What are the responsibilities and job description for the Senior Information Systems Security Officer (ISSO)-W2 Only position at Information Resource Group, Inc.?
Job Details
Role: Senior Information Systems Security Officer (ISSO)-W2 Only
Location: Columbia, SC
Duration: One Year contract.
Job Description:
IRG Clients is seeking an expert Senior ISSO to lead and support security and compliance efforts for complex information system environments. The ideal candidate will oversee the implementation of security programs in accordance with FISMA, NIST, CMS MARS-E, HIPAA, and other regulatory standards.
Key Responsibilities:
- Lead the development, implementation, and enhancement of security and compliance programs.
- Perform architectural reviews, risk assessments, and security audits for internal and external systems.
- Maintain and update System Security Plans (SSPs), Privacy Impact Assessments (PIAs), Interconnection Security Agreements (ISAs), and other security artifacts.
- Oversee security and compliance reviews of contracts, Business Associate Agreements (BAAs), and Data Usage/Sharing Agreements.
- Serve as the primary point of contact for third-party audits and compliance assessments.
- Collaborate with agency leadership, vendors, and business partners to ensure risk mitigation and security best practices.
- Utilize eGRC systems (RSA Archer), Microsoft Office, System Center Service Manager, Bizagi, and Atlassian tools for documentation and reporting.
Required Skills & Qualifications:
- 5 years of experience in IT security, including working with IBM System 390/zSeries, Windows, Linux, Databases (Relational & NoSQL), Networking Infrastructure, and Web Applications.
- Strong knowledge of FISMA, NIST, CMS MARS-E, and HIPAA security and privacy frameworks.
- Prior experience working within a FISMA-compliant security program.
- Hands-on experience with eGRC systems.
- Proficiency in risk management frameworks (RMF) and their integration into System Development Life Cycle (SDLC).
- Experience in cloud security and vendor management.
- Strong ability to engage technical and non-technical audiences, prioritize tasks, and work in fast-paced, results-oriented environments.
- Proficiency in Microsoft Office (Word, Excel, PowerPoint, Visio) with experience in branding and template usage.
Preferred Skills:
- Experience with ITIL-based Information Security Management.
- Health Information Technology (HIT) experience.
Education & Certifications:
- Required: ISC(2), ISACA, SANS GIAC, or other relevant Information Security Certification.
- Preferred: Bachelor's degree in Computer Science, Information Security, or a related field (or 10 years of experience in lieu of a degree).