Job Description
Information Systems Security Officer (ISSO)\n
Company: Eastbay Systems, LLC (Previously DANASTAR Professional Services, LLC)
\n
Location: Washington, DC
\n
Job Type: Full-Time | Hybrid
Company Description\n
Eastbay Systems, LLC is an established IT and cybersecurity consulting firm supporting federal government agencies. We specialize in Cybersecurity Program Management, Governance, Risk & Compliance (GRC), Security Engineering, and Security Operations (SOC).
Role Description\n
We are seeking a technically proficient Information Systems Security Officer (ISSO) to support federal cybersecurity programs. The ideal candidate combines strong FISMA/RMF compliance experience with technical GRC expertise and a solid understanding of system security architectures, security controls, and continuous monitoring.
\n
The ISSO will work closely with security engineers, SOC analysts, system owners, and administrators to assess security risks, validate controls, and maintain the security posture of assigned systems.
Key Responsibilities\n
- \n
- Manage FISMA/RMF compliance activities, security assessments, system documentation, and POA&Ms.
- Execute Information Security Continuous Monitoring (ISCM) activities, including security control assessments, vulnerability management, and risk remediation tracking.
- Understand and evaluate system security architectures, configurations, and technical security controls.
- Identify security logging and monitoring requirements and collaborate with the SOC to ensure appropriate log collection, monitoring, and coverage.
- Review user access, privileged accounts, authentication controls, and access management practices.
- Assess and maintain ports, protocols, and services (PPS) baselines and identify security risks.
- Collaborate with security engineering, SOC, cloud, and DevSecOps teams to identify gaps and implement corrective actions.
- Support ongoing authorization, FedRAMP oversight, audits, and compliance reporting.
\n
\n
\n
\n
\n
\n
\n
\n
Qualifications\n
- \n
- Experience as an ISSO or in a technical GRC, cybersecurity engineering, or federal cybersecurity compliance role.
- Strong knowledge of FISMA, NIST RMF, NIST SP 800-53, and continuous monitoring requirements.
- Technical understanding of network security, cloud environments, system architectures, logging, vulnerability management, and access controls.
- Familiarity with SIEM solutions, vulnerability scanners, security configuration tools, and GRC platforms.
- Ability to analyze technical security findings, assess risks, and coordinate remediation with engineering and operations teams.
- Strong communication, documentation, and organizational skills.
- Bachelor's degree in Cybersecurity, Computer Science, Information Technology, or a related field, or equivalent experience.
- Security+, CISSP, CISM, CGRC, or similar certification preferred.
- Ability to satisfy federal background investigation and suitability requirements.
\n
\n
\n
\n
\n
\n
\n
\n
\n
Equal Employment Opportunity\n
Eastbay Systems, LLC is an Equal Opportunity Employer. We provide equal employment opportunities without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, age, disability, veteran status, or any other legally protected characteristic.
