Find Jobs
Find Jobs Near You – Available Work in Your Location
Senior Information System Security Officer - PLACEMENT
Career Insights for Cyber Security Analyst
See where this job fits in the broader career landscape. Knowing your career path helps you see what's possible from here.
Scorecard
Based on Maryland data
Review key factors to help you decide if this role fits your goals. How is this calculated?
What they do
A Cyber Security Analyst works on monitoring, controlling, and maintaining systems that protect the security of large databases, including databases with customer information and patient files. Analyzes the examination of client computer systems, identification of weak points in security, development and implementation of new systems, and monitoring and response to security issues.
$145,455 / year median in Maryland
+2% projected growth
Job Description
Senior Information System Security Officer
- PLACEMENT
Skills - Information System Security
- Software Engineering
- Brand
- Security Clearance
- Project Management
- Preventive Maintenance
- Performance Management
- Documentation
- eXist
- FOCUS
- Access Control
- Patch Management
- Information Security
- RMF
- Risk Management Framework
- FISMA
NIST SP 800
Series
NIST 800-53
- Incident Management
- Risk Assessment
- Continuous Monitoring
- Management
- Change Request Management
- Configuration Management
- Traceability Matrix
- Security Controls
- Impact Analysis
- Auditing
- Cyber Security
- Regulatory Compliance
- eMASS
- SAP GRC
- Cloud Security
- FedRAMP
- Authorization
- Communication
- FEMA
- DoD
- CISSP
- CISM
- IT Service Management
- Innovation
- Collaboration
- Recruiting
- Artificial Intelligence
- Privacy
- Insurance
- Finance
- Professional Development
- Training
- Leadership
- CompTIA
- Customer Service
- Career Counseling
SAP BASIS
- Law
- ADA
- Apex
- Oracle Application Express
- Information System Security
- Software Engineering
- Brand
- Security Clearance
- Project Management
- Preventive Maintenance
- Performance Management
- Documentation
- eXist
- FOCUS
- Access Control
- Patch Management
- Information Security
- RMF
- Risk Management Framework
- FISMA
NIST SP 800
Series
NIST 800-53
- Incident Management
- Risk Assessment
- Continuous Monitoring
- Management
- Change Request Management
- Configuration Management
- Traceability Matrix
- Security Controls
- Impact Analysis
- Auditing
- Cyber Security
- Regulatory Compliance
- eMASS
- SAP GRC
- Cloud Security
- FedRAMP
- Authorization
- Communication
- FEMA
- DoD
- CISSP
- CISM
- IT Service Management
- Innovation
- Collaboration
- Recruiting
- Artificial Intelligence
- Privacy
- Insurance
- Finance
- Professional Development
- Training
- Leadership
- CompTIA
- Customer Service
- Career Counseling
SAP BASIS
- Law
- ADA
- Apex
- Oracle Application Express
- Summary Job#: 3041526
For immediate response, please send to : Updated WORD resume, desired hourly/salary rate, and best time to speak!
Position:
Sr. ISSO x7
OPENINGS Location:
FEMA St. Elizabeth Campus (SE DC)
- Currently remote but must be comfortable coming on-site when needed
Duration:
6 Month Contract to Hire (Brand New 5 Year Contract)
MUST HAVES
- Ability to obtain and maintain a DHS Public Trust up to a Top Secret Clearance
BS & 10 YOE OR AS & 13 YOE OR 16+ YOE
- Experience manage RMF process and POA&Ms
- Comfortable managing multiple systems at once and assisting with automating systems
Shift:
Monday
- Friday, 9 AM
- 5 PM 7
OPENINGS:
Sr.
Level ISSO Environment:
- In discussions with the CISO, it was clear that the security program and systems have been neglected for at least a year, if not longer.
- While documentation, artifacts, and security plans may exist, t is little confidence that they are current, complete, or in good condition.
- The CISO's primary goal is to get the environment back on track and clean up existing security and compliance issues.
- Focused on increasing automation wver possible to improve efficiency and reduce manual effort.
- The immediate focus is remediation and stabilization, with automation initiatives to follow once processes are back under control.
- The environment consists of roughly 90 systems, although the exact number is unclear.
- The team wants to move away from assigning ISSOs to individual systems and instead organize responsibilities by security control areas (e.g., Access Control, Configuration Management) across all systems.
- Rather than owning a specific set of systems, ISSOs would be responsible for managing and monitoring their assigned control families enterprise-wide.
- T is not a high level of confidence in the current patch management process and patching posture across the environment.
Skillset:
- Senior ISSO with 10+ years of Information Security experience supporting federal systems
- Deep expertise leading the full RMF lifecycle and ATO process end-to-end
- Strong knowledge of
FISMA, NIST 800-37, NIST 800-53, DHS 4300
Series, and federal cybersecurity requirements
- Experience serving as the primary cybersecurity lead/advisor for system owners, PMOs, and senior leadership
- Hands-on experience developing and maintaining SSPs, POA&Ms, Configuration Management Plans, Contingency Plans, and Incident Response Plans
- Experience conducting risk assessments, annual security assessments, vulnerability assessments, and continuous monitoring activities
- Ownership of POA&M management, remediation planning, audit findings, and compliance tracking
- Experience performing Security Impact Analyses, change request reviews, and configuration management activities
- Ability to develop and maintain authorization boundary diagrams, security architectures, and security requirement traceability matrices
- Experience with security control implementation, self-assessments, control inheritance, and business impact analyses
- Strong background supporting security audits, ATO packages, compliance reviews, and accreditation efforts
- Experience developing remediation plans and advising stakeholders on cybersecurity risks and compliance requirements
- Familiarity with CSAM, eMASS, RegScale, or similar GRC platforms
- Knowledge of cloud security and FedRAMP authorization processes
- Strong communication skills with the ability to brief executives, present risk findings, and work directly with senior leadership
- Preferred experience supporting DHS, FEMA, DoD, or other federal agencies
- CISSP, CISM, or CASP+ certification preferred (IAT Level III equivalent) EEO Employer Apex Systems is an equal opportunity employer.
We do not discriminate or allow discrimination on the basis of race, color, religion, creed, sex (including pregnancy, childbirth, breastfeeding, or related medical conditions), age, sexual orientation, gender identity, national origin, ancestry, citizenship, genetic information, registered domestic partner status, marital status, disability, status as a crime victim, protected veteran status, political affiliation, union membership, or any other characteristic protected by law. Apex will consider qualified applicants with criminal histories in a manner consistent with the requirements of applicable law. If you have visited our website in search of information on employment opportunities or to apply for a position, and you require an accommodation in using our website for a search or application, please contact our Employee Services Department at or . Everforth Apex is a world-class IT services company that serves thousands of clients across the globe. When you join Everforth Apex, you become part of a team that values innovation, collaboration, and continuous learning. We offer quality career resources, training, certifications, development opportunities, and a comprehensive benefits package. Our commitment to excellence is reflected in many awards, including ClearlyRateds Best of Staffing in Talent Satisfaction in the United States and Great Place to Work in the United Kingdom and Mexico. Everforth Apex uses a virtual recruiter as part of the application process. for more details. By applying for this job, you agree to receive calls, AI-generated calls, text messages, or emails from Everforth Apex and its affiliates, and contracted partners. Frequency varies for text messages. Message and data rates may apply. Carriers are not liable for delayed or undelivered messages. You can reply STOP to cancel and HELP for help. You can access our privacy policy at
Everforth Apex Benefits Overview:
Everforth Apex offers a range of supplemental benefits, including medical, dental, vision, life, disability, and other insurance plans that offer an optional layer of financial protection. We offer an ESPP (employee stock purchase program) and a
Benefits
- Professional Development
- Employee Stock Options (ESOs)
- Health Insurance
- Dental Insurance