MANTECH seeks a career and customer-oriented Information System Security Officer (ISSO) to join our team supporting a federal agency’s Safeguards and Risk Management (SRM) mission. This is a fully remote position and only expected to be in the office in case of emergency or if requested/required by government.
Responsibilities include but not limited to:
-
Categorizes systems (FIPS 199) in coordination with system owners, accounting for high-volume PII/NPI data aggregation risks inherent to organizational data.
-
Build the control package: apply NIST SP 800-53 controls, develop the SSP, draft implementation statements, and collect evidence validating secure data ingestion and processing.
-
Guide system owners on writing and resolving implementation statements.
-
Drive controls to secure status and see them through testing, with emphasis on data integrity, encryption-in-transit (TLS), and Identity & Access Management (IAM).
-
Partner closely with the Security Assessment Provider/SCA to ensure quality of artifacts and evidence to enable the assessment.
-
Advise system owners on control prioritization, ensuring alignment with both NIST frameworks and financial regulatory data protection standards (e.g., FFIEC expectations).
-
Support RMF & A&A: Cyber Risk Framework (CRF) input, Change Request Reviews, POA&M tracking, SA&A Project List, and SOPs/A&A artifacts on a best-effort basis.
Minimum Qualifications:
-
Hands-on experience with NIST RMF (800-30, 800-37, 800-53, and 800-53A) – practical implementation, not just familiarity.
-
Demonstrated experience building control packages and drafting implementation statements.
-
Experience in creating or supporting Security Assessment Plans and Security Assessment Reports.
-
Experience with Q-Compliance (or the ability to ramp quickly).
-
Experience interpreting data from vulnerability scanning tools (e.g., Tenable, Qualys) to identify risks in databases and file-processing pipelines.
-
Understanding network architectures, including SaaS, IaaS, or PaaS environments; experience securing modern, cloud-native web platforms preferred.
-
Technical background sufficient to collaborate with system owners on design documentation.
Preferred Qualifications:
-
SME-level knowledge of NIST SP 800-137 (ISCM).
-
1+ years of technical experience with Python, Java, or PHP – sufficient to read, interpret, and understand code to independently verify control implementation and evaluate technical alternate solutions for complex NIST requirements.
-
1+ year of experience with a GRC tool (such as CSAM).
-
Experience with Q-Compliance and/or Q-Audit.
-
Experience with API testing (REST APIs), JSON payload security, and/or scripting and automation.
-
Relevant industry certifications (e.g., CISA, CAP, CISSP, Security+).
Clearance Requirements:
-
Must be a U.S. Citizen with the ability to obtain and maintain a Public Trust clearance prior to starting this position.
Physical Requirements:
-
Must be able to remain in a stationary position 50% and constantly operate a computer and other office productivity machinery, such as a calculator, copy machine and computer printer.