Tyto Athene is searching for a Senior Information System Security Officer (ISSO) to support our federal client in Washington, DC.
This role is responsible for researching, generating, and validating security controls that support the customers’ Risk Management Framework (RMF). Responsibilities include defining, creating, and maintaining Systems Security Plans (SSP) and other related documentation to support Accreditation and Authorization (A&A) reviews and to achieve Authority to Operate (ATO). Additionally, ISSOs review systems to identify potential security weaknesses, recommend improvements to remediate vulnerabilities, and assist with implementing changes and documenting upgrades.
In addition to performing as an ISSO, the selected individual will also serve as a Team Lead to include making work assignments and mentoring and training less experienced team members.
Responsibilities:Developing and updating security authorization packages in accordance with the client’s requirement and compliant with FISMA.
Core documents that you will be responsible for include but are not limited to: System Security Plan (SSP), Risk Assessment Report, Security Assessment Plan and Report, Contingency Plan, Incident Response Plan (IRP), Standard Operating Procedures (SOP), Plan of Actions and Milestones (POA&M), Remediation Plans, Configuration Management Plan (CMP), etc.Validate that protective measures for physical security are in place to support the system's security requirementsMaintain an inventory of hardware and software for the information systemDevelop, coordinate, test, and train staff on Contingency Plans and Incident Response PlansManage emerging and defined risks associated with the administration and use of assigned information systemsCoordinate with relevant stakeholders to achieve and maintain the information systems' compliance and authorization to operate (ATO)Perform risk analyses to determine cost-effective and essential safeguardsSupport Incident Response and Contingency activitiesAble to perform security control assessment using NIST 800-53A publication as well as OMB A-130 and OMB A-123 circularsConduct independent scans of the application, network, and database (where required)Provide continuous monitoring to enforce client security policy and procedures and create processes that will provide oversight for the system ownerCoordinate with multiple stakeholders to complete mandatory agency data calls in a timely mannerTrain and mentor less experienced team members Required:Minimum of 6 years of hands-on experience as an ISSO with at least 3 of those years spent leading system authorizations for federal government HVA, critical, high, and/or cloud systems.Minimum 2 of the following relevant certifications (currently active and maintained over the life of the contract): CISSP, CISM, CGRC, CRISC, ISSMP, CISA, CCSP, CEH, Security+, PMP.Exceptional speaking, writing, and presentation skills with experience briefing up to CISO level.Expert knowledge of FISMA, RMF, NIST, and cyber-related OMB memoranda.Knowledge of cyber network defense concepts and security tools (e.g., SIEM, EDR, Tenable).Excellent organizational skills to support tracking detailed tasks and meeting deadlines 100% of the time.Excellent interpersonal skills to build and nurture strong working relationships with all stakeholders.
Desired:Bachelor’s Degree or higher in Cybersecurity, Management Information Systems, Information Technology, or a related fieldUnderstanding and experience using JCAM Clearance:Secret Clearance required Benefits:Highlights of our benefits include Health/Dental/Vision, 401(k) match, Flexible Time Off, STD/LTD/Life Insurance, Referral Bonuses, professional development reimbursement, and maternity/paternity leave.