ISSO Specialist
Job description
ISSO Specialist at Bamboohr.
About the role
Bamboohr is seeking an Information System Security Officer (ISSO) Specialist to join our dynamic team in Washington, District of Columbia. This full-time position is crucial for ensuring the security and integrity of our information systems. As an ISSO Specialist, you will be responsible for implementing and maintaining security protocols, conducting risk assessments, and ensuring compliance with federal regulations. You will work closely with various stakeholders to safeguard sensitive information and support the organization's mission through effective security practices.
Key facts
What you'll do
- Develop, implement, and manage security policies and procedures to protect the organization's information systems from unauthorized access or breaches.
- Conduct comprehensive risk assessments to identify vulnerabilities and recommend appropriate mitigation strategies.
- Monitor security controls and systems to ensure compliance with federal regulations and industry standards, including NIST and FISMA.
- Collaborate with IT teams to ensure that security measures are integrated into the system development lifecycle.
- Provide guidance and support to staff on security best practices and incident response protocols.
- Prepare and maintain documentation related to security policies, procedures, and incident reports.
- Conduct regular security training sessions for employees to raise awareness about potential threats and security measures.
- Respond to security incidents and breaches, coordinating with relevant teams to investigate and resolve issues promptly.
- Stay updated on the latest security trends, threats, and technologies to enhance the organization's security posture.
- Assist in the preparation for audits and assessments by external entities to demonstrate compliance with security standards.
- Participate in the development of disaster recovery and business continuity plans to ensure the organization can maintain operations during a security incident.
- Engage with external partners and stakeholders to foster collaboration on security initiatives and share best practices.
Requirements
- Bachelor's degree in Computer Science, Information Technology, Cybersecurity, or a related field.
- A minimum of 3 years of experience in information security, risk management, or a related area.
- Strong understanding of security frameworks and compliance standards, such as NIST, FISMA, and ISO 27001.
- Proven experience in conducting risk assessments and vulnerability assessments.
- Familiarity with security tools and technologies, including firewalls, intrusion detection systems, and encryption methods.
- Excellent analytical and problem-solving skills, with the ability to think critically under pressure.
- Strong communication skills, both verbal and written, to effectively convey security concepts to technical and non-technical audiences.
- Ability to work independently and collaboratively within a team environment.
- Relevant certifications such as CISSP, CISM, or Security+ are preferred.
Nice to have
- Experience with cloud security practices and technologies.
- Knowledge of incident response and forensic investigation techniques.
- Familiarity with security automation tools and scripting languages.
- Previous experience in a government or defense contracting environment.
- Understanding of privacy regulations and data protection laws.
Skills & tools
- Proficient in security assessment tools, vulnerability scanners, and risk management software.
- Familiarity with network security protocols and technologies.
- Knowledge of operating systems, including Windows, Linux, and Unix, from a security perspective.
- Experience with security information and event management (SIEM) systems.
- Strong project management skills, with the ability to manage multiple tasks and deadlines effectively.
Practical notes
- This position is based in Washington, D.C., and may require occasional travel for training or conferences.
- The ISSO Specialist will report directly to the Chief Information Security Officer (CISO) and work closely with other IT and security personnel.
- Candidates must be eligible for a security clearance, which may require a background check.
- Bamboohr is committed to fostering a diverse and inclusive workplace, and we encourage applications from all qualified individuals.
META
Company: Bamboohr
Title: ISSO Specialist
Listed
location: Washington, District of Columbia
Job type: Full-time
Apply URL: https://technalink.bamboohr.com/careers/25