NikSoft Systems Corp.

Information System Security Officer (Cybersecurity Assessment & Authorization)

NikSoft Systems Corp. · Falls Church, Virginia, United States

IT Services and IT Consulting · 51-200 employees

19 h ago
Senior (5-10 yrs) Full-time United States
Log in to apply, save this posting, or score it against your profile with AI.

About the role

The Information System Security Officer will lead security assessments, manage A&A processes, and design secure enterprise IT architectures. They will also act as a subject matter expert to guide stakeholders and brief leadership on IT risk and assurance initiatives.

What they look for

NIST RMF ISO Frameworks Governance Risk and Compliance Security Architecture Vulnerability Scanning Network Scanning Information Assurance Risk Management Cloud Computing Compliance Documentation Project Management Executive Briefing CISSP CISM CGRC

Requirements

Candidates must have at least 5 years of experience in Cybersecurity Assessment & Authorization or Risk Management Framework environments. A bachelor's degree in a related field and a high-level security certification such as CISSP, CISM, or CGRC are required.

Full description

Opened to U.S. Citizen and/or Green card holders only.

NikSoft Systems Corporation is a recognized Information Technology solutions provider. Founded in 1998 and based in Reston, Virginia, NikSoft is a CMMI Level 3 Certified company with an established reputation for excellence and on-time delivery with a consistently high customer satisfaction rating from its Federal Government and private consulting contracts.

Position Overview

We are seeking an Information System Security Officer (Cybersecurity Assessment & Authorization). You will support security assessments for diverse application domains, including cloud computing environments. This critical role serves as the primary Subject Matter Expert (SME) for the A&A process, managing large-scale, high-risk security compliance and architecture initiatives.

Key Responsibilities

  • Lead Risk Assessments: Conduct security assessments and document compliance using NIST RMF and ISO frameworks.
  • Manage A&A Processes: Oversee validation, accreditation, and documentation utilizing Governance, Risk, and Compliance (GRC) tools.
  • Design Secure Architecture: Support blueprints, standards, and guidelines for secure enterprise IT infrastructures.
  • Conduct Vulnerability Scanning: Interrogate systems for configuration status using network and vulnerability scanning tools.
  • Act as A&A SME: Guide stakeholders, cross-functional business units, and new A&A resources through the USPS validation process.
  • Brief Leadership: Build action plans, manage schedules, and brief executives on cross-functional IT risk and assurance.

Required Qualifications

  • Framework Expertise: Proven proficiency with NIST Risk Management Framework (RMF) and ISO standards.
  • Technical Skills: Strong background in GRC systems, security architecture principles, and network scanning technologies.
  • Project Management: Track record of driving large, complex, and high-risk IT initiatives.
  • Soft Skills: Excellent organizational skills alongside senior-level executive briefing capabilities.

Experience, Education & Certifications

  • Experience: Minimum 5+ years of direct experience in Cybersecurity Assessment & Authorization (A&A), Information Assurance, or Risk Management Framework (RMF) environments.
  • Education: Bachelor's degree in Cybersecurity, Information Technology, Computer Science, or a related field (relevant senior-level experience may substitute for a degree).
  • Certifications: a current high-level security certification such as ICS2 CISSP (IAM Level III standard), ISACA CISM, or CGRC (Certified in Governance Risk and Compliance) preferred.

Opened to U.S. Citizen and/or Green card holders only.

****Candidates must be able to obtain a Postal Sensitive Clearance (US Citizenship or Green Card required). Additionally, candidates must not have traveled outside of the USA for a combined period not to exceed 6 months within the last 3 years.***