
Information System Security Officer (ISSO) Manager
Rosslyn, VAJob$138–278K/yrSeen todaySeen in employer's feed today
Most applications go out cold — see where you stand first. No sign-up to start.
Watch jobs like this. New roles like this one near Rosslyn, VA, by email.
Don't just apply. Show up ready.
Olive works from this exact posting.
At a glance
Olive lists jobs from US employers, including remote roles you can work from the United States.
Requirements
Credentials this posting asks for.
Job overview
Deloitte’s Cyber team is hiring an Information System Security Officer (ISSO) Manager to support federal and other government clients. The role serves as ISSO for designated systems, leads authorization and assessment activities, and coordinates vulnerability remediation, continuous monitoring, and incident response. The successful candidate brings experience with federal security frameworks and GRC tools, holds an active Top Secret clearance, and works onsite five days a week at a client site in Washington, D.C.
Skills & qualifications
Skills
Qualifications
Full job description
Our Deloitte Cyber team understands the unique challenges and opportunities businesses face in cybersecurity. Join our team to deliver powerful solutions to help our clients navigate the ever-changing threat landscape. Through powerful solutions and managed services that simplify complexity, we enable our clients to operate with resilience, grow with confidence, and proactively manage to secure success.
Work You'll Do
As a Project Information System Security Officer (ISSO) Manager, Strategy, Growth and Transformation on the Deloitte Cyber Team, you will:
-
Serve as the ISSO for designated information systems, maintaining System Security Plans (SSPs) and authorization documentation
-
Lead ATO activities including, system categorization, security documentation development, control implementation, compliance, remediation action tracking, continuous monitoring, and security maturity activities
-
Coordinate vulnerability and compliance assessments, review findings, and track remediation activities with system owners and technical stakeholders
-
Monitor security control implementation, system integrity and prepare systems for assessments.
-
Coordinate security incident response activities, communicate risk and compliance status, and support security governance and awareness efforts
A successful candidate would possess these skills:
-
Strong technical skills and experience with IT and Operational Technology, both on-premise and in the cloud including FedRAMP
-
Advanced experience with all steps within the NIST Risk Management Framework (RMF).
-
Extensive experience with selecting, tailoring, implementing, assessing, and monitoring NIST SP 800-53 controls
-
Advanced experience with governance, risk and compliance (GRC) solutions such as JCAM and OpenRMF
-
Ability to work independently and collaborate as part of a team
-
Effective written and verbal communication skills
-
Meticulous attention to detail and quality of work product
-
Ability to build and sustain professional relationships
-
Ability to lead projects or workstreams
-
Ability to manage and prioritize multiple tasks in a fast-paced and dynamic environment
-
Strong interpersonal skills and professional demeanor
-
Ability to meet deadlines
-
Ability to provide clear guidance to others
The Team
Deloitte's Government & Public Services (GPS) practice - our people, ideas, technology and outcomes - is designed for impact. Serving federal, state, & local government clients as well as public higher education institutions, our team of professionals brings fresh perspective to help clients anticipate disruption, reimagine the possible, and fulfill their mission promise.
Our Cyber Strategy & Transformation offering develops and transforms cyber programs in line with a client's strategic objectives, regulatory requirements, and risk appetite. It keeps the enterprise a step ahead of the evolving threat landscape and gives stakeholders confidence in the organization's cyber posture. Includes design of the cyber organization, governance, and risk assessments.
The Project Delivery Talent Model is designed for professionals with specialized skills that align to a current client need. Team members focus on delivering services to clients, without additional expectations related to business development or promotion. Their employment is tied to their role on a project, and they are eligible for a benefits package that is competitive for project delivery-focused professionals.
Qualifications
Required:
-
Bachelor's degree
-
Must be legally authorized to work in the United States without the need for employer sponsorship, now or at any time in the future
-
Active Top Secret (SCI Eligibility) security clearance required
-
Must be able to work onsite, 5 Days a week, at the client site in Washington, D.C.
-
7+ Years of Experience with the following:
-
Serving as an Information System Security Officer (ISSO) supporting U.S. Department of Defense (DoD) or Federal Government information systems
-
Performing security and compliance activities, including Security Assessment and Authorization (SA&A) activities and application of the NIST RMF
-
Using Nessus to perform vulnerability and compliance scanning and review vulnerability results
-
Developing, implementing and maintaining security policies, procedures, and standards
-
Experience supporting security governance processes and leveraging GRC solutions such as JCAM and OpenRMF
-
One of the following certifications:
-
Certified Information Systems Security Professional (CISSP) certification
-
Certified in Risk and Information Systems Control (CRISC) certification
Preferred:
-
Experience supporting operational mission systems
-
Experience preparing risk reports and security dashboards
For individuals assigned and/or hired to work in Virginia, Deloitte is required by law to include a reasonable estimate of the compensation range for this role. This compensation range is specific to Virginia and takes into account the wide range of factors that are considered in making compensation decisions including but not limited to skill sets; experience and training; licensure and certifications; and other business and organizational needs. At Deloitte, it is not typical for an individual to be hired at or near the top of the range for their role and compensation decisions are dependent on the facts and circumstances of each case. A reasonable estimate of the current range is $137,500 to $278,300.
You may also be eligible to participate in a discretionary annual incentive program, subject to the rules governing the program, whereby an award, if any, depends on various factors, including, without limitation, individual and organizational performance.
All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, age, disability or protected veteran status, or any other legally protected basis, in accordance with applicable law.
Similar jobs, posted recently
Open roles like this one, listed in the last 30 days.
Cybersecurity - Information System Security Manager (ISSM)The Boeing Company · Herndon, VA · $140–190K/yrPosted 5 days agoPosted 5 days agoDeputy Chief Information OfficerOffice of the Secretary of Health and Human Services · Washington, DC · $152–228K/yrPosted 1w agoPosted 1w ago
Aviation Security Watch OfficerFederal Aviation Administration · Washington, DC · $104–161K/yrPosted 5 days agoPosted 5 days ago
Information Technology Specialist (Security)Architect of the Capitol · Washington, DC · $144–187K/yrPosted 1w agoPosted 1w ago
Chief Information OfficerOffice of Special Counsel · Washington, DC · $169–197K/yrPosted 2 days agoPosted 2 days ago
You've read the whole posting — now see how you match it.