitoring activities for assigned systems, including the review and analysis of security control assessment results, vulnerability scan findings, configuration compliance results, and other security-relevant data to assess the ongoing security posture of assigned systems.
  • Review and analyze vulnerability scan results from tools such as Nessus, Tenable.io, or equivalent platforms for assigned systems, assessing the severity and exploitability of identified vulnerabilities, coordinating remediation activities with system owners, and tracking remediation progress.
  • Support the preparation and submission of security authorization packages to the Authorizing Official (AO) and Authorizing Official Designated Representative (AODR), ensuring all required documentation is complete, accurate, and meets SBA and federal standards.
  • Collaborate with system owners, developers, and IT operations teams to ensure security requirements are implemented and maintained throughout the system lifecycle, providing technical guidance on the implementation of NIST SP 800-53 security controls.
  • Review and assess proposed system changes, configuration changes, and new technology deployments for assigned systems, evaluating potential security impacts and documenting findings and recommendations in accordance with SBA's change management and configuration management processes.
  • Support incident response activities for assigned systems, coordinating with the SOC and incident response team to ensure timely reporting, documentation, and resolution of security incidents affecting assigned systems.
  • Develop and maintain system-level security documentation beyond the core ATO…
To View & Apply for jobs on this site that accept applications from your location or country, tap the button below to make a Search.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
 
 
 
Search for further Jobs Here:
(Try combinations for better Results! Or enter less keywords for broader Results)
Location
Increase/decrease your Search Radius (miles)
0
200
Filters
Education Level
Experience Level (years)
Posted in last:
Salary