Information System Security Officer
Arlington County, VA - USA
Job Summary
Company Overview
XPECT Solutions LLC.has built a strong reputation by supporting our clients in meeting their strategic goals and mission objectives. We provide high quality resources for a wide range of IT and security solutions at best-value pricing. Our success is built on a solid foundation of well-vetted highly technical personnel a disciplined project management approach and an overarching commitment to customer service. We develop test deploy and support exceptional solutions that enhance system functionality while maximizing reliability and availability and ensure the tightest security.
Job Overview
XPECT Solutions seeks an experienced Information Systems Security Officer (ISSO) to lead compliance and security operations for government information this role you will navigate the full NIST Risk Management Framework ensure adherence to NIST 800-53 controls and DHS 4300A requirements and oversee continuous authorization and monitoring activities. You will partner with Government Security Assurance Management teams IT Program Managers and security operations centers to protect critical systems and maintain compliance posture. This role demands deep technical security expertise regulatory knowledge and the ability to communicate complex security concepts to diverse stakeholders.
Core Responsibilties (to include but not limited to):
Risk Management Framework & Authorization
- Participate in all phases of the NIST 800-37 Risk Management Framework (Prepare Categorize Select Implement Assess Authorize Monitor)
- Ensure systems comply with NIST 800-53 security controls and DHS 4300A requirements
- Prepare comprehensive security documentation and collect security artifacts in advance of assessments
- Conduct self-assessments and support Security Control Assessment activities
Security Compliance & Remediation
- Evaluate effectiveness of proposed solutions to audit findings Security Control Assessments and other security weaknesses
- Perform root cause analysis of audit findings and security incidents
- Develop requirements for security control remediation activities
- Review vulnerability scans from security assessment tools (Nessus WebInspect DbProtect etc.)
- Develop security control implementation statements and review supporting procedures and work instructions
- Review and update the System Security Plan (SSP) and supporting security documentation
- Work with Government Security Assurance Management (SAM) on Plan of Action and Milestones (POA&M) closure requests
- Prepare status reports on security control accuracy and completeness
- Interpret security principles and requirements for remediation plans
- Brief Security Assurance Management and support teams on security posture and remediation strategies
- Perform security impact analysis of proposed configuration changes
- Review security implications of system changes with Government IT Program Managers (ITPMs) and support staff
Continuous Monitoringg & Ongoing Operations
Once a system is operational the ISSO performs recurring activitiesad hoc daily weekly monthly quarterly and annuallydocumented in the continuous monitoring plan:
- Support all Authorization to Operate (ATO) and continuous authorization activities
- Plan of Action and Milestones (POA&M) Management to track identified system weaknesses to resolution
- Information Security Vulnerability Management (ISVM)review system scans at least monthly for new weaknesses missed patches unauthorized assets or configuration changes
- Patch Management to ensure all systems are patched regularly and compliance is maintained
- Document and monitor any security issues or inconsistencies
- Review ISVM findings for applicability and create POA&Ms or take corrective action as required
- Audit Log Monitoring and Event Managementperiodically review logs for security incidents unauthorized access attempts and anomalous activity
- Awareness and Trainingensure all system users complete security awareness and role-based security training annually
- Work with federal product managers to prioritize security-related POA&Ms or enhancements into active sprints and releases
- Provide 247 on-call support for security incidents and escalations
- Ensure compliance with Zero Trust cybersecurity principles and support agency adoption of zero trust network architectures
Requirements:
- Must Be Able to Obtain Public Trust Level 6C
- Bachelors Degree in Physics Mathematics Information Technology Computer Science Business or related discipline
- Minimum of 5years of professional experience in cybersecurity information assurance or related technical roles.
- Demonstrable expertise in NIST RMF NIST 800-53 NIST 800-37 and DHS 4300A requirements
- Knowledge and experience of information security practices within federal and/or state government environments.
- Excellent written and oral skills
- Ability to work on-site in Crystal City Virginia1 dayper week
- CISSP CCSK GCIH or other advanced cybersecurity certification
- Experience with FedRAMP FISMA or other federal compliance frameworks
- Hands-on experience with vulnerability assessment tools (Nessus WebInspect Qualys etc.)
- Experience in Zero Trust architecture design and implementation
- Knowledge of cloud security (AWS Azure GCP) and containerized environments
- Experience working with Security Operations Centers (SOCs) and incident response teams
- Demonstrated success working with Agile/DevSecOps practices and sprint-based development environments
Benefits
Xpect Solutions Inc.is a one-of-a-kind employer with a talented team that is cleared at various levels and is certified in dozens of industry-recognized certifications. Our talented staff are the key to our success. They bring the knowledge experience and technical skills to deliver the best solutions to our customers.
We support our team by providing open communication win-win partnerships with clients and vendors a team-oriented culture that supports an employeefocus on professional development and growth for a long-lasting and happy career.
We offer a benefits package that is designed to keep our most important assets our employees healthy happy energized and moving forward. Our philosophy is simple empower our employees with the benefits resources and the financial incentives they need to be successful.
Benefits and Perks:
- A competitive Medical Dental and Vision plan
- Retirement Savings Plan
- Life Insurance
- AD&D Insurance
- Short Term and Long Term Disability Insurance
- 3 weeks of annual PTO
- 11 days of Holiday PTO
- Performance Awards
- Referral Bonus Plan (of up to $2500/year)
- Education Reimbursement/Training (of up to $2500/year)
#CJ
Required Experience:
Unclear Seniority
About Company
Xpect Solutions is a systems integrator, providing innovative Information Technology and Physical Security Solutions.