Information System Security Officers maintaining IT security posture through collaboration with stakeholders. Supporting system security policies and risk management for national cybersecurity objectives.
Responsibilities
Serve as the primary liaison between the Cybersecurity Group, system owners, ECCP, and information owners on security and risk matters.
Ensure systems follow security policies, including vulnerability scanning, patching, and configuration management.
Verify compliance for commercial and open‑source software through OCIO governance processes.
Support incident reporting and coordination with the SOC.
Determine system categorization and control selection under the Risk Management Framework.
Coordinate with stakeholders on ECCP controls and expansion of standard control providers.
Manage IPAs and PIAs.
Review security reports and participate in briefings with system owners and leadership.
Monitor overall security posture and prepare updated Security Posture Reports.
Requirements
Required Certifications: CISSP or Security +
Education, Background, and Years of Experience: Bachelor of Science Degree
3 -5 years of experience as an ISSO/ISSM
3 - 5 years ISSO/ISSM support including
Maintain the security posture of assigned information systems and ensure compliance with federal security requirements (e.g., NIST, FISMA).
Support system authorization and accreditation activities, including preparing and maintaining A&A documentation.
Monitor system security controls and ensure they are implemented, operating, and effective.
Perform continuous monitoring activities and review security logs, scans, and reports.
Identify, track, and remediate vulnerabilities in coordination with engineering teams.
Conduct periodic security assessments and risk analysis.
Prepare and maintain system security plans, contingency plans, incident response plans, and related artifacts.
Ensure proper configuration management practices are followed for all system changes.
Support security incident response activities, including documenting and escalating events.
Work closely with system owners, developers, and administrators to ensure security is integrated throughout the system lifecycle.
Communicate security risks and recommendations to stakeholders and leadership.
Ensure users maintain proper security awareness and follow established policies and procedures.
Participate in audits and reviews, providing evidence, documentation, and responses as needed.
Track and report on Plan of Action & Milestones (POA&Ms).
Ensure compliance with policies related to access control, patch management, and security operations.
Customer Security Engineer managing end - to - end pentesting services at Aikido Security. Ensuring customer value and addressing vulnerabilities for a developer - first security product.
Cybersecurity GRC Specialist developing compliance standards across IT environments at Axpo Group. Collaborate with teams to safeguard critical systems and implement cybersecurity policies in energy sector.
Lead Cybersecurity Specialist managing enterprise cybersecurity programs at NexThreat. Overseeing cybersecurity research, engineering, and technical services while ensuring federal compliance.
Manager overseeing Netflix's global physical security technology design and build programs across multiple business verticals. Leading a team to ensure best - in - class security systems and vendor management.
Information System Security Officer liaising between Cybersecurity Group and information owners. Ensuring compliance and security posture for national security IT systems in a hybrid environment.
Technician in workplace health and safety conducting interventions in member companies of CIAMT. Focusing on risk prevention and improving workplace safety conditions.
Security Manager overseeing and processing security clearances for Danish Government and NATO compliance. Liaising with security authorities and ensuring organizational requirements are met.
Business Cybersecurity Partner overseeing cybersecurity and compliance in Aerospace sector. Ensure alignment with regulatory frameworks and manage compliance with cybersecurity requirements.
Lead Security Engineer shaping the security strategy for a renewable energy startup. Focus on secure architecture, risk management, and cross - functional collaboration.
Entry - level Cybersecurity Consultant aiding in the delivery of cybersecurity services across client engagements. Develop skills in Governance, Risk and Compliance under experienced consultants’ guidance.