Information Systems Security Officer (ISSO)

Posted:
10/6/2024, 11:29:25 PM

Experience Level(s):
Mid Level ⋅ Senior

Field(s):
IT & Security

Workplace Type:
Remote

Information Systems Security Officer (ISSO)

Job Category: Information Technology

Time Type: Full time

Minimum Clearance Required to Start: None

Employee Type: Regular

Percentage of Travel Required: Up to 10%

Type of Travel: Local

* * *

The Opportunity:

CACI is seeking an Information Systems Security Officer (ISSO) to join our team of technical and functional experts supporting the U.S. Department of Homeland Security (DHS) Headquarters, Chief Technology Officer Directorate (CTOD), Artificial Intelligence and Emerging Technology (AI/ET) initiative. This team works with a federal workforce staff with technical expertise for the smooth functioning of high-visibility, department-wide AI initiatives.

The ideal candidate for the Information Systems Security Officer (ISSO) role will possess a strong understanding of FISMA, NIST, and IT security processes, with demonstrated experience in IT security assessments, audits, and documentation. They should excel in developing and maintaining Certification & Accreditation (C&A) documentation, ensuring compliance with DHS 4300A and NIST SP guidance. The candidate should have a proven track record in information assurance, maintaining operational security postures, and supporting system owners and security managers.

This is a remote work eligible position.

Responsibilities:

The Information Systems Security Officer (ISSO) provides support for the designated FISMA boundaries and associated System Owner (SO) and Information System Security Manager (ISSM) to ensure customer systems maintain their Authority to Operate (ATO) with a security posture in accordance with DHS 4300A and NIST SP guidance. This support includes providing IT security assessment and IT security audit functions to ensure FISMA compliance; developing and maintaining documentation to support Certification & Accreditation (C&A) as required by the Federal Information Security Management Act (FISMA); ensuring all C&A and system security documentation is kept up to date; and ensuring systems meet all security requirements mandated by DHS 4300A and DHS Management Directives.

Responsibilities include, but are not limited to:

  • Provide IT security assessment and IT security audit functions to ensure FISMA compliance.
  • Develop and maintain documentation in support of Certification & Accreditation (C&A).
  • Provide ISSO support to ensure customer systems obtain and maintain their Authority to Operate (ATO) with a security posture in accordance with NIST SP 800-53A guidance.
  • Ensure all C&A and system security documentation (Security Plan, Privacy Threshold Analysis, Privacy Impact Assessment, e-Authentication, FIPS-199, Business Impact Analysis, Continuity of Operations, Inter-Agency Service Agreement, etc.) is kept up to date or created when needed.
  • Provide support to Federal ISSO for implementing, and enforcing information systems security policies, standards, and methodologies.
  • Prepare and maintain documentation.
  • Assist in the evaluation of security solutions to ensure they meet security requirements for processing DHS information.
  • Assist as required with the Configuration Management (CM) for the information system to maintain security.
  • Develop and maintain documentation for C&A in accordance with NIST, FISMA and DHS policies. Assist with evaluating security solutions to ensure they meet security requirements for processing system's designated data requirements.
  • Maintain operational security posture for an information system or program.
  • Provide support to System Owner (SO) and Information System Security Manager (ISSM) for maintaining the appropriate operational IA posture for a system, program, or enclave.
  • Develop and update system security plans and other IA documentation.
  • Provide information assurance for all information security systems, ensuring its confidentiality, integrity, and availability.
  • Provide supporting documentation for decisions granting authorization to operate IT systems at acceptable levels of risk, monitoring and testing of IT systems for vulnerabilities and indications of compromise, incident response and remediation, the development of appropriate policy, relevant user security awareness and training, and compliance with applicable government and other external standards.

Qualifications:

Required: 

  • Ability to obtain DoD Security Clearance
  • Ability to obtain Department of Homeland Security (DHS) Entry On Duty (EOD) - Active EOD preferred
  • BA/BS and 8 years’ experience in a related field, or equivalent (equivalency includes MA/MS + 5 years applicable experience or AA/AS +10)
  • 4+ years as an ISSO, working with FISMA, or in other directly relatable positions
  • Demonstrated experience in SELC, Information Security processes, audits, tools, implementation, FISMA, NIST, and IT security
  • Understanding of information security best practices
  • Ability to work independently and as part of a team
  • Able to communicate clearly and professionally with senior Federal government representatives to field and troubleshooting questions and issues

Desired: 

  • Certified Information Systems Security Professional (CISSP)
  • Certified Authorization Professional (CAP)
  • Information Technology Infrastructure Library v4 (ITIL v4)
  • Previous DHS or DoD experience
  • Experience working in a geographically dispersed, remote workforce
  • Strong organization and communications skills and ability to work collaboratively with Senior Government Leaders
  • Advanced MS Office Suite proficiency (Excel, PowerPoint, Word, Teams)
  • Excellent written and verbal communications skills
  • Excellent interpersonal skills and able to relate effectively with program employees, government/client representatives, and internal organizational functional representatives
  • Experienced receiving initial information and guidance, conducting research to better understand requirements, and achieving high quality results
  • Knowledge of Enterprise Architecture fundamental
  • Cloud network or architecture experience (E.g., Nutanix, AWS, Azure, Google, etc.)
  • Experience in reviewing NIST controls, understanding inheritance, and writing control implementation statements to address how a system is meeting control requirements.

-

_____________________________________________________________________________

What You Can Expect:

 

A culture of integrity.

At CACI, we place character and innovation at the center of everything we do. As a valued team member, you’ll be part of a high-performing group dedicated to our customer’s missions and driven by a higher purpose – to ensure the safety of our nation.

 

An environment of trust.

CACI takes pride in fostering a diverse and accessible culture where every individual feels supported to chart their own path. You’ll have the autonomy to take the time you need through a unique flexible time off benefit and have access to robust learning resources to make your ambitions a reality.

 

A focus on continuous growth.

Together, we will advance our nation's most critical missions, build on our lengthy track record of business success, and find opportunities to break new ground — in your career and in our legacy.

 

Your potential is limitless. So is ours.

Learn more about CACI here.

_____________________________________________________________________________

Pay Range: There are a host of factors that can influence final salary including, but not limited to, geographic location, Federal Government contract labor categories and contract wage rates, relevant prior work experience, specific skills and competencies, education, and certifications. Our employees value the flexibility at CACI that allows them to balance quality work and their personal lives. We offer competitive compensation, benefits and learning and development opportunities. Our broad and competitive mix of benefits options is designed to support and protect employees and their families. At CACI, you will receive comprehensive benefits such as; healthcare, wellness, financial, retirement, family support, continuing education, and time off benefits. Learn more here.

Since this position can be worked in more than one location, the range shown is the national average for the position.

The proposed salary range for this position is:

$68,400-$143,700

CACI is an Equal Opportunity/Affirmative Action Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, pregnancy, sexual orientation, gender identity, age, national origin, disability, status as a protected veteran, or any other protected characteristic.