What are the responsibilities and job description for the Information Systems Security Officer (ISSO) position at NextGen Federal Systems?
The ISSO will support CBP customers by ensuring system compliance with federal cybersecurity policies, guidelines, and frameworks. The ISSO will work closely with system owners, security engineers, and program management to maintain system accreditation, enforce security best practices, and mitigate cybersecurity risks.
Key Responsibilities
Ensure compliance with DHS policies, Federal Information Security Modernization Act (FISMA), National Institute of Standards and Technology (NIST) Special Publication (SP) 800-53, and other applicable security requirements. Develop and maintain Security Authorization Packages (SAP) under Risk Management Framework (RMF), including System Security Plans (SSP), Security Assessment Reports (SAR), and Plan of Action & Milestones (POA&M). Perform Continuous Monitoring (ConMon) activities, including vulnerability assessments, security audits, and system reviews. Monitor and report security incidents, ensuring compliance with DHS reporting guidelines and procedures.
Conduct security impact assessments for new systems, applications, and technology integrations. Review and validate system configurations against Security Technical Implementation Guides (STIGs) and DHS Security Policies. Support Authorization to Operate (ATO) and system accreditation activities, working with DHS Cybersecurity Division (CISA) and other stakeholders. Assist with penetration testing, vulnerability scanning, and remediation of identified weaknesses.
Stay current on emerging cybersecurity threats, technologies, and best practices relevant to DHS systems.
Required Qualifications
Equal Opportunity Employer/Protected Veterans/Individuals with Disabilities.
RefID: B01x
Key Responsibilities
Ensure compliance with DHS policies, Federal Information Security Modernization Act (FISMA), National Institute of Standards and Technology (NIST) Special Publication (SP) 800-53, and other applicable security requirements. Develop and maintain Security Authorization Packages (SAP) under Risk Management Framework (RMF), including System Security Plans (SSP), Security Assessment Reports (SAR), and Plan of Action & Milestones (POA&M). Perform Continuous Monitoring (ConMon) activities, including vulnerability assessments, security audits, and system reviews. Monitor and report security incidents, ensuring compliance with DHS reporting guidelines and procedures.
Conduct security impact assessments for new systems, applications, and technology integrations. Review and validate system configurations against Security Technical Implementation Guides (STIGs) and DHS Security Policies. Support Authorization to Operate (ATO) and system accreditation activities, working with DHS Cybersecurity Division (CISA) and other stakeholders. Assist with penetration testing, vulnerability scanning, and remediation of identified weaknesses.
Stay current on emerging cybersecurity threats, technologies, and best practices relevant to DHS systems.
Required Qualifications
- Bachelor’s degree in Cybersecurity, Information Technology, Computer Science, or a related field (or equivalent experience)
- 10 years of experience with background in cybersecurity, risk management, or IT security roles
- Ability to obtain and retain a CBP Background Investigation
- One of the following certifications: CISSP (Certified Information Systems Security Professional), CISM (Certified Information Security Manager), Security (CompTIA Security ), and/or CEH (Certified Ethical Hacker) or equivalent
- Experience with NIST RMF, DHS Information Security Program, DHS 4300A/B, and Federal IT security frameworks
- Hands-on experience with security tools (e.g., Nessus, Splunk, ACAS, HBSS, SIEM solutions)
- Understanding of network security, cloud security (AWS, Azure, or Google Cloud), and endpoint protection
- Active DHS Suitability, CBP Background Investigation and/or Top Secret Clearance
- Experience supporting DHS or other Federal Government cybersecurity programs
- Familiarity with DevSecOps, automation tools, and secure coding practices
- Experience conducting security control assessments and audits
Equal Opportunity Employer/Protected Veterans/Individuals with Disabilities.
RefID: B01x