As an ISSO you'll be supporting as the point of contact (POC) to the information system owner (SO), ISSM, CISO on all matters (technical and otherwise) involving the security of assigned information systems (on prem, vendor, and cloud-based).
Ensure the assigned FISMA systems maintain their ATO through independent security assessment and authorization;
The ISSO shall have oversight responsibility to ensure proper access controls have been implemented and managed;
ISSO shall ensure audit logs are reviewed at an agreed upon frequency, where the frequency may increase if warranted by incident or situational awareness.
Be responsible for conducting assessments of controls for their system to ensure the controls have been implemented properly and are still effective where the risk posture is documented in a system risk assessment report.
Ensure documents provided to auditors are what was requested and approved for release.
Ensure that new vulnerabilities are evaluated by the respective subject matter expert and corrective action implemented.
Collaborate with the Security Engineer in conducting security impact assessments on change to their respective FISMA systems.
Collaborate with the Security Operations Center in reviewing vulnerability and compliance scan results at an agreed upon frequency.
Requirements
Completed Bachelor’s degree from an accredited university in an IT related field.
Strong working knowledge and familiarity with NIST publications and privacy frameworks.
Demonstrated understanding of cloud service models, hybrid models, financial applications, and mobile security technologies and tools.
Demonstrated experience supporting an industry risk management tool executing A&A activities.
Ability to identify and assess risks and recommend appropriate remediation strategies.
Must be well-organized and detail-oriented with the ability to coordinate, prioritize multiple tasks, and be adaptable to change to accomplish assignments.
Ability to work independently and with teams.
Professional and polished interpersonal and communication skills.
Proficient with Microsoft Office to include Outlook, Word, PowerPoint, and Excel.
One or more of the following certifications: Security+, Network+, CASP, CISA, CEH, or other industry recognized certification.
Tech Stack
Cloud
Benefits
paid parental leave
flexible time off
certification and training reimbursement
digital mental health and wellbeing support memberships