- Company Name
- Datasoft Technologies, Inc.
- Job Title
- Senior Information System Security Officer (ISSO) - 25-03166
- Job Description
-
**Job Title:**
Senior Information System Security Officer (ISSO)
**Role Summary:**
Provide expert cybersecurity consulting to a government Office of Cybersecurity. Oversee day‑to‑day security and compliance for complex IT environments, develop and maintain RMF artifacts, conduct audits, manage risk, and collaborate with leadership, stakeholders, and third parties.
**Expectations:**
- 12‑month consulting assignment with potential extension
- On‑site engagement with the agency’s cybersecurity team
- Deliver comprehensive security plans, risk assessments, and compliance documentation for FISMA, NIST, CMS MARS‑E, HIPAA, and related standards
- Act as primary liaison for third‑party audits and vendor security reviews
**Key Responsibilities:**
- Develop, review, and maintain System Security Plans, Privacy Impact Assessments, ISAs, CMAs, and other RMF artifacts
- Perform architectural reviews and risk analyses of security requests (network design, access models, firewall rules, configuration deviations, vulnerability findings)
- Lead audit and assessment activities for internal and business partner systems, ensuring compliance with agency policies and regulations
- Manage contract and business associate agreement reviews for security and privacy compliance
- Serve as primary contact for third‑party audits and security assessments
- Coordinate with agency leadership, business partners, vendors, and cross‑functional teams to recommend and implement risk mitigation strategies
- Document findings and recommendations using tools such as Archer eGRC, Microsoft Office, System Center Service Manager, Bizagi, and Atlassian
**Required Skills:**
- Strong knowledge of FISMA, NIST, CMS MARS‑E, HIPAA Security and Privacy frameworks
- 5+ years’ experience with IBM System 390/zSeries, Windows, Linux, relational/non‑relational databases, networking, and web applications
- 3–5+ years of risk management and RMF (ISS, Information Security Architect, Security Control Assessor) experience
- Experience with eGRC systems (e.g., Archer) and cloud/vendor security
- Proficiency in performing vulnerability management, firewall rule analysis, baseline configuration review, and security architecture assessment
- Excellent communication skills for engaging technical and non‑technical stakeholders
- Ability to multitask, prioritize, and deliver results in a consulting environment
**Required Education & Certifications:**
- Active certification from ISC² (CCSP, CISSP, or equivalent), ISACA (CISM, CISA), or SANS GIAC (e.g., GCIA, GCIH, GCFA)
- Minimum of 3–5 years of experience in a FISMA‑compliant program
- Prior health information technology experience preferred
- Bachelor’s degree in Computer Science, Information Security, or related field (or equivalent experience)
---