Information System Security Officer
Agile DefenseAbout the role
At Agile Defense we know that action defines the outcome and new challenges require new solutions. That’s why we always look to the future and embrace change with an unmovable spirit and the courage to build for what comes next.
Our vision is to bring adaptive innovation to support our nation's most important missions through the seamless integration of advanced technologies, elite minds, and unparalleled agility—leveraging a foundation of speed, flexibility, and ingenuity to strengthen and protect our nation’s vital interests.
Requisition #: 381Job Title: Information System Security OfficerLocation: Ashburn, VirginiaClearance Level: Active DoD - SecretRequired Certification(s): · CompTIA Network+, CompTIA Security +, CISSP and Security auditing are recommended. CSAM cert preferred.
SUMMARYThe U.S. Customs and Border Protection (CBP) Office of Information and Technology (OIT), Enterprise Infrastructure and Operation Directorate (EIOD), Network Architecture and Engineering Division (NAED) provides management services and oversight of the CBP infrastructure to protect, defend and restore the confidentiality, integrity and availability of CBP mission essential data communications and applications. The purpose of this task order is to provide network architecture and network engineering services. NAE ensures a standardized, high performance, and secure enterprise network architecture for the CBP enterprise that seamlessly integrates existing and emerging technologies. NAED, which comprises the Network Architecture Branch (NAB) and Network Engineering Branch (NEB).The ISSO will be the Designated Person(s) assigned to one or more existing FISMA Systems of Record as well as new IT Systems that are slated as new work products to develop an Authority to Operate (ATO) and follow-on Continuous Monitored system. As a Designated ISSO, they will sign a DHS sponsored Letter that lays out the roles and responsibilities of the ISSO function to maintain Compliance requirements on a daily basis. The ISSO will report to a Designated Information System Security Manager (ISSM) and the Director of Security. Due to the importance of keeping system(s) updated to meet FISMA guidelines, while supporting DHS/CISA directives around limiting vulnerabilities, the ISSO role is of upmost importance throughout its lifecycle.
JOB DUTIES AND RESPONSIBILITIES· Document and provide information on security controls (implemented in systems being engineered, implemented, or maintained by NAE) as directed by the Government.· Make recommendations, implement security controls, and/or reengineer systems to address Plan of Action and Milestones (POA&M) and audit findings.· Implement and document security controls and applicable processes for CBP systems to ensure compliance with the CBP Risk Management Framework, FISMA regulations, and applicable DHS/CBP/DoD security policies.· Provide expert analysis and recommendations on risk (to include impact and likelihood) and mitigation options for security findings, gaps, and vulnerabilities. This includes developing appropriate responses to audit report findings. If risks cannot be resolved, the ISSO will work with the Director of Security, ISSM, and System Owner (SO) to develop a Deviation Waiver Request (Risk Acceptance) based on thorough analysis and industry standards identifying the risk, impact/threat if exploited, existing countermeasures, risk level, and reason/justification for risk.
QUALIFICATIONSRequired Certifications· CompTIA Network+, CompTIA Security +, CISSP and Security auditing are recommended. CSAM cert preferred.Education, Background, and Years of Experience· Senior ISSO role will highlight past experiences over a 5-to 10-year period.
ADDITIONAL SKILLS & QUALIFICATIONSRequired Skills· A senior ISSO role will highlight past experiences over a 5-to 10-year period.· Must have a background with Zero Trust compliance.· Familiarity with Palo Alto, Zscaler, and Mobility support.Previous work experience in the following area includes, but is not limited to:· Familiarity with network and information system security principles and best practices.· In-depth knowledge of the Risk Management Framework (RMF), the NIST publications, and the DHS 4300A.· Experience with implementing the NIST 800-53 Security Controls in an Assessment & Authorization (A&A) process.· Experience reviewing Nessus scans, managing vulnerability mitigation and information security process in an Enterprise environment.· Basic understanding of Enterprise networking concepts.· Ability to work well within a team environment and build rapport with government and customer organizations.
WORKING CONDITIONSEnvironmental Conditions· The primary worksite will be Government sites within the National Capital Region (NCR) and Northern· Virginia. There will be occasions w
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s