← All jobs
Information Systems Security Officer (ISSO)
Washington, District of Columbia · On-site · Full-time · Engineering
Apply well, not just fast
Create a free account and upload your resume to get a match score, keyword gaps, a tailored resume, a cover letter and interview prep for this job.
About the role
CybersecurityPenetration TestingProgram ManagementSAPRisk Management
NextGen Federal Systems is looking to hire an ISSO to support our efforts with US Customs and Border Protection's Office of Acquisition in Washington, DC.
The ISSO will support CBP customers by ensuring system compliance with federal cybersecurity policies, guidelines, and frameworks. The ISSO will work closely with system owners, security engineers, and program management to maintain system accreditation, enforce security best practices, and mitigate cybersecurity risks.
Key Responsibilities
Ensure compliance with DHS policies, Federal Information Security Modernization Act (FISMA), National Institute of Standards and Technology (NIST) Special Publication (SP) 800-53, and other applicable security requirements. Develop and maintain Security Authorization Packages (SAP) under Risk Management Framework (RMF), including System Security Plans (SSP), Security Assessment Reports (SAR), and Plan of Action & Milestones (POA&M). Perform Continuous Monitoring (ConMon) activities, including vulnerability assessments, security audits, and system reviews. Monitor and report security incidents, ensuring compliance with DHS reporting guidelines and procedures.
Conduct security impact assessments for new systems, applications, and technology integrations. Review and validate system configurations against Security Technical Implementation Guides (STIGs) and DHS Security Policies. Support Authorization to Operate (ATO) and system accreditation activities, working with DHS Cybersecurity Division (CISA) and other stakeholders. Assist with penetration testing, vulnerability scanning, and remediation of identified weaknesses.
Stay current on emerging cybersecurity threats, technologies, and best practices relevant to DHS systems.