[Hiring] ISSO Support Specialist @CyberData Technologies
ISSO Support Specialist @CyberData Technologies
All Others
Salary unspecified
Remote Location
🇺🇸 USA Only
Employment Type full-time
Posted YDay

[Hiring] ISSO Support Specialist @CyberData Technologies

YDay - CyberData Technologies is hiring a remote ISSO Support Specialist. 💸 Salary: unspecified 📍Location: USA

Role Description

The Information System Security Officer (ISSO) supports organization’s information systems by managing day-to-day cybersecurity compliance, risk management, and system authorization activities. The ISSO works closely with system owners, technical teams, the cybersecurity organization, and other stakeholders to ensure assigned systems remain compliant with federal and agency’s security requirements throughout their lifecycle.

The ISSO Support Specialist performs the following duties:

  • Serve as the primary cybersecurity/compliance point of contact for assigned HRSA systems.
  • Support the NIST Risk Management Framework (RMF) and system Authorization to Operate (ATO) lifecycle, including initial authorizations and ongoing authorization activities.
  • Oversee the security posture for one or more system(s) throughout the entire lifecycle; provides continuous monitoring through scheduled audits, controls testing, and audit reviews, and escalates issues as needed.
  • Oversee the implementation of information technology (IT) security controls and security authorization documents; ensure the system is Federal Information Security Management Act (FISMA) compliant with mandated security policies and requirements.
  • Provide technical recommendations for all Risk Assessments and Vulnerability Assessments conducted for the system or site; provide security analysis of IT activities to ensure that appropriate security measures are in place and being enforced.
  • Coordinate penetration testing or other 'red team' activities that might occur at/or traverse the system’s infrastructure as part of a Security Control Assessment (SCA).
  • Promote IT security awareness information to the user community by validating the user community is completing their annual training.
  • Oversee and maintain regulatory requirements and participate on the Change Control Board (CCB) by reviewing system changes for security implications.
  • Provide general system security support to ensure a secure posture is in place for systems that support key program areas.
  • Verify that application/system security postures are implemented as stated; document deviations by performing FISMA/NIST compliance monitoring.
  • Recommend required actions to correct deviations.
  • Develop/update system security plans, risk assessments, disaster recovery, and contingency plans, incident response and additional system development life-cycle (SDLC) security documentation for systems and/or applications in alignment with the SDLC.
  • Provide coordination, consolidation, and submission of the Authority to Operate (ATO) security documentation for CISO approval.
  • Track security assessment and authorization (SA&A) packages, reviewing authorization documents to confirm that security requirements are compliant.
  • Facilitate remediation/mitigation of the POA&Ms to reduce risk and address weaknesses to the system.
  • Provide Continuous Monitoring support/guidance by reviewing security documentation, logs, scans and ensuring system backups are performed.
  • Review hardware/software asset inventory and ensure completion; advise system owner (SO) and management regarding gaps.
  • Assist the CISO and SO with security-related inquiries and issues; coordinate protective or corrective measures when an incident or vulnerability is discovered.
  • Identify security weaknesses and document the weaknesses in the Security Assessment Report (SAR).
  • Work with SOs, developers, and administrators to develop an access control or role-based model that ensures secure access to the system/application.
  • Implement processes to control, enforce, and monitor access and privileges which lead to securing the systems and information.
  • Review system changes for security implications; conduct security impact assessments when system changes or additions occur to the system.
  • Analyze and support security control assessments by verifying results with the organization’s IS/IA requirements.
  • Confirm that the level of risk is within acceptable limits.
  • Analyze the effectiveness of the system security safeguards to ensure they demonstrate the intended level of protection and functionality.
  • Advise or inform SO and leadership on risks to the security posture.
  • Develop security risk assessment; advise SO on requirements in alignment with security risk assessment results.
  • Develop disaster recovery and contingency plans for systems and/or applications to reduce system risk.
  • Provide operational risk management support which involves participating in risk assessments, managing system weaknesses, and providing ongoing risk monitoring, threat management and mitigation support.
  • Evaluate and provide input into the risk and adequacy of security measures proposed or provided in response to system acquisitions.
  • Perform risk assessments, as required by the client.
  • Review threat and vulnerability assessment findings to quantify and prioritize vulnerabilities in a system.
  • Serve as IT security subject matter expert (SME)/POC for customer interactions and communications.
  • Coordinate across teams to ensure compliance with policies and alignment with the Risk Management Framework (RMF) and HHS or Operating Division policies, procedures, and guidance.
  • Manage delivery risks/logical escalation related to delivery requirements.

Qualifications

  • Hands-on experience supporting federal cybersecurity programs, particularly FISMA, NIST RMF, NIST SP 800-53 security controls, ATOs, POA&Ms, security assessments, and continuous monitoring.
  • Experience working with federal eGRC platforms such as Archer.
  • Familiarity with vulnerability management and cloud environments such as AWS or Azure.

Requirements

  • Must have FEDRAMP experience with cloud-based systems.

Company Description

Before You Apply
🇺🇸 Be aware of the location restriction for this remote position: USA Only
Beware of scams! When applying for jobs, you should NEVER have to pay anything. Learn more.
ISSO Support Specialist @CyberData Technologies
All Others
Salary unspecified
Remote Location
🇺🇸 USA Only
Employment Type full-time
Posted YDay
Apply for this position
Did not apply
Applied
Sent Follow-Up
Interview Scheduled
Interview Completed
Offer Accepted
Offer Declined
Application Denied
Unlock 120,000+ Remote Jobs
🇺🇸 Be aware of the location restriction for this remote position: USA Only
Beware of scams! When applying for jobs, you should NEVER have to pay anything. Learn more.
Apply for this position
Did not apply
Applied
Sent Follow-Up
Interview Scheduled
Interview Completed
Offer Accepted
Offer Declined
Application Denied
Unlock 120,000+ Remote Jobs
×

Apply to the best remote jobs
before everyone else

Access 120,000+ vetted remote jobs and get daily alerts.

4.9 ★★★★★ from 500+ reviews
Unlock All Jobs Now

Maybe later