Alternative Information System Security Officer (A-ISSO) III
BOOST LLCAbout the role
BOOST LLC is a dynamic management consulting firm that offers an array of government-compliant back-office solutions to support our teaming partners within the GovCon space. Our consultants are experts in the areas of Accounting, Contracts, Human Resources, Recruiting & Sourcing, and Strategic Pricing and our passion is to guide and propel our partners towards success within this competitive sector.
BOOST is helping our client; ZenPoint Solutions LLC (“ZenPoint Solutions”) find a highly qualified Business Analyst II. ZenPoint Solutions is a rapidly expanding Information Technology (IT) services company in the federal sector. We foster a thriving, ambitious work environment that prioritizes employee well-being and a positive company culture. We invite you to join our team and help us shape a dynamic future as we deliver innovative solutions to address the nation's most critical IT missions.
Position Overview: One of our Department of State contracts is seeking an A-ISSO (Senior) to join our team in providing advanced cybersecurity and system integration services. The ideal candidate is a proactive, self-motivated professional with extensive experience in securing information systems.
In this role, the A-ISSO will ensure the appropriate security posture is maintained across various platforms, including cloud-based SaaS/PaaS solutions, server-based applications, databases, development environments, standalone systems, and desktop/laptops. They will oversee and assist in the implementation of controls and procedures to safeguard DOS information systems from unauthorized modification, disclosure, or destruction. Additionally, the A-ISSO will be responsible for updating key security documentation, including system security plans, change management protocols, incident response plans, and related policies and procedures.
Clearance Requirement: Candidates must hold a minimum Interim Secret clearance and be able to secure a full scope Secret clearance once on contract
Work Location: Washington, DC
Work Schedule (Hybrid): Three (3) days onsite at the customer's facility and two (2) remote days; work schedule is subject to change based on customer needs and without prior notice
Key Responsibilities:
- Ensure systems are operated, maintained, and disposed of in accordance with security policies and procedures
- Maintain the operational security posture of information systems
- Create and maintain existing information system security documentation, including SSP, Security Controls Traceability Matrix (SCTM), and Risk Management Framework (RMF) Body of Evidence
- Ensure all users have the requisite security clearance, authorization, need-to-know, and are aware of their security responsibilities before being granted access to the system, and periodically thereafter
- Write security control implementation details describing how security features are implemented based upon the requirements set forth by NIST 800-53
- Prepare system documentation for assessment in accordance with RMF, FISMA and NIST Special Publications (800-37, 800-53 and others); identify deficiencies and provide recommendations for solutions; assist in writing remediation plans for findings, create Plan of Action (POA&M) in the GRC tool, and track them to closure
- Participate in Authority to Operate Assessment activities in support of Security Control Assessors and Information System Security Managers
- Create security policies and maintain existing information system security documentation
- Conduct periodic and continuous monitoring of the system to ensure compliance with the authorization package
- Participate in the change management process, including reviewing “Change Requests” and assisting in the assessment of security impact of proposed changes
- Conduct daily, weekly, and monthly audit review and management of the audit collection system for assigned systems, boundaries, and components
- Continuously review and evaluate best practices for implementing a comprehensive audit program
- Implement vulnerability management programs including tracking, remediating and closing of identified vulnerabilities
- Support penetration testing efforts
- Provide direction and guidance to less experienced cybersecurity personnel
- Remain sensitive to security infractions and assist in security investigations and responses as requested
- Assist with conducting contingency plan testing and remediate weaknesses identified during testing
- Oversee system recovery processes to ensure that security features and functions are fully restored and operating correctly after an out
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s
Similar roles
R&D Category Manager, Dairy & Dairy Alternatives
Cargill
Host/Hostess iGaming Show (Restaurant Alternative) $20 - $25/hr.
Evolution
$50,000/yr
Card Shuffler - Range $14-$16/hour - (Server Alternative)
Evolution
$32,000/yr