Senior Information Systems Security Officer
Listed on 2026-08-22
-
IT/Tech
Cybersecurity, Information Security & Data Protection, Security Management & Operations
Senior Information Systems Security Officer
Dexian Government Solutions is recruiting for a Senior Information Systems Security Officer to support our proposal effort for the DHS CIETS in DC Metro area.
Position OverviewServes as DHS I&A's senior offensive security and technical assessment specialist. This position is responsible for identifying vulnerabilities, assessing system security posture, validating security control effectiveness, conducting penetration testing activities, evaluating software assurance risks, and providing actionable remediation recommendations across classified and unclassified environments. The Senior ISSO serves as the day‑to‑day cybersecurity lead for assigned systems and acts as the principal interface between system owners, program managers, system administrators, security engineers, ISSMs, and Security Control Assessors (SCAs).
The position ensures systems remain compliant, authorized, and secure throughout their operational lifecycle.
System Security Management, the Senior ISSO shall:
- Manage cybersecurity activities for assigned systems.
- Ensure systems maintain compliance with DHS and Intelligence Community requirements.
- Monitor system security posture.
- Coordinate implementation of cybersecurity requirements.
- Provide ongoing security oversight throughout the system lifecycle.
RMF and Authorization Support, the Senior ISSO shall:
- Develop and maintain RMF documentation.
- Support Assessment & Authorization (A&A) activities.
- Maintain System Security Plans (SSPs).
- Assist with Security Assessment Reports (SARs).
- Manage Plan of Action and Milestones (POA&M) documentation.
- Support ATO and ongoing authorization efforts.
- The ISSO is typically the individual most directly responsible for maintaining authorization artifacts on a day‑to‑day basis.
Continuous Monitoring, the Senior ISSO shall:
- Execute continuous monitoring activities.
- Review vulnerability scan results.
- Track remediation actions.
- Support recurring security assessments.
- Ensure systems remain compliant between authorization cycles.
- Report security posture changes to leadership.
Vulnerability Management, the Senior ISSO shall:
- Coordinate remediation efforts with system administrators and engineers.
- Validate corrective actions.
- Maintain POA&M records.
- Monitor remediation timelines.
- Escalate unresolved cybersecurity risks.
Audit and Compliance Support, the Senior ISSO shall:
- Support cybersecurity audits and inspections.
- Provide evidence supporting compliance assessments.
- Respond to auditor requests.
- Support OIG and Intelligence Community inspections.
Security Control Management, the Senior ISSO shall:
- Verify implementation of required security controls.
- Coordinate control testing activities.
- Support Security Control Assessors during assessments.
- Validate remediation of identified findings.
- Assist in maintaining compliance with NIST and Intelligence Community control requirements.
Risk Management Support, the Senior ISSO shall:
- Identify and document cybersecurity risks.
- Participate in risk assessments.
- Coordinate with ISSMs and risk management personnel.
- Assist in preparing risk recommendations for Government review.
Stakeholder Coordination, the Senior ISSO shall:
- Coordinate with system owners regarding cybersecurity requirements.
- Support engineering and architecture reviews.
- Participate in change control activities.
- Support implementation of new technologies.
- Facilitate communication between technical and cybersecurity stakeholders.
Stakeholder Interaction, the Senior ISSO routinely interfaces with:
- Information Systems Security Managers (ISSMs)
- Security Control Assessors (SCAs)
- Security Risk Management Engineers
- Cybersecurity Engineers
- System Owners
- Program Managers
- System Administrators
- Authorizing Officials and their representatives
- At least two (2) years of recent experience in each of the following areas: A&A, FISMA compliance, IC cybersecurity policy and standards, continuous monitoring, CDS, and secure cloud and hybrid engineering, with a total of at least 10 years of total related experience.
- Experience in emerging and evolving security risk management practices including automating A&A and continuous monitoring activities.
- Exper…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).