Senior ISSO/ISSE ? National Vetting Center
Listed on 2026-09-14
-
IT/Tech
Cybersecurity, Information Security & Data Protection, Security Management & Operations
Full-Time/Part-Time Full-Time
Description
Position Overview
We are seeking a highly experienced Senior Information System Security Officer / Information System Security Engineer (ISSO/ISSE) to support the cybersecurity, security engineering, risk management, and authorization activities for the National Vetting Center (NVC).
This is a Key Personnel position requiring a senior cybersecurity professional who can provide both operational security oversight and technical security engineering expertise. The successful candidate will help ensure that systems remain secure, compliant, and authorized throughout their lifecycle.
The Senior ISSO/ISSE will work closely with system owners, cybersecurity engineers, Security Control Assessors (SCAs), program leadership, infrastructure teams, and government stakeholders to implement security controls, manage risk, support authorization activities, and maintain continuous monitoring.
Key Responsibilities
- Serve as a senior cybersecurity advisor and primary security point of contact for assigned NVC systems and environments.
- Perform ISSO and ISSE responsibilities supporting system security throughout the system development and operational lifecycle.
- Lead and support Risk Management Framework (RMF) activities, including categorization, control implementation, assessment, authorization, and continuous monitoring.
- Develop, maintain, and update System Security Plans (SSPs) and related security authorization documentation.
- Implement, evaluate, and monitor security controls in accordance with federal cybersecurity requirements.
- Support Authorization to Operate (ATO) and ongoing authorization activities.
- Coordinate with Security Control Assessors to provide assessment evidence and resolve identified security deficiencies.
- Review security assessment findings and develop risk-based remediation strategies.
- Manage and track Plans of Action and Milestones (POA&Ms) and security weaknesses.
- Validate remediation activities and ensure vulnerabilities and control deficiencies are appropriately addressed.
- Perform security engineering reviews of systems, applications, networks, and infrastructure.
- Evaluate system architectures and technical designs for cybersecurity risks.
- Provide recommendations for security architecture, system hardening, access controls, encryption, authentication, and other security mechanisms.
- Support security requirements throughout system design, development, implementation, and operations.
- Conduct security risk assessments and analyze potential threats and vulnerabilities.
- Support continuous monitoring activities and periodic security control assessments.
- Review vulnerability assessment results and coordinate remediation with technical teams.
- Monitor system changes and determine their potential impact on security posture and authorization status.
- Ensure security documentation remains accurate and reflects current system configurations and controls.
- Coordinate with system administrators, network engineers, developers, cloud engineers, cybersecurity analysts, and other technical personnel.
- Support security audits, inspections, assessments, and compliance reviews.
- Prepare cybersecurity status reports, risk assessments, briefings, and executive-level presentations.
- Provide technical guidance and mentorship to junior ISSOs and cybersecurity personnel.
- Stay current with federal cybersecurity policies, NIST publications, emerging threats, and security engineering best practices.
Required Qualifications
- Bachelor's degree in Cybersecurity, Information Systems, Information Technology, Computer Science, Engineering, or a related field
. - Significant experience in information security, cybersecurity, information assurance, security engineering, or a related discipline.
- Demonstrated experience performing ISSO and/or ISSE responsibilities.
- Strong experience with the NIST Risk Management Framework (RMF).
- Experience implementing and assessing cybersecurity controls.
- Experience supporting federal security authorization and ATO processes.
- Experience developing and maintaining System Security Plans and authorization documentation.
- Experience managing POA&Ms, vulnerabilities, security findings, and remediation activities.
- Knowledge of NIST SP 800-53 security controls and federal cybersecurity requirements.
- Ability to evaluate technical architectures and identify cybersecurity risks.
- Strong understanding of security engineering principles, system hardening, access control, authentication, encryption, and network security.
- Experience…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).