We use cookies. Find out more about it here. By continuing to browse this site you are agreeing to our use of cookies.
#alert
Back to search results
New

Information System Security Officer

ANALYGENCE
United States, D.C., Washington
Oct 01, 2026

Tharros supports the Department of Homeland Security (DHS) with cybersecurity services across its Intelligence Enterprise.

In support of this mission, we have an immediate opportunity for an Information System Security Officer (ISSO). In this role you will independently own the security posture of a portfolio of DHS Intelligence Enterprise systems, including Cross Domain Solutions and cloud-hosted systems, in accordance with ICD 503 and DHS 4300C. You will maintain ATO packages, manage POA&Ms and change control, and serve as a SCIF Information Security Compliance Representative (ISCR). This position is on-site in a Government SCIF in Washington, DC.

Duties include but not limited to:


  • Create and maintain ATO packages for assigned systems in the GRC tool and monitor their compliance.
  • Perform self-assessments of assigned on-premise and cloud systems against the A&A SOP.
  • Manage POA&Ms, waivers, and risk exceptions; provide weekly or bi-weekly activity reports.
  • Perform audit log reviews at least weekly, respond to NOSC alerts, and ensure periodic scanning.
  • Coordinate system changes through IATT requests and serve on the Configuration Management Board when designated.
  • Facilitate annual contingency plan tests and submit quarterly CPEM reporting.
  • Deliver ISSO reports (incident response, POA&M, ConMon metrics) to ISSMs and system owners.
  • Serve as SCIF ISCR and mentor junior ISSOs.
  • BS degree in Information Technology, Cybersecurity, Information Systems, or Computer Science OR minimum of 6 years' experience in IT or cybersecurity.
  • Minimum of 3 years' experience as an ISSO or in RMF package ownership.
  • Active TS/SCI clearance and U.S. citizenship; willingness to undergo a DHS counterintelligence-scope polygraph.
  • Knowledge of the Risk Management Framework (RMF), NIST SP 800-37, NIST SP 800-53, and ICD 503.
  • Knowledge of Cross Domain Solution engineering and governance, including NCDSMO mandates and Raise the Bar requirements.
  • Knowledge of hybrid classified/unclassified, on-premise and cloud environments, DevSecOps, and agile methodologies.
  • Skill in securing Linux and Windows operating systems and cloud technologies.
  • Skill in managing change control and authorization impacts.
  • Ability to independently manage a portfolio of systems.
  • Proficient in Microsoft Office Suite to include Teams or similar workplace chat and videoconferencing tools.
  • Excellent written and oral communications skills.

Desired


  • CGRC (formerly CAP), CompTIA Security+, or CySA+ certification.
  • Experience with RSA Archer, eMASS, or a similar GRC tool.
Applied = 0

(web-9db6c7984-p2wxp)