Information System Security Officer (ISSO)
HarmoniaAbout the role
Harmonia Holdings Group, LLC is an award-winning, rapidly growing federal government contractor committed to providing innovative, high-performing solutions to our government clients and focused on fostering a workplace that encourages growth, initiative, creativity, and employee satisfaction.
We are seeking a highly skilled Information System Security Officer (ISSO) to support the implementation of security controls within a secure SCIF environment. The ISSO will be responsible for ensuring compliance with government security policies and standards while providing oversight of system security, assessing risks, and implementing necessary security controls to safeguard classified systems and data.
Key Responsibilities:
- Implement and maintain security controls in accordance with government regulations, such as NIST 800-53, FISMA, and DoD Risk Management Framework (RMF).
- Monitor, evaluate, and maintain the security posture of systems, ensuring compliance with Security Technical Implementation Guides (STIGs) and other relevant security requirements.
- Develop and update System Security Plans (SSPs), Risk Assessments, Plan of Action and Milestones (POA&Ms), and other documentation to reflect the current system security state.
- Collaborate with system administrators, network engineers, and other IT staff to identify, mitigate, and document risks associated with system vulnerabilities and security threats.
- Ensure continuous monitoring of systems by reviewing audit logs, conducting vulnerability scans, and assessing the effectiveness of existing security controls.
- Provide support for security assessments and accreditation processes, ensuring that security controls are properly implemented and verified.
- Lead security control assessments and assist with audits and inspections from internal and external agencies.
- Serve as the point of contact for all system security-related matters and provide guidance to system owners on maintaining compliance with security regulations.
- Conduct regular security briefings and training to staff on the importance of maintaining security best practices within the SCIF environment.
- Respond to and manage security incidents, coordinating with relevant stakeholders to perform root cause analysis and remediation.
- Ensure that systems and networks comply with the Continuous Monitoring Program (CMP) and Incident Response Plan (IRP) for rapid detection and response to security events.
Required Qualifications:
- Top Secret clearance with SCI eligibility is required.
- Strong experience as an Information System Security Officer (ISSO) or similar role within a SCIF or other highly secure government environments.
- Knowledge of Risk Management Framework (RMF), NIST 800-53, FISMA, and other relevant government security regulations.
- Experience developing and maintaining System Security Plans (SSPs), POA&Ms, and other security documentation.
- Strong understanding of Security Technical Implementation Guides (STIGs) and hardening of systems.
- Proven ability to implement, manage, and monitor security controls, assess vulnerabilities, and mitigate security risks.
- Hands-on experience with vulnerability management tools, SIEM solutions, and continuous monitoring technologies.
- Familiarity with security incident response procedures, including root cause analysis and remediation.
- Strong analytical and problem-solving skills with attention to detail.
- Excellent communication and collaboration skills to work effectively with technical teams and senior leadership.
Preferred Qualifications:
- Relevant certifications such as Certified Information Systems Security Professional (CISSP), Certified Information Security Manager (CISM), or Certified Information Systems Auditor (CISA).
- Experience with classified systems accreditation processes and Continuous Diagnostics and Mitigation (CDM).
- Familiarity with security automation tools and processes.
Work Environment:
- This position is 100% onsite in a SCIF environment, ensuring the secure handling of classified information.
- Occasional after-hours work may be required to address security inciden
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s