Senior Information Systems Security Officer @Diné Development Corporation
All Others
Salary unspecified
Remote Location
🇺🇸 USA Only
Employment Type full-time
Posted 5d ago

[Hiring] Senior Information Systems Security Officer @Diné Development Corporation

5d ago - Diné Development Corporation is hiring a remote Senior Information Systems Security Officer. 💸 Salary: unspecified 📍Location: USA

Role Description

We are seeking a Senior Information Systems Security Officer to join our dynamic team. In this role, you will lead our client's ISSO and Risk and Compliance teams, overseeing activities related to risk management, compliance, and information system security. Your expertise in FedRAMP, RMF, and accreditation assessments will be crucial in ensuring our client's systems adhere to Federal standards.

Responsibilities

  • Accreditation Assessments:
    • Perform security control assessment services for clients in commercial and government sectors, ensuring compliance with NIST RMF and FedRAMP requirements.
    • Develop and review RMF packages with meticulous attention to detail and accuracy.
    • Assist contract companies in meeting Federal agency including OMB, and EO or Intelligence Community mandates for security compliance.
    • Collaborate with private entities to establish effective cybersecurity programs, particularly for critical infrastructure.
    • Maintain FISMA authorization to operate for information systems through internal audits and adherence to NIST RMF security controls.
    • Act as the primary advisor on NIST RMF compliance, offering guidance on resolving outstanding issues and meeting security control requirements.
    • Conduct comprehensive security control assessments following NIST, IHS, and CISA guidelines.
    • Provide expert recommendations to the Approval Official regarding network and system authorizations.
    • Assist with implementing General Support Systems (GSS).
    • Assist with implementing Common Controls.
    • Assist advising continuous monitoring and implementing RBD program.
    • Train and educate team members and stakeholders on NIST RMF principles and best practices.
  • FedRAMP Compliance:
    • Serve as the organization's trusted Subject Matter Expert (SME) for FedRAMP, wielding a deep understanding of its requirements, guidelines, and controls.
    • Conduct internal FedRAMP readiness assessments to identify and remediate gaps or deficiencies prior to Third-Party Assessment Organizations (3PAOs) assessments.
    • Coordinate FedRAMP readiness assessments with 3PAOs.
    • Develop and maintain essential FedRAMP compliance documentation (System Security Plans (SSPs), Security Assessment Reports (SARs), and Plan of Actions and Milestones (POA&Ms)).
    • Assist with remediating any findings identified during FedRAMP assessments and preparing for audits by the Federal government or authorized entities.
    • Act as a liaison with the FedRAMP program office to facilitate effective communication and compliance alignment.
  • ISSO Tasks:
    • Develop a real-time risk management system that fosters collaboration and enhances security practices within the organization.
    • Conduct regular security risk analyses for hospitals and healthcare systems to identify vulnerabilities and mitigate potential threats.
    • Provide daily advisory support to the National Security Director, addressing security concerns and participating in the implementation of a robust incident response program.
    • Stay abreast of Healthcare IT technologies and apply NIST 800 series methodologies to safeguard them effectively.
    • Train and mentor IT Security Team members, equipping them with the knowledge and skills needed to perform their roles efficiently.
    • Provide technical leadership to accreditation assessors and ISSOs.
    • Conduct analysis of current environment and provide recommendations to align accreditation processes with NIST and RMF guidance.
    • Create and maintain information security policies in compliance with NIST and HIPAA regulations.
    • Utilize Archer to develop and maintain system accreditation lifecycle workflows and ATO packet management processes.
    • Conduct comprehensive security control assessments following NIST, IHS, and CISA guidelines.
  • Risk and Compliance Management:
    • Conduct security risk analyses for current and emerging systems.
    • Provide expert recommendations to the Approval Official regarding network and system authorizations.
    • Coordination of risk assessment and compliance activities between R&C and ISSO teams.
    • Conduct comprehensive assessments of security controls for IHS systems and sites, following NIST and CISA guidelines and ensuring adherence to risk management practices.
    • Offer guidance and advice on risk management techniques, procedures, and best practices to subordinate commands.
    • Act as Lead consultant for security control assessors and ISSO coordination, develop the processes and document standard procedures, fostering a collaborative and high-performing work environment.
    • Provide expert recommendations to the Approval Official (AO) regarding the authorization of organizations' networks and systems on IHS networks.
    • Thoroughly review system and site artifacts to verify compliance with NIST RMF requirements and identify potential areas for improvement.
    • Utilize network scanning and patching tools to mitigate vulnerabilities and enhance system security.
    • Prepare and present Approval to Operate (ATO) or Interim Approval to Test (IATT) documents, ensuring compliance with assessment requirements and CATOs.
    • Stay current with relevant NIST publications, NIST, CISA and IHS standards, and other guidelines.
    • Contribute to the development of policies, procedures, and methodologies that align with NIST RMF and support the organization's transition to these frameworks.
    • Train new security control assessors and other team members, ensuring they possess the necessary skills and knowledge to excel in their roles.
    • Utilize network scanning and patching tools to mitigate vulnerabilities and enhance system security.
    • Conduct staff assistance visits and annual FISMA security control assessments for DRSN sites, providing valuable insights and recommendations for improvement.
    • Manage deliverables, coordinate briefings, and oversee staff visits using effective project management practices.
    • Provide expert advice and produce necessary artifacts to ensure ongoing compliance with NIST RMF requirements and maintain a robust security posture.

Qualifications

  • Years of Experience: 10+ Years Relevant Experience
  • Education Level: Bachelor’s Degree; Master’s Degree preferred
  • Clearance Requirements: Public Trust
  • Certification Requirements: CISSP
  • Experience leading large projects in a Federal healthcare environment.
  • Strong knowledge and understanding of HIPAA, PII, NIST, FISMA, and FedRAMP.
  • Proficiency with Nessus and Archer GRC (2 years desired).
  • Expert knowledge of RMF, NIST, accreditation assessments, and DISA-STIGs.
  • Excellent communication and briefing skills for client leadership.

Benefits

  • Eligible full-time employees receive a comprehensive benefits package, including medical, dental, vision, life and disability coverage, retirement savings with company match, and paid time off.
  • Additional benefits include voluntary supplemental benefits, access to an employee assistance program, and educational assistance with tuition reimbursement.
Before You Apply
️
🇺🇸 Be aware of the location restriction for this remote position: USA Only
‼ Beware of scams! When applying for jobs, you should NEVER have to pay anything. Learn more.
Senior Information Systems Security Officer @Diné Development Corporation
All Others
Salary unspecified
Remote Location
🇺🇸 USA Only
Employment Type full-time
Posted 5d ago
Apply for this position
Did not apply ✓
Applied ✓
Sent Follow-Up ✓
Interview Scheduled ✓
Interview Completed ✓
Offer Accepted ✓
Offer Declined ✓
Application Denied ✓
Unlock 125,000+ Remote Jobs
️
🇺🇸 Be aware of the location restriction for this remote position: USA Only
‼ Beware of scams! When applying for jobs, you should NEVER have to pay anything. Learn more.
Apply for this position
Did not apply ✓
Applied ✓
Sent Follow-Up ✓
Interview Scheduled ✓
Interview Completed ✓
Offer Accepted ✓
Offer Declined ✓
Application Denied ✓
Unlock 125,000+ Remote Jobs
×
Apply to the best remote jobs
before everyone else

Access 125,000+ vetted remote jobs and get daily alerts.

4.9 ★★★★★ from 500+ reviews

⚡ 126,903+ remote jobs, refreshed hourly

🔔 Real-time alerts: Apply first, direct to employer

🛡️ Vetted companies, no scams, true remote only

Unlock All Jobs Now

Maybe later