Enter a job title or keyword

ISSOControl Evaluator


Job Location:

Washington, DC - USA

Monthly Salary: Not provided by the employer
Posted: 30 August 2026 (14 days ago)
Application Deadline: 27 November 2026
Vacancies: 1 Vacancy

Job Summary

Koniag Data Solutions a Koniag Government Services company is seeking an experiencedInformation System Security Officer (ISSO) / Control Evaluatorto support a comprehensive enterprise cybersecurity services engagement for a federal civilian agency. This position requires the ability to obtain and maintain a government background investigation commensurate with a Moderate Risk designation (Minimum Background Investigation or higher) and applicable system access authorizations prior to performing work. Work will be performed primarily at the clients facility located in Washington DC with potential for hybrid/remote arrangements as offer competitive compensation and an extraordinary benefits package including health dental and vision insurance 401K with company matching flexible spending accounts paid holidays three weeks paid time off and role sits within the Information Security Division (ISD) and supports the agencys Risk Management Framework (RMF) program FISMA compliance obligations continuous monitoring activities and security controls assessment and evaluation functions across a diverse portfolio of on-premises cloud-hosted and hybrid information ideal candidate is a technically proficient and operationally experienced cybersecurity professional with a deep understanding of NIST security frameworks federal information security policy security assessment methodologies and the practical application of security controls across complex multi-technology enterprise environments. This individual must possess the ability to develop and maintain in-depth technical knowledge of assigned systems build trusted relationships with system owners and stakeholders and independently execute a broad range of ISSO responsibilities with minimal Government ISSO / Control Evaluator is responsible for providing comprehensive information system security officer support and security controls assessment and evaluation services across an assigned portfolio of federal information systems. This individual develops and sustains in-depth technical operational and working-level expertise about each assigned system advocates for system owner needs as they align to cybersecurity and privacy requirements and ensures each system maintains its authorization to operate in accordance with federal and agency security policies and role requires active participation in the agencys enterprise change control processes continuous monitoring activities Ongoing Authorization (OA) programs and audit support functions as well as contributions to automation visualization and data structure efforts that provide real-time visibility into control status and security posture across the responsibilities will include but are not limited to:ISSO Core ResponsibilitiesDevelop and sustain in-depth technical operational and working-level expertise about all assigned information systems including thorough knowledge of system architecture assets data flows operational environment management hierarchy and how each system fits into the broader enterprise IT and maintain a professional rapport and trusted working relationship with system owners program offices and technical support personnel for all assigned systems understanding their operational needs and advocating for those needs as they align to cybersecurity and privacy absorb and maintain current familiarity with all available system documentation for assigned systems including System Security Plans (SSPs) topology diagrams architecture diagrams and data flow access to and gain increasing proficiency with the operational tools administrative consoles and enterprise cybersecurity platforms used to manage and monitor assigned systems extracting meaningful data to produce continuously updated control status visualizations and assigned systems are onboarded into enterprise tools and reporting mechanisms including the agencys Governance Risk and Compliance (GRC) tool in accordance with established procedures and participate in the weekly Enterprise Change Control Board (ECCB) process ensuring security impacts of proposed changes are evaluated and documented for all assigned current awareness of all active Acceptance of Risk (AOR) documents for assigned systems ensuring resubmission for approval before knowledge management services for all accreditation-related artifacts including appointment orders Authority to Operate (ATO) documentation AORs Memoranda of Understanding/Agreement and Data Sharing Agreements ensuring all documents are organized and accessible in the designated central SupportCreate update revise and maintain cybersecurity and privacy documentation for all assigned systems across the enterprise ensuring all documentation is aligned to applicable agency implementation procedures and reviewed for acceptance by the Office of the and maintain the following documentation types among others:System Security Plans (SSPs) with detailed technology-specific control implementation descriptions for all technologies within the system boundaryConfiguration Management Plans (CMPs)Information System Contingency Plans (ISCPs) and Contingency Plan Test Reports (ISCP-TRs)E-authentication Risk Assessments (ERAs)User recertification documentationArchitecture topology and data flow diagrams (OV-1 and SV-1 equivalent)Ensure all control implementation descriptions are written to a level of detail that demonstrates how each control is specifically implemented across all technologies within the system boundary avoiding high-level generalizations or simple restatement of NIST control all Government comments edits and questions on documentation within 10 business days of receipt and escalate stakeholder unresponsiveness to the Government POC after 10 business days without selected policy and procedure documents are delivered in both Adobe and Word formats and are Section 508 accessibility remediated as Assessment and Evaluation SupportProvide security and privacy controls assessment and continuous monitoring assessment support for all assigned systems including testing and validation of NIST SP 800-53 controls documentation of NIST SP 800-53A Determine If Statements (DISs) and mapping of vulnerabilities to applicable draft Security and Risk Assessment Plans (SAPs) for delivery not less than 10 business days prior to beginning an assessment and draft Security and Risk Assessment Reports (SARs) and Plan of Action and Milestones (POAMs) within 30 business days from point-in-time assessment technical control assessments across all technology types within the system boundary (e.g. Windows UNIX Cisco F5 Load Balancer) including sampling across in-scope devices users and services ensuring assessments are comprehensive to the scope identified in the SAP and 100% aligned to the GRC and deliver Annual Assessment Reports (AARs) per in-scope system within 120 business days from point-in-time annual assessment kick-off and multi-year assessment reports in accordance with applicable all Government feedback into revised deliverables within 5 business days of receipt of comments ensuring final deliverables are comprehensive peer-reviewed and aligned to agency assessment reports that include visual representation against the NIST Cybersecurity Framework (CSF) and are comprehensive to the scope identified in the Authorization (OA) Evaluation SupportFor systems approved for Ongoing Authorization (OA) develop and submit an OA Playbook to the agency for approval including a documented testing methodology for each OA core control covering Test Strategy Test Design Test Execution Results Evaluation and OA Positive Testing monthly in accordance with agency implementation procedures documenting all results in the agency GRC OA Negative Testing annually in accordance with agency implementation procedures coordinating with penetration testing resources as necessary to execute negative test OA testing comprehensively across the technology stack of each target system documenting results in detail within the GRC tool in a clear and concise Reporting SupportCollect compile validate and submit FISMA reporting metrics for all assigned systems and programs leveraging automation to the greatest degree possible to ensure accuracy and completeness of collected to the consolidated FISMA metrics reports ensuring data is mathematically accurate and representative of the total agency FISMA inventory delivered for Government review not later than 10 business days prior to submission due the development and maintenance of dynamically updatable FISMA metrics visualizations and dashboards that pull data directly or indirectly from collected SupportSupport and facilitate internal and external audits of assigned FISMA systems including audits conducted by the Inspector General (IG) General Accountability Office (GAO) and internal audit meetings and walkthroughs coordinate with relevant support personnel supply auditors with requested artifacts and respond to follow-up questions in accordance with auditors schedules and SOC reports are received from program offices for audit purposes as required and that all audit artifacts are delivered on time reviewable by the Government and minimizing repeated requests from Value Asset (HVA) Assessment SupportComplete CISAs on-demand High Value Assets Assessment 3.0 (HVA 3.0) Training and provide course completion certificate to the Information System Security Manager (ISSM).Develop maintain and regularly update the agency HVA inventory list at least annually and incorporate HVA activities into broader IT and information security and privacy management planning categorize and prioritize HVAs implement and validate required security controls identify HVA connections and dependencies and support timely remediation of HVA assessment findings in accordance with established plans milestones and Continuous Monitoring (CONMON) SupportFacilitate monthly FedRAMP CONMON meetings with applicable stakeholders for assigned systems maintaining a general understanding of each system to provide appropriate guidance and comments to Cloud Service Providers (CSPs).Review vulnerability penetration test and ad hoc reporting from CSPs ensuring vendor actions pose no security risks to the enterprise and review and approve major changes when required by the Visualization and Data Structures SupportDesign construct automate and maintain visualizations (dashboards) and underlying data structures that reflect the status or effectiveness of security controls monitoring status capabilities and metrics for assigned continuous feeds from enterprise cybersecurity tools (typically in .csv format) using scripting or other automation techniques to construct visualizations that reflect the status or effectiveness of monitored maintain and document the underlying data structures supporting all visualizations including all Extract-Transform-Load (ETL) requirements data intake and data normalization approved visualizations available via the agency intranet portal ensuring they are updated automatically on a continual basis or refreshed on at least a weekly schedule as Risk Management (ERM) SupportMaintain cybersecurity and privacy risk registers for assigned systems ensuring they are updated monthly and available via online visualization and internal web the Factor Analysis of Information Risk (FAIR) methodology to assist in quantifying risk and support the integration of cybersecurity and privacy risks into the agency ERM Risk Register as major risks related to cybersecurity privacy theft of information and sensitive information protection (both internal and external threats) and collaborate on building out risk register entries with associated controls and planned & ComplianceEnsure all ISSO activities comply with applicable Federal security requirements including FISMA NIST SP 800-53 Rev 5 NIST SP 800-53A Rev 5 NIST SP 800-37 Rev 2 FIPS 199 FIPS 200 OMB Circular A-130 HSPD-12 and all referenced agency policies and implementation with annual cybersecurity awareness training requirements and maintain all required certifications as current and unexpired throughout the period of all work products are Section 508 accessibility compliant where required and that all documentation is government-owned and free of proprietary or company-specific and Experience:Required:Bachelors degree in Cybersecurity Information Technology Computer Science Information Systems or a related field from an accredited college or university. Equivalent combination of education and directly relevant work experience may be considered in lieu of a of 5 years of experience in information security with at least 3 years of dedicated experience serving as an ISSO security control assessor or equivalent role supporting federal information systems under the NIST experience developing maintaining and submitting System Security Plans (SSPs) Security Assessment Plans (SAPs) Security Assessment Reports (SARs) and Plans of Action and Milestones (POAMs) in a federal agency experience conducting NIST SP 800-53A security and privacy controls assessments across multi-technology enterprise -on experience with a federal agency Governance Risk and Compliance (GRC) tool for documentation management and continuous monitoring to obtain and maintain a government background investigation commensurate with a Moderate Risk designation (Minimum Background Investigation or higher) and all required system access authorizations prior to performing :Prior experience supporting federal civilian agency cybersecurity programs particularly within an ISD or OCIO supporting Ongoing Authorization (OA) programs including development of OA Playbooks and execution of positive and negative testing supporting FISMA reporting including collection and submission of metrics via the CyberScope supporting HVA assessments and FedRAMP Continuous Monitoring Skills and Competencies:Exceptional communication skills in Englishboth written and oralwith the demonstrated ability to produce clear concise thorough and professionally written technical documentation aligned to agency templates and implementation knowledge of the NIST Risk Management Framework (RMF) including NIST SP 800-37 Rev 2 NIST SP 800-53 Rev 5 NIST SP 800-53A Rev 5 NIST SP 800-30 Rev 1 and NIST SP understanding of federal information security law policy and standards including FISMA FIPS 199 FIPS 200 OMB Circular A-130 HSPD-12 and applicable OMB ability to write detailed technology-specific security control implementation descriptions for all technology types within a system boundary (e.g. Windows UNIX/Linux network devices web applications cloud platforms) avoiding high-level -on experience assessing technical control families (AC AU IA SC SI) across mixed technology environments including sampling strategies and cross-technology with enterprise cybersecurity tools commonly used in federal environments including vulnerability scanning platforms (e.g. Tenable Nessus/Security Center) SIEM platforms (e.g. Microsoft Sentinel) endpoint detection and response (EDR) tools and GRC developing and maintaining dashboard visualizations and underlying data structures using scripting automation and data analysis techniques (e.g. PowerShell Python Power BI Kusto Query Language).Familiarity with cloud security principles and security assessment considerations for IaaS PaaS and SaaS environments including AWS and Microsoft Azure organizational skills with the ability to manage multiple concurrent system assignments documentation deadlines and stakeholder relationships simultaneously with a high degree of accuracy and attention to of Section 508 accessibility compliance requirements as they apply to technical documentation and reporting with Microsoft Office Suite SharePoint and enterprise collaboration tools such as Microsoft Skills and Competencies:Certified Information Systems Security Professional (CISSP) Certified Information Security Manager (CISM) CompTIA Security or equivalent cybersecurity certification meeting DoD/Federal IAM or IAT level requirements.(ISC)² Systems Security Certified Practitioner (SSCP) ISACA Certified in Risk and Information Systems Control (CRISC) or equivalent risk management with the Factor Analysis of Information Risk (FAIR) methodology for quantitative cybersecurity risk assessment and risk register supporting Ongoing Authorization (OA) programs including development of OA Playbooks incorporating both positive and negative testing methodologies aligned to agency-specific test with FedRAMP Continuous Monitoring requirements and experience facilitating monthly CONMON meetings with Cloud Service Providers (CSPs).Experience supporting HVA assessment programs including HVA inventory management remediation plan development and coordination with CISA in accordance with BOD 18-02 and OMB with enterprise GRC tools for documentation management continuous monitoring tracking POAM management and FISMA metrics reporting including familiarity with CyberScope submission developing and maintaining data automation pipelines ETL processes and dashboard visualizations using tools such as Power BI PowerShell Python or Kusto Query Language (KQL) in support of continuous monitoring and FISMA with Privacy Act requirements Privacy Impact Assessment (PIA) development Privacy Threshold Analysis (PTA) and System of Records Notice (SORN) with Microsoft Purview Microsoft Defender for Endpoint Microsoft Sentinel Tenable Security Center or other enterprise security tools identified in the agencys cybersecurity tool supporting internal or external audits conducted by the Inspector General (IG) General Accountability Office (GAO) or other oversight bodies including artifact collection facilitation of walkthroughs and audit response Equal Employment Opportunity Policy:The company is an equal opportunity employer. The company shall not discriminate against any employee or applicant because of race color religion creed ethnicity sex sexual orientation gender or gender identity (except where gender is a bona fide occupational qualification) national origin or ancestry age disability citizenship military/veteran status marital status genetic information or any other characteristic protected by applicable federal state or local law. We are committed to equal employment opportunity in all decisions related to employment promotion wages benefits and all other privileges terms and conditions of company is dedicated to seeking all qualified applicants. If you require an accommodation to navigate or to apply to a position on our website please contact Heaven Wood via e-mail at or by calling to request accommodations. Koniag Government Services (KGS) is an Alaska Native Owned corporation supporting the values and traditions of our native communities through an agile employee and corporate culture that delivers Enterprise Solutions Professional Services and Operational Management to Federal Government Agencies. As a wholly owned subsidiary of Koniag we apply our proven commercial solutions to a deep knowledge of Defense and Civilian missions to provide forward leaning technical professional and operational solutions. KGS enables successful mission outcomes for our customers through solution-oriented business partnerships and a commitment to exceptional service delivery. We ensure long-term success with a continuous improvement approach while balancing the collective interests of our customers employees and native communities. For more information please visit Opportunity Employer/Veterans/Disabled. Shareholder Preference in accordance with Public Law 88-352

About Company

Company Logo

What We Do Koniag Government Services (KGS) is an Alaska Native Corporation comprised of multiple wholly owned subsidiary companies that deliver Enterprise Solutions, Professional Services, and Operations Management to Federal Government agencies. With an agile employee and corporate ... View more

View Profile View Profile