Information System Security Officer (ISSO)
Washington, District Of Columbia, United States
Full Time Mid-level / Intermediate Clearance required USD 150K+
RIVA Solutions, Inc.
We empower our mission-driven community of passionate, innovative professionals to modernize government digital services.- Serve as the primary cybersecurity point of contact for assigned classified information systems.
- Develop, maintain, and manage security authorization packages in accordance with Risk Management Framework (RMF) guidelines.
- Conduct continuous monitoring, risk assessments, and security impact analyses for assigned systems.
- Ensure all systems comply with CNSS, NIST 800-53, RMF, and agency-specific security policies and standards.
- Perform security control assessments and validate implementation of applicable security controls.
- Draft and maintain System Security Plans (SSPs), Plan of Actions and Milestones (POA&Ms), Security Assessment Reports (SARs), and other required cybersecurity documentation.
- Provide technical guidance on security architecture, security controls, and remediation strategies.
- Coordinate with Information System Owners (ISOs), Information System Security Managers (ISSMs), and system administrators on security issues.
- Respond to and document security incidents, ensuring appropriate incident response measures are executed.
- Support configuration management processes, ensuring security impact assessments are conducted for system changes.
- Participate in internal and external cybersecurity audits, inspections, and reviews.
- Conduct security briefings, training sessions, and awareness activities for system users.
- Maintain system audit logs and assist with forensic investigations as needed.
- Bachelor's Degree in Cybersecurity, Information Assurance, Information Technology, or a related field.
- Minimum 5+ years of cybersecurity experience with at least 3+ years in an ISSO or similar role.
- Strong understanding of RMF, NIST 800-53 controls, CNSS policies, and DISA STIGs.
- Experience developing and managing security authorization packages.
- Proficient in vulnerability management, POA&M tracking, and incident response processes.
- Ability to work independently and collaborate across multi-disciplinary teams.
- Must have an active Top Secret / SCI clearance.
- Experience supporting Department of Commerce (DOC) or federal cybersecurity programs.
- Familiarity with eMASS or similar security management platforms.
- Industry certifications such as Security+, CISSP, CISM, or CAP are preferred but not required.
- Health, Dental, and Vision Coverage
- Life Insurance
- Retirement Benefits / 401K with Company Matching
- HSA/FSA Spending Accounts
- Long- and Short-Term Disability
- Pet Insurance
- Wellness Program Initiatives
- RIVA Flex
- Additional Workplace Benefits
Tags: Audits CISM CISSP Clearance CNSS DISA eMASS Incident response Monitoring NIST NIST 800-53 POA&M Risk assessment Risk management RMF Security assessment Security Assessment Report Security Impact Analysis STIGs System Security Plan Top Secret Vulnerability management
Perks/benefits: 401(k) matching Health care Insurance Wellness
More jobs like this
Explore more career opportunities
Find even more open roles below ordered by popularity of job title or skills/products/technologies used.