RiVidium Inc.
Quantico, Virginia

Information Systems Security Officer (ISSO) ? Subject Matter Expert, Level I (VA, Quantico)

OnsitePosted 2 days agoTop Secret/SCI

We tailor your resume to this role and apply for you in seconds.

Apply to Information Systems Security Officer (ISSO) ? Subject Matter Expert, Level I (VA, Quantico) at RiVidium Inc.

Job details

Location
Quantico, Virginia
Work type
Onsite
Clearance
Top Secret/SCI
Posted
2 days ago
Apply on
appone.com

About this role

RiVidium Inc. is seeking an experienced Information Systems Security Officer (ISSO) - (SME), Level I to serve the team for all Cybersecurity and Intelligence Enterprise Information Technology Services (CIEITS) program activities.

The Information Systems Security Officer (ISSO) — (SME), Level I is responsible for providing comprehensive cybersecurity support for a portfolio of 130+ Department of Homeland Security (DHS) Intelligence Enterprise (DHS IE) information systems spanning classified and unclassified environments, including on-premises, cloud, hybrid, and cross-domain solutions.

Serving as the principal cybersecurity advisor to system owners, the ISSO ensures compliance with Federal, DHS, and Intelligence Community (IC) cybersecurity requirements throughout the system lifecycle. This position is responsible for implementing the NIST Risk Management Framework (RMF), maintaining continuous authorization readiness, managing security documentation, coordinating vulnerability remediation, and supporting ongoing security operations.

In addition to traditional ISSO responsibilities, the incumbent serves as the Sensitive Compartmented Information Facility (SCIF) Information Security Compliance Representative (ISCR), ensuring assigned SCIF systems, hardware, and facilities remain compliant with Intelligence Community security policies and accreditation requirements.

The ideal candidate possesses extensive experience supporting complex Federal cybersecurity programs and demonstrates expertise in RMF, continuous monitoring, vulnerability management, cloud security, SCIF compliance, and classified information system security.

Key Responsibilities

  • Perform Information Systems Security Officer (ISSO) responsibilities for a portfolio of 130+ assigned information systems throughout the system lifecycle in accordance with NIST RMF, supporting Steps 1, 2, 3, and 6.
  • Serve as the primary cybersecurity advisor to system owners regarding security posture, authorization status, compliance, risk management, and operational security.
  • Ensure information systems are operated, maintained, monitored, and decommissioned in accordance with DHS, Intelligence Community, and Federal cybersecurity requirements.
  • Develop, maintain, and update all RMF security documentation within the Governance, Risk, and Compliance (GRC) platform, including:
    • System Security Plans (SSPs)
    • Plans of Action and Milestones (POA&Ms)
    • Risk Acceptance and Exception documentation
    • Privacy Threshold Analyses (PTAs)
    • Contingency Plans (CPs)
    • Rules of Behavior
    • System inventories and supporting authorization artifacts
  • Manage and track POA&Ms using established review intervals (30, 60, 90, 120, and 180 days), ensuring timely remediation or submission of risk waivers and exception requests.
  • Conduct weekly audit log reviews and investigate anomalous or suspicious activity in coordination with cybersecurity operations teams.
  • Coordinate system modifications, configuration changes, and authorization boundary updates with the ISSM, Security Control Assessor (SCA), and Authorizing Official (AO/DAO) through the Information Assurance Technical Tracking (IATT) process.
  • Notify the ISSM whenever system changes could impact the Authorization to Operate (ATO).
  • Perform day-to-day cybersecurity operations, including:
    • Security incident response support
    • Personnel security coordination
    • Physical and environmental security oversight
    • Security awareness activities
    • Configuration management support
  • Ensure DHS 4300C system decommissioning requirements are properly executed and support system recovery activities following contingency events or disasters.
  • Plan, coordinate, and facilitate annual Contingency Plan Test Exercises, including tabletop, simulation, parallel, and full operational testing.
  • Prepare and submit Quarterly Continuous Protection and Evaluation Metrics (CPEM) reports for assigned systems.
  • Serve as the SCIF Information Security Compliance Representative (ISCR) by:
    • Maintaining compliance with Intelligence Community SCIF security requirements
    • Completing mandatory ICOP training
    • Coordinating with the DHS I&A CISO SCIF Compliance Team
    • Maintaining inventory accountability for SCIF hardware and information systems
    • Reporting SCI security incidents
    • Preparing and submitting Monthly SCIF Security Checklists
  • Prepare Weekly Activity Reports (WARs), POA&M status reports, Incident Response reports, removable media reports, privileged user reports, and other required Government deliverables.
  • Support vulnerability management by coordinating vulnerability scanning activities, reviewing scan results, and tracking remediation efforts.
  • Collaborate with ISSMs, engineers, developers, system administrators, and cybersecurity operations teams to maintain continuous authorization and improve enterprise security posture.

 

Minimum Qualifications

  • Active Top Secret/Sensitive Compartmented Information (TS/SCI) security clearance.
  • Minimum 5–10 years of experience serving as an Information Systems Security Officer (ISSO), Information Systems Security Manager (ISSM), or in a comparable cybersecurity role supporting Federal Government or Intelligence Community programs.
  • Current Certified Information Security Manager (CISM), Certified Authorization Professional (CAP), or comparable Governance, Risk, and Compliance (GRC) certification.
  • Certified Information Systems Security Professional (CISSP) certification is highly desirable.
  • Demonstrated experience supporting RMF authorization activities across hybrid cloud and on-premises environments.
  • Working knowledge of:
    • NIST Risk Management Framework (RMF)
    • NIST SP 800-53
    • DHS Sensitive Systems Policy Directive 4300C
    • CNSSI 1253
    • ICD 503
  • Experience using Governance, Risk, and Compliance (GRC) tools such as RSA Archer.
  • Experience using vulnerability assessment tools such as Nessus, ACAS, or equivalent.
  • Experience securing Windows, Linux, and open-source operating systems.
  • Experience supporting Cross Domain Solutions (CDS) and associated security governance requirements.
  • Familiarity with DevSecOps, Agile software development methodologies, and secure software lifecycle practices.
  • Bachelor's degree in Cybersecurity, Information Systems, Computer Science, Information Assurance, or a related technical discipline.

Preferred Qualifications

  • AWS Certified Security – Specialty, Microsoft Azure Security Engineer Associate, or equivalent cloud security certification.
  • Experience serving as a SCIF Information Security Compliance Representative (ISCR) or coordinating with Special Security Officers (SSOs).
  • Experience supporting Cross Domain Solution (CDS) governance, including National Cross Domain Strategy and Management Office (NCDSMO) requirements and Raise-the-Bar (RTB) initiatives.
  • Familiarity with Continuous Protection and Evaluation Metrics (CPEM) reporting requirements and Intelligence Community Continuous Monitoring (IC ConMon) programs.
  • Experience supporting DHS Intelligence & Analysis (I&A), the Intelligence Community, or other classified Federal cybersecurity environments.

Required Certifications

One or more of the following certifications are required:

  • Certified Information Security Manager (CISM)
  • Certified Authorization Professional (CAP)
  • Governance, Risk, and Compliance (GRC) Certification

Preferred:

  • Certified Information Systems Security Professional (CISSP)
  • AWS Certified Security – Specialty
  • Microsoft Certified: Azure Security Engineer Associate

Clearance Requirement

Active Top Secret/Sensitive Compartmented Information (TS/SCI) Clearance Required

Ready to apply to RiVidium Inc.?
We tailor your resume to this role and apply for you.

About RiVidium Inc.

RiVidium Inc.
Quantico, Virginia