Information Systems Security Officer

Location

Massachusetts + 1 moreAll locations: Massachusetts | Pennsylvania

Posted

2 days ago

Salary

$92.2K - $125.1K / year

Seniority

Senior

Bachelor DegreeMicrosoft WordExcelAI

Job Description

Information Systems Security Officer

Contact Government Services

Title: Information Systems Security Officer ISSO Location: United States Job Description: Information Systems Security Officer (ISSO) Boston, MA | Remote | Hybrid Philadelphia, PA Information Technology Full Time Hybrid Apply for this job ISSO Employment Type: Full-Time Experienced Department: Information Technology CGS is seeking an Information Systems Security Officer (ISSO) with DIACAP and/or RMF experience who has deep expertise in security assessment documentation to support Dept. of Commerce systems and efforts to achieve their Authorization to Operate (ATO). This position is located at the client site in the Herbert Hoover building in Washington DC. The scope of this position includes full life-cycle Assessment and Authorization (A&A) management through all 6 Steps of the RMF process in support of the Government ISSM. In this role, youll conduct security assessment and information system security oversight activities in accordance with NIST 800.53 that support systems from the perspective RMF requirements. CGS brings motivated, highly skilled, and creative people together to solve the governments most dynamic problems with cutting-edge technology. To carry out our mission, we are seeking candidates who are excited to contribute to government innovation, appreciate collaboration, and can anticipate the needs of others. Here at CGS, we offer an environment in which our employees feel supported, and we encourage professional growth through various learning opportunities. Skills and attributes for success - Review systems to identify potential security weaknesses and recommend improvements to amend vulnerabilities, implement changes, and document upgrades. - Maintain responsibility for managing cybersecurity risk from an organizational perspective. - Identify organizational risks, prioritize those risks, and maintain a risk registry for escalating and presenting those risks to senior leadership. - Provide security guidance and IS validation using the National Institute of Standards and Technology (NIST) RMF, DoC, and local security policies. - Providing configuration management (CM) recommendations for information system security software, hardware, and firmware, and coordinating changes and modifications with the ISSM, Security Control Assessor (SCA), and Authorizing Official (AO). - Maintain vulnerability scanning tool compliance such as HBSS or ACAS and patch management such as IAVM to ensure IT staff pushes patches to all systems in an effort to maintain compliance with all applicable directives, manage system changes, and assess the security impact of those changes. - Support security authorization activities including transitioning from the legacy Information Assurance Certification and Accreditation Process (DIACAP) to compliance with the DoC RMF. - Provide subject matter expertise for cyber security and trusted system technology. - Apply advanced technical knowledge and analysis of specialized functional areas in task requirements to develop solutions to complex problems. - Research, write, review, disposition, feedback, and finalize recommendations regarding cyber security policy, assessment and authorization assessments (A&As), security test and evaluation reports, and security engineering practices and processes. - Conduct research and write risk assessment reports to include risk thresholds, evaluation, and scoring. - Support analysis of the findings and provide expert technical guidance for mitigation strategies, including implementation advice on the cyber security risk findings and other complex problems. Qualifications - Bachelors Degree. - A minimum of five (5) years experience as an Information Assurance (IA) Analyst, ISSE, ISSO, or similar role in ATO package development including generating security documentation for requirements, security control assessment, STIG and IAVA compliance, Standard Operating Procedures, test results, etc. - eMASS experience. - Professional security certification such as CCNA Security, CySA, GICSP, GSEC, CompTIA Security+, CE, SSCP, or higher. - Strong desktop publishing skills using Microsoft Word and Excel. - Experience with industry writing styles such as grammar, sentence form, and structure. - Ability to multi-task in a deadline-oriented environment. Ideally, you will also have - CISSP, CASP, or a similar certificate is preferred. - Masters Degree in Cybersecurity or related field. - Strong initiative, detail orientation, organizational skills, and aptitude for analytical thinking. - Demonstrated ability to work well independently and as a part of a team. - Excellent work ethic and a high commitment to quality. Our Commitment Contact Government Services (CGS) strives to simplify and enhance government bureaucracy through the optimization of human, technical, and financial resources. We combine cutting-edge technology with world-class personnel to deliver customized solutions that fit our clients specific needs. We are committed to solving the most challenging and dynamic problems. For the past seven years, weve been growing our government contracting portfolio, and along the way, weve created valuable partnerships by demonstrating a commitment to honesty, professionalism, and quality work. Here at CGS, we value honesty through hard work and self-awareness, professionalism in all we do, and to deliver the best quality to our consumers, mending those relations for years to come. We care about our employees. Therefore, we offer a comprehensive benefits package: - Health, Dental, and Vision - Life Insurance - 401k - Flexible Spending Account - Health, Dependent Care, and Commuter - Paid Time Off and Observance of State/Federal Holidays Contact Government Services LLC is an Equal Opportunity Employer. Applicants will be considered without regard to their race, color, religion, sex, sexual orientation, gender identity, national origin, disability, or status as a protected veteran. Join our team and become part of government innovation. Explore additional job opportunities with CGS on our Job Board: https://cgsfederal.com/join-our-team For more information about CGS, please visit https://www.cgsfederal.com or contact Email: emailprotected CJ92213.33 - $125,146.66 a year We may use artificial intelligence (AI) tools to support parts of the hiring process, such as reviewing applications, analyzing resumes, or assessing responses. These tools assist our recruitment team but do not replace human judgment. Final hiring decisions are ultimately made by humans.

Related Categories

Related Job Pages

More Security Engineer Jobs

Sport Alliance GmbH logo

Platform and Security Engineer

Sport Alliance GmbH

Digitalization of the fitness industry - Leading service provider for SaaS, Fintech, and lead generation.

Full TimeRemoteTeam 201-500Since 2011H1B No Sponsor

• Developer-Driven SecOps: Leverage your programming background to transition manual security and infrastructure processes into automated, self-service APIs and internal tooling, speaking the same language as our product engineers. • Platform Operations: Design, implement, and operate cloud infrastructure (primarily AWS) as a secure, reliable platform, enabling self-service for engineering teams to deploy and run applications. • Infrastructure Hardening: Apply defense-in-depth and zero-trust principles, implementing layered security controls across network, compute, identity, and data tiers. • Security Standards & Governance: Develop, document, and enforce security standards, guidelines, and hardening baselines for software development (SDLC) and platform operations, driving adoption across the organization. • Incident Response: Detect, triage, manage, and respond to cyber security incidents, owning the process from initial signal through resolution and post-mortem. • Hands-on Security Engineering: Actively address vulnerabilities, implement security features (WAF rules, SIEM monitors, access policies), and improve overall platform resilience. • Continuous Threat Review: Conduct ongoing reviews of security tooling (such as our CNAPP Wiz), processes, and controls in response to new threats, architecture changes, and internal risk assessments. • Harness Engineering: Extend and improve our tooling that supports the Agent-Harnesses to safeguard AI-assisted development workflows across the SDLC. • Stakeholder Collaboration: Coordinate, communicate, and align seamlessly with key stakeholders including the CTO, CISO, Engineering Managers, Tech Leads, and cross-functional product teams.

Poland
zł21K - zł26K / month
Deutsche Telekom IT Solutions logo

Information Security Risk Manager

Deutsche Telekom IT Solutions

As Hungary’s most attractive employer in 2025 (according to Randstad’s representative survey), Deutsche Telekom IT Solutions is a subsidiary of the Deutsche Telekom Group. The company provides a wide portfolio of IT and telecommunications services with more than 5300 employees. We have hundreds of large customers, corporations in Germany and in other European countries. DT-ITS received the Best in Educational Cooperation award from HIPA in 2019, acknowledged as the Most Ethical Multinational Company in 2019. The company continuously develops its four sites in Budapest, Debrecen, Pécs and Szeged and is looking for skilled IT professionals to join its team.

Full TimeRemoteTeam 5,001-10,000

Role Description As an Information Security Risk Manager, you will be part of a centralized information security governance team providing security risk management services across multiple Deutsche Telekom legal entities. The role focuses on operating and continuously improving the information security risk management framework, while supporting and enabling local risk managers through consultation, training, and professional use of GRC tools. You will contribute to transparent risk reporting, effective risk mitigation, and harmonized governance practices in a complex, multinational environment. - Operate and continuously improve the information security risk management process, methodologies, and related policies - Ensure alignment with group-level security standards and governance requirements - Support the integration of risk management into business and IT processes - Act as a trusted advisor for supported legal entities on information security risk topics - Train and upskill local risk managers on risk processes, methods, and policies - Provide hands-on guidance during risk identification, assessment, and treatment - Support professional usage of the GRC platform by local risk managers - Assist in risk creation, maintenance, and lifecycle management within the tool - Collect user feedback and represent business needs toward process and tool improvements - Identify, create, and manage information security risks in cooperation with stakeholders - Monitor and support risk mitigation actions, including follow-up on progress and effectiveness - Ensure risks are properly documented and audit-ready - Prepare and maintain Top 10 risk reports, quarterly risk summaries, and ad-hoc reports - Define, monitor, and analyze risk KPIs and metrics - Provide management with insights on risk trends and improvement areas Qualifications - Bachelor’s or Master’s degree in Information Security, Computer Science, Engineering, Business Informatics, or a related field - High-level English language knowledge (spoken and written) - At least mid-level German language proficiency - 3–7+ years of experience in Information Security / Cybersecurity / Risk Management / GRC roles - Experience in large enterprise or multinational environments - Strong understanding of information security risk management frameworks (e.g. ISO 27005, NIST RMF) - Knowledge of information security standards (e.g. ISO 27001, NIST, CIS) - Ability to apply security governance principles in practical, business-aligned ways - Strong communication and stakeholder management skills - Ability to explain security and risk topics in business-friendly language - Structured, proactive, and solution-oriented mindset Requirements - Experience in training, coaching, or enablement activities - Experience working in a shared service or internal consulting model is an advantage - CRISC, CISM, CISSP, COBIT, ITIL or similar governance-related certifications - Hands-on experience with GRC tools (e.g. ServiceNow, Archer, OneTrust, or similar) Benefits - *Please be informed that our remote working possibility is only available within Hungary due to European taxation regulation. Company Description As Hungary’s most attractive employer in 2025 (according to Randstad’s representative survey), Deutsche Telekom IT Solutions is a subsidiary of the Deutsche Telekom Group. The company provides a wide portfolio of IT and telecommunications services with more than 5300 employees. We have hundreds of large customers, corporations in Germany and in other European countries. DT-ITS received the Best in Educational Cooperation award from HIPA in 2019, acknowledged as the Most Ethical Multinational Company in 2019. The company continuously develops its four sites in Budapest, Debrecen, Pécs and Szeged and is looking for skilled IT professionals to join its team.

Hungary
Booz Allen Hamilton logo

Mission Security Engineer

Booz Allen Hamilton

Booz Allen Hamilton is an award-winning provider of strategic innovation, management consulting, technology, and engineering services. Founded in 1914, the comp

Titile: Mission Security Engineer Location: Lexington Park United States Full time job requisition id: R0239061 Job Description: The Opportunity: Everyone knows security needs to be "baked in" to a system architecture-you actually know how to bake it in. You can identify and implement ways to harden systems and reduce their attack surface. What if you could use your cyber engineering skills to design and develop secure systems for the Department of War? We're looking for a security engineer who can create solutions for the U.S. Navy that will withstand even the most advanced cyber threats. As a solutions architect at Booz Allen, you'll design secure systems to support critical operations. You'll coordinate work with our team to identify the right mix of tools and techniques to translate your client's IT needs and future goals into a plan that will enable secure and effective solutions. We need to come up with the best solutions, so you'll investigate new techniques, break free from the legacy model, and go where the industry is going. You'll lead the team through a critical approach to network design, providing alternatives and customizing solutions to maintain a balance of security and mission needs. Work with us as we protect and advance secure communications for our client's missions. Join us. The world can't wait. You Have: - 3+ years of experience with mission security methods, techniques, and systems - Experience analyzing engineering requirements, testing, and evaluation in lifecycle support of systems engineering and security disciplines, including Cybersecurity, Mission Security, Software Assurance, Supply Chain Risk Management, and Operations Security - Experience applying secure coding practices, securing operating systems, and virtualization - Ability to design security architectures based on requirements from the analysis of adversary threats and proposed countermeasures - Secret clearance - Bachelor's degree in Engineering, Mathematics, or Physics Nice If You Have: - Experience with Cross Domain Solutions (CDS) - Experience analyzing and directing modeling on proposed architectures in Cameo or MagicDraw - Experience with cryptographic algorithm implementation - Experience implementing and testing security countermeasures - Experience working with Security State of the Art (S-SOTA) technologies - Knowledge of Commercial-of-the-Shelf (COTS) FPGA security features - Master's degree in Engineering, Mathematics, or Physics Clearance: Applicants selected will be subject to a security investigation and may need to meet eligibility requirements for access to classified information; Secret clearance is required. Compensation At Booz Allen, we celebrate your contributions, provide you with opportunities and choices, and support your total well-being. Our offerings include health, life, disability, financial, and retirement benefits, as well as paid leave, professional development, tuition assistance, work-life programs, and dependent care. Our recognition awards program acknowledges employees for exceptional performance and superior demonstration of our values. Full-time and part-time employees working at least 20 hours a week on a regular basis are eligible to participate in Booz Allen's benefit programs. Individuals that do not meet the threshold are only eligible for select offerings, not inclusive of health benefits. We encourage you to learn more about our total benefits by visiting the Resource page on our Careers site and reviewing Our Employee Benefits page. Salary at Booz Allen is determined by various factors, including but not limited to location, the individual's particular combination of education, knowledge, skills, competencies, and experience, as well as contract-specific affordability and organizational requirements. The projected compensation range for this position is $86,900.00 to $198,000.00 (annualized USD). The estimate displayed represents the typical salary range for this position and is just one component of Booz Allen's total compensation package for employees. Identity Statement As part of the hiring process, we will ask you to complete an identity verification process that leverages advanced biometrics and artificial intelligence to ensure authenticity and protect against identity fraud. You are expected to be on camera during interviews and assessments. We reserve the right to take your picture to verify your identity and prevent fraud. Candidate AI Usage Policy AI is a part of our daily work at Booz Allen, and we are committed to the responsible and ethical use of AI tools. However, we want to ensure a fair candidate process based on your own skills and knowledge. As part of this commitment, the use of artificial intelligence (AI) or other tools to assist with responses during interviews (whether in-person or virtual) is prohibited unless permission is explicitly provided. Work Model Our people-first culture prioritizes the benefits of collaboration, whether it occurs in person or virtually. To support engagement and effective communication, employees working virtually are generally expected to have their cameras on during meetings. - Remote: If this position is listed as remote, there may still be occasions when you are required to work in person at a Booz Allen or customer facility. - Hybrid: If this position is listed as hybrid, you will be expected to work from a Booz Allen facility frequently, in alignment with leadership expectations and the needs of the role. You may also be required to work from or visit a customer facility. - Onsite: If this position is listed as onsite, work will primarily be performed at a Booz Allen office or customer facility, where employees will collaborate directly with colleagues and customers as required by the role. Commitment to Non-Discrimination All qualified applicants will receive consideration for employment without regard to disability, status as a protected veteran or any other status protected by applicable federal, state, local, or international law.

Maryland
$86.9K - $198K / year
Booz Allen Hamilton logo

Cybersecurity Engineer

Booz Allen Hamilton

Booz Allen Hamilton is an award-winning provider of strategic innovation, management consulting, technology, and engineering services. Founded in 1914, the comp

Cybersecurity Engineer Locations: Arlington, VA Annapolis Junction, MD time type Full time job requisition id R0238313 Cybersecurity Engineer The Opportunity: Everyone is trying to “harness the cloud,” but not everyone knows how to secure it. As a cloud security architect, you know how to assess and implement requirements that ensure the safety of information systems and protect them against intentional or inadvertent access or destruction. What if you could use your cloud security skills to improve one of the largest software factories in the DoD? We need you to help us develop cloud-based security architectures for some of the most critical systems. As a Cybersecurity Engineer on our team, you’ll be responsible for operating, securing, and monitoring the cloud infrastructure, including system hardening, patching, and vulnerability management. You'll be responsible for understanding and translating the DoD requirements from the stakeholders to the technical teams and ensuring the solutions have met the requirements. This is an opportunity to use the latest cloud technologies as you look for ways to secure your customer’s environment. You’ll sharpen your skills in automation of security events, cloud-based security, and zero-trust architecture while building peace of mind in critical infrastructure. Help us transform and secure the software delivery to a state-of-the-art multirole warfighter with cloud technology. Join us. The world can’t wait. You Have: - Experience securing cloud infrastructure and applications in AWS GovCloud - Experience with Authority to Operate (ATO) and DoD Cloud SRG requirements - Experience with CMMC authorizations - Knowledge of centralized logging, boundary defense, web app firewalls, system patching, RBAC, and vulnerability scanning​ - Secret clearance - Bachelor’s degree - DoD 8570 IAT Level II or IAT Level III Certification Nice If You Have: - Experience with scripting languages, including PowerShell, Bash, or Python - Experience writing documentation - Knowledge of the cybersecurity risk management process and cybersecurity tools used in DoD environments - Knowledge of governance, risk, and compliance strategies and tools - HBSS or ACAS Certification - AWS Certifications Clearance: Applicants selected will be subject to a security investigation and may need to meet eligibility requirements for access to classified information; Secret clearance is required. Compensation At Booz Allen, we celebrate your contributions, provide you with opportunities and choices, and support your total well-being. Our offerings include health, life, disability, financial, and retirement benefits, as well as paid leave, professional development, tuition assistance, work-life programs, and dependent care. Our recognition awards program acknowledges employees for exceptional performance and superior demonstration of our values. Full-time and part-time employees working at least 20 hours a week on a regular basis are eligible to participate in Booz Allen’s benefit programs. Individuals that do not meet the threshold are only eligible for select offerings, not inclusive of health benefits. We encourage you to learn more about our total benefits by visiting the Resource page on our Careers site and reviewing Our Employee Benefits page. Salary at Booz Allen is determined by various factors, including but not limited to location, the individual’s particular combination of education, knowledge, skills, competencies, and experience, as well as contract-specific affordability and organizational requirements. The projected compensation range for this position is $62,000.00 to $141,000.00 (annualized USD). The estimate displayed represents the typical salary range for this position and is just one component of Booz Allen’s total compensation package for employees. This posting will close within 90 days from the Posting Date. Identity Statement As part of the hiring process, we will ask you to complete an identity verification process that leverages advanced biometrics and artificial intelligence to ensure authenticity and protect against identity fraud. You are expected to be on camera during interviews and assessments. We reserve the right to take your picture to verify your identity and prevent fraud. Candidate AI Usage Policy AI is a part of our daily work at Booz Allen, and we are committed to the responsible and ethical use of AI tools. However, we want to ensure a fair candidate process based on your own skills and knowledge. As part of this commitment, the use of artificial intelligence (AI) or other tools to assist with responses during interviews (whether in-person or virtual) is prohibited unless permission is explicitly provided. Work Model Our people-first culture prioritizes the benefits of collaboration, whether it occurs in person or virtually. To support engagement and effective communication, employees working virtually are generally expected to have their cameras on during meetings. - Remote: If this position is listed as remote, there may still be occasions when you are required to work in person at a Booz Allen or customer facility. - Hybrid: If this position is listed as hybrid, you will be expected to work from a Booz Allen facility frequently, in alignment with leadership expectations and the needs of the role. You may also be required to work from or visit a customer facility. - Onsite: If this position is listed as onsite, work will primarily be performed at a Booz Allen office or customer facility, where employees will collaborate directly with colleagues and customers as required by the role. Commitment to Non-Discrimination All qualified applicants will receive consideration for employment without regard to disability, status as a protected veteran or any other status protected by applicable federal, state, local, or international law.

Virginia + 1 moreAll locations: Virginia | Maryland
$62K - $141K / year