TL;DR
Information System Security Officer Lead (Cybersecurity): Applies Risk Management Framework (RMF) and NIST 800-series standards to protect multi-tenant cloud and hybrid-enterprise environments with an accent on conducting vulnerability analyses and engineering remediation plans that satisfy rigorous FISMA requirements. Focus on translating technical security gaps into clear, executive-level narratives that facilitate informed risk-management decisions.
Location: Hybrid role in Reston, VA
Company
hirify.global brings adaptive innovation to support our nation's most important missions through the seamless integration of advanced technologies, elite minds, and unparalleled agility.
What you will do
- Apply the Risk Management Framework (RMF) and NIST 800-series standards to protect multi-tenant cloud and hybrid-enterprise environments.
- Conduct deep-dive vulnerability analyses and engineer remediation plans that satisfy rigorous FISMA requirements.
- Translate technical security gaps into clear, executive-level narratives that facilitate informed risk-management decisions.
- Manage security authorization processes, such as Authorization/Certification & Accreditation (A&A) and Authorization to Operate (ATO).
- Develop associated documentation for security authorization processes.
- Analyze security vulnerabilities, provide comprehensive assessments, and develop effective remediation instructions.
Requirements
- Bachelor’s degree in computer science, Engineering, STEM, Information Technology, or Cybersecurity.
- A minimum of 8 years of experience in information security, with at least 5 years specifically in a lead ISSO or similar leadership capacity on large complex USG programs.
- One or more of the following certifications required: Active Certified Information Systems Security Professional (CISSP), Active Certified Information Security Manager (CISM).
- Must have a Secret (TS Eligible) clearance level.
Nice to have
- Active Project Management Professional (PMP) certification
- Active ISC2 Certified in Governance, Risk and Compliance (CGRC)
- Knowledge of FedRAMP
- Knowledge of A-123 audit Experience and Expertise with GRC tools such as CSAM
Culture & Benefits
- Culture defined by the 6Hs: Happy, Helpful, Honest, Humble, Hungry, Hustle.
- Competitive and comprehensive benefits package (refer to company website).
- Employees are the number one priority, and the importance we place on our culture here is fundamental.
- A positive and connected environment where motivation and satisfaction have an outsized effect on everything we do.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →