Sr. Information System Security Officer (ISSO)

Washington, DC, US • Posted 4 days ago • Updated 1 hour ago
Full Time
On-site
USD 120,000.00 per year
Fitment

Dice Job Match Score™

🔗 Matching skills to job...

Job Details

Skills

  • Recruiting
  • Information Security
  • Information Systems
  • Policies and Procedures
  • Information System Security
  • NIST SP 800 Series
  • Risk Assessment
  • Security Analysis
  • SAP Security
  • SAR
  • Standard Operating Procedure
  • STIG
  • Configuration Management
  • Risk Analysis
  • Continuous Monitoring
  • Vulnerability Scanning
  • Database
  • Inventory
  • Computer Hardware
  • Enterprise Architecture
  • Incident Management
  • Management
  • Law Enforcement
  • Criminal Justice
  • Regulatory Compliance
  • Legal
  • Software Development Methodology
  • Development Testing
  • Records Management
  • DoD
  • Auditing
  • Reporting
  • Media
  • Evaluation
  • Data Collection
  • Training
  • FISMA
  • Risk Management Framework
  • RMF
  • Privacy
  • Authorization
  • SPA
  • OMB
  • CNSS
  • Publications
  • System Security
  • Writing
  • Technical Analysis
  • Communication
  • Relationship Management
  • Business Acumen
  • ISACA
  • CISSP
  • FedRAMP
  • ServiceNow
  • Nessus
  • Qualys
  • BSD
  • Unix
  • Microsoft Windows
  • Microsoft Operating Systems
  • Microsoft Windows NT
  • Linux
  • Open Source
  • Policy Writing
  • Security Clearance
  • Life Insurance
  • Professional Development
  • IT Service Management
  • Network
  • Cloud Computing
  • Cyber Security
  • Law

Summary

Description

Tyto Athene is hiring a Sr. Information Security Officer (ISSO) to support a federal customer in Washington, DC. The successful candidate will ensure information systems meet security requirements and will lead and support ongoing privacy-related activities, including the development, implementation, maintenance, and enforcement of federal and organizational policies and procedures governing the protection of Personally Identifiable Information (PII) and other sensitive data. The ISSO will bring strong knowledge of federal privacy laws and regulations and will support the Governance Risk and Compliance program with federally mandated privacy requirements, policies, and procedures.

Responsibilities:
  • Lead and support information system security boundary responsibilities utilizing the Risk Management Framework (RMF) lifecycle, including system Authorization to Operate (ATO) and continuous monitoring, while ensuring privacy and legal requirements are fully integrated.
  • Develop, update, and maintain security authorization packages in accordance with client requirements and NIST SP 800-53, including System Security and Privacy Plans (SSPPs), Risk Assessment Reports (RARs), Security Assessment Plans (SAP), Security Assessment Reports (SAR), Contingency Plans, Incident Response Plans, Standard Operating Procedures (SOPs), Plans of Action and Milestones (POA&Ms), STIG deviations, Configuration Management Plans, Security Impact Assessments, and related artifacts.
  • Maintain, manage and support POA&M and remediation activities, including validation of corrective actions and participation in the continuous monitoring process.
  • Perform security and privacy risk analyses and technical assessments to identify weaknesses, deficiencies, and gaps, and recommend cost-effective and compliant safeguards.
  • Provide continuous monitoring oversight, including review of vulnerability scan results for applications, networks, and databases, ensuring findings are addressed in accordance with security and privacy policies.
  • Maintain an inventory of hardware and software within the system security boundary and coordinate with system owners, records management, and enterprise architecture stakeholders.
  • Develop, coordinate, test, and train on Contingency Plans and Incident Response Plans, and support incident response and continuity activities.
  • Conduct and oversee Privacy Threshold Analyses (PTAs) and Privacy Impact Assessments (PIAs), and remain current with evolving OMB policies, NIST guidance, and federal privacy laws.
  • Apply and interpret law enforcement and federal privacy requirements, including Criminal Justice Information Services (CJIS) Security and Privacy Policy, and support compliance within a Legislative Branch environment.
  • Support High Value Asset (HVA) identification and categorization using privacy, legal, and risk-based frameworks.
  • Develop, update, and maintain privacy directives, policies, and SOPs, including translating approved privacy policy into actionable operational procedures.
  • Integrate privacy-by-design principles into the System Development Life Cycle (SDLC), ensuring privacy requirements are addressed throughout system planning, development, testing, deployment, and maintenance.
  • Review, update, and deliver enterprise privacy training programs, including privacy awareness, advanced privacy training, records management, data collection practices, and role-based training models tailored to Legislative Branch versus DoD applicability.
  • Coordinate with internal and external stakeholders to complete mandatory agency data calls, audits, and reporting requirements in a timely manner.

Qualifications

Required:
  • 8+ years of professional experience with at least 6 years supporting ISSO RMF activities.
  • Bachelor's Degree or 4 years of additional experience in lieu of a degree.
  • Knowledge of and proficiency in federal government privacy programs, with working knowledge of privacy laws and regulations and their relationship to the Privacy Act of 1974 and the E-Government Act of 2002.
  • A demonstrated understanding of information privacy, including information access, the release of information, and implementation of control technologies as they apply to privacy information contained in electronic and non-electronic media.
  • Experience with Cybersecurity Awareness Training (CSAT) related privacy initiatives, including evaluation of training effectiveness, data collection practices, and selection of appropriate privacy training models.
  • Experience with HR privacy and behavioral privacy considerations related to workforce data and monitoring activities.
  • Thorough understanding and knowledge of FISMA, NIST RMF and Security and Privacy Assessment and Authorization (SPA&A) processes.
  • Experience with NIST publications, OMB circulars and memoranda, and CNSS publications and their requirements and impact on system security.
  • Proficiency in writing technical analysis reports with strong written and oral communication skills.
  • Ability to work quickly, efficiently, and accurately in a dynamic and fluid environment.
  • Good relationship management, business acumen, judgment, and ability to think critically.

Desired:
  • Preferred certifications: CRISC, CAP, CISSP, or equivalent.
  • Experience with FedRAMP and cloud service providers.
  • Experience with CSAM and ServiceNow.
  • Experience with vulnerability assessments tools such as Nessus and/or Qualys.
  • Experience in administrating BSD/UNIX, Windows, Windows NT, Linux, or other open-source compliant systems.
  • Policy writing background is highly preferred.
  • CIPP/G/US Certification is a PLUS.

Clearance:
  • with Public Trust eligibility required.

Location:
  • On-site contract with Hybrid allowance in Washington DC a minimum of two days a week (Tuesday and Thursday) but can be increased based on customer needs.

About Tyto Athene

Compensation:
  • Compensation is unique to each candidate and relative to the skills and experience they bring to the position. The salary range for this position is typically between $120,000-$135,000. This does not guarantee a specific salary as compensation is based upon multiple factors such as education, experience, certifications, and other requirements, and may fall outside of the above-stated range.

Benefits:
  • Highlights of our benefits include Health/Dental/Vision, 401(k) match, Paid Time Off, STD/LTD/Life Insurance, Referral Bonuses, professional development reimbursement, and parental leave.

Tyto Athene is a trusted leader in IT services and solutions, delivering mission-focused digital transformation that drives measurable success. Our expertise spans four core technology domains-Network Modernization, Hybrid Cloud, Cybersecurity, and Enterprise IT-empowering our clients with cutting-edge solutions tailored to their evolving needs. With over 50 years of experience, Tyto Athene proudly support Defense, Intelligence, Space, National Security, Civilian, Health, and Public Safety clients across the United States and worldwide.

At Tyto Athene, we believe that success starts with our people. We foster a collaborative, innovative, and mission-driven environment where every team member plays a critical role in shaping the future of technology. Are you ready to join #TeamTyto?

Tyto Athene, LLC is an Equal Opportunity Employer; all qualified applicants will receive consideration for employment without regard to race, color, religion, sex, [sexual orientation, gender identity,] national origin, disability, status as a protected veteran, or any characteristic protected by applicable law.
Employers have access to artificial intelligence language tools (“AI”) that help generate and enhance job descriptions and AI may have been used to create this description. The position description has been reviewed for accuracy and Dice believes it to correctly reflect the job opportunity.
  • Dice Id: 91085617
  • Position Id: e67cc140cce4ae95076fe2d39aaf7401
  • Posted 4 days ago
Create job alert
Set job alertNever miss an opportunity! Create an alert based on the job you applied for.

Similar Jobs

Washington, District of Columbia

Today

Full-time

USD 120,001.00 - 160,000.00 per year

Washington, District of Columbia

Today

Full-time

USD 80,001.00 - 120,000.00 per year

Fort Belvoir, Virginia

Today

Full-time

Washington, District of Columbia

Today

Full-time

Search all similar jobs