*Work with Progression, Inc. get your application bumped to the front of the line*
ISSO
Herndon, VA
$150k + benefits
MUST:
Active TS/SCI clearance with SCI eligibility and ability to pass a CI/scope polygraph
Experienced Information Systems Security Officer (ISSO)
10 years overall IT / Cyber Security
5 - 7 years direct ISSO experience
Hands-on DoD Risk Management Framework (RMF) experience supporting ATO efforts
Expertise with NIST SP 800-53 and NIST SP 800-53A security controls
Experience with AFPD 17-1 and AFI 17-130
Hands-on experience using Xacta to manage RMF workflows, security controls, implementation tabs, risk assessments, POA&Ms, and non-compliant controls
Experience drafting and maintaining ATO Body of Evidence documentation including SSPs, SARs, Contingency Plans, and Continuous Monitoring artifacts
Experience writing Security Test Procedures (STPs) and building Security Controls Traceability Matrices (SCTMs)
STIG and SCAP implementation and remediation experience across operating systems, applications, and infrastructure
ACAS/Nessus vulnerability scanning and analysis experience
Splunk log analysis experience to validate security controls, investigate anomalies, and verify control effectiveness
Experience conducting cybersecurity risk assessments and monitoring security events
Incident response experience including log review, investigations, containment, evidence preservation, and post-incident activities
Ability to translate security requirements into clear and testable implementation guidance for engineering teams
Ability to communicate technical risks and findings to system owners, government stakeholders, and leadership
Ability to execute technical tasks independently with minimal oversight
DoD 8570 IAM-II compliant certification such as Security+, CISSP, or CISM
Bachelor's degree in relevant technical field OR equivalent qualifying experience required (6 years in specific cyber field and bachelors or subbed for 10 years & no degree)
DUTIES:
Draft, review, and maintain Body of Evidence components for DoD ATO packages
Develop and refine security control implementation statements across all control families
Ensure Security Authorization Process documentation complies with federal and DoD requirements
Maintain system security documentation and execute RMF workflows within Xacta
Manage POA&M entries, supporting evidence, remediation tracking, and close-outs
Interpret STIG and SCAP findings and coordinate remediation with system administrators and developers
Conduct and analyze ACAS/Nessus vulnerability scans
Validate vulnerability findings with engineering teams and track remediation through closure
Perform Splunk log analysis to validate security control operation and effectiveness
Investigate security anomalies and support technical security assessments
Develop Security Test Procedures and Security Controls Traceability Matrices
Translate cybersecurity requirements into actionable implementation guidance for engineering teams
Support incident response investigations, containment actions, evidence preservation, and lessons learned
Conduct cybersecurity risk assessments and continuous monitoring activities
Support system owners and engineering teams throughout RMF and ATO processes
Communicate technical risks, vulnerabilities, findings, and required actions to government stakeholders and leadership
Participate in security meetings, external audits, assessments, and authorization activities
Support Security Control Assessor activities as needed
Support secure classified and high-side environments
*Progression Inc. is an affirmative action/equal opportunity employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, status as a protected veteran, or status as an individual with a disability.* #INDPRO