Information Security Officer

Strategic Operational Solutions

  • Washington, DC
  • 2 days ago
  • Full-time

Highlights

Responsibilities:Provide security advisory services and operational support to ensure a secure, compliant cloud data platform environment in Microsoft AzureSupport implementation and enforcement of federal security requirements including FISMA, NIST SP 800-53, FedRAMP, OMB, and DHS guidanceLead security architecture and design activities including Zero Trust implementation, RBAC/ABAC access control, encryption, and identity integrationOversee Authority to Operate (ATO) processes, including development of security documentation, control assessments, and coordination with Authorizing Officials and OCIOConduct continuous monitoring activities including vulnerability scanning, compliance checks, audit logging, and security metrics reportingIdentify, assess, and mitigate security risks, including managing POA&Ms, audit findings, and system vulnerabilitiesEnsure proper data protection controls including encryption in transit and at rest, key management, data classification, and privacy compliance for PII/CUI/PHISupport incident response activities including detection, reporting, investigation, forensics, and remediation in coordination with FTC CSIRTDevelop and maintain security documentation including risk assessments, system security plans, POA&Ms, and compliance artifactsProvide cybersecurity input to cloud engineering efforts such as identity integration (Entra ID), SIEM integration (Microsoft Sentinel), and secure data pipeline configurationsConduct vulnerability assessments, penetration testing coordination, and supply chain risk assessments for cloud services and toolsCollaborate with program management, engineering, and data teams to ensure security is integrated across all solution componentsServe as the designated Information System Security Officer (ISSO) and act as a primary point of contact for security-related audits, data calls, and compliance reviewsMinimum QualificationsBachelor's or Master's degree in Cybersecurity, Information Technology, Computer Science, or related fieldMinimum 5 years of experience in information security, including federal cloud security environments of similar scope and complexityProven experience supporting ATO/ATU processes and continuous monitoring in government environmentsExperience securing cloud environments, preferably Microsoft Azure, including identity, networking, and data protection controlsHands-on experience with vulnerability management, incident response, and risk assessment processesAbility to obtain and maintain a Public Trust clearance and comply with federal security training requirementsRequired Certifications:Certified Information Systems Security Professional (CISSP) CertificationCertified Cloud Security Professional (CCSP) CertificationCompTIA Cloud+ CertificationSkills and CompetenciesStrong background in network security, threat detection, and vulnerability managementIn-depth knowledge of securing cloud environments (e.g., Microsoft Azure) and services related to big dataProficiency in data encryption, masking, anonymization, and data loss preventionSpecific expertise in securing large-scale data systemsProven experience in handling security incidents from detection and analysis to recovery and post-incident reportingDeep knowledge of federal cybersecurity frameworks, including NIST SP 800-53, NIST SP 800-207 (Zero Trust), and FedRAMP requirementsProficiency in security technologies including SIEM tools (e.g., Microsoft Sentinel), identity and access management (Entra ID), and vulnerability scanning toolsExperience implementing least privilege access, RBAC/ABAC models, and secure identity federationAbility to analyze complex security risks and develop actionable mitigation strategiesFamiliarity with large-scale data systems, analytics platforms, and securing structured/unstructured data environmentsExcellent written and verbal communication skills, including the ability to produce detailed security documentation and reportsStrong collaboration skills with cross-functional technical teams and government stakeholdersAbility to manage multiple priorities in a compliance-driven, high-security federal environmentJob Type: Full-timeWork Location: In person. All work performed under this contract shall take place at the following locations:Federal Trade Commission Headquarters 600 Pennsylvania Avenue, NW Washington DC 20580Federal Trade Commission GAO Building 441 G Street NW Washington DC 20548

Numbers & Facts

LocationWashington, DC
Job TypeFull-time

Description

Brief Overview of Position:Strategic Operational Solutions (STOPSO) is seeking candidates for an Information Security Officer role to support a federal client where we are focused on delivering innovative operations and solutions through proven successful methods. This individual is responsible for the planning, execution, and delivery of all program activities supporting the project. The Information Security Officer will ensure STOPSO provides advisory services, operational assistance for Government-managed and licensed components, and the expertise necessary to ensure secure and compliant operations. Responsibilities:Provide security advisory services and operational support to ensure a secure, compliant cloud data platform environment in Microsoft AzureSupport implementation and enforcement of federal security requirements including FISMA, NIST SP 800-53, FedRAMP, OMB, and DHS guidanceLead security architecture and design activities including Zero Trust implementation, RBAC/ABAC access control, encryption, and identity integrationOversee Authority to Operate (ATO) processes, including development of security documentation, control assessments, and coordination with Authorizing Officials and OCIOConduct continuous monitoring activities including vulnerability scanning, compliance checks, audit logging, and security metrics reportingIdentify, assess, and mitigate security risks, including managing POA&Ms, audit findings, and system vulnerabilitiesEnsure proper data protection controls including encryption in transit and at rest, key management, data classification, and privacy compliance for PII/CUI/PHISupport incident response activities including detection, reporting, investigation, forensics, and remediation in coordination with FTC CSIRTDevelop and maintain security documentation including risk assessments, system security plans, POA&Ms, and compliance artifactsProvide cybersecurity input to cloud engineering efforts such as identity integration (Entra ID), SIEM integration (Microsoft Sentinel), and secure data pipeline configurationsConduct vulnerability assessments, penetration testing coordination, and supply chain risk assessments for cloud services and toolsCollaborate with program management, engineering, and data teams to ensure security is integrated across all solution componentsServe as the designated Information System Security Officer (ISSO) and act as a primary point of contact for security-related audits, data calls, and compliance reviewsMinimum QualificationsBachelor's or Master's degree in Cybersecurity, Information Technology, Computer Science, or related fieldMinimum 5 years of experience in information security, including federal cloud security environments of similar scope and complexityProven experience supporting ATO/ATU processes and continuous monitoring in government environmentsExperience securing cloud environments, preferably Microsoft Azure, including identity, networking, and data protection controlsHands-on experience with vulnerability management, incident response, and risk assessment processesAbility to obtain and maintain a Public Trust clearance and comply with federal security training requirementsRequired Certifications:Certified Information Systems Security Professional (CISSP) CertificationCertified Cloud Security Professional (CCSP) CertificationCompTIA Cloud+ CertificationSkills and CompetenciesStrong background in network security, threat detection, and vulnerability managementIn-depth knowledge of securing cloud environments (e.g., Microsoft Azure) and services related to big dataProficiency in data encryption, masking, anonymization, and data loss preventionSpecific expertise in securing large-scale data systemsProven experience in handling security incidents from detection and analysis to recovery and post-incident reportingDeep knowledge of federal cybersecurity frameworks, including NIST SP 800-53, NIST SP 800-207 (Zero Trust), and FedRAMP requirementsProficiency in security technologies including SIEM tools (e.g., Microsoft Sentinel), identity and access management (Entra ID), and vulnerability scanning toolsExperience implementing least privilege access, RBAC/ABAC models, and secure identity federationAbility to analyze complex security risks and develop actionable mitigation strategiesFamiliarity with large-scale data systems, analytics platforms, and securing structured/unstructured data environmentsExcellent written and verbal communication skills, including the ability to produce detailed security documentation and reportsStrong collaboration skills with cross-functional technical teams and government stakeholdersAbility to manage multiple priorities in a compliance-driven, high-security federal environmentJob Type: Full-timeWork Location: In person. All work performed under this contract shall take place at the following locations:Federal Trade Commission Headquarters 600 Pennsylvania Avenue, NW Washington DC 20580Federal Trade Commission GAO Building 441 G Street NW Washington DC 20548

Similar Jobs

See more jobs