Position Title: ISSO / Control Evaluator – Senior Opportunity: SBA Enterprise Cybersecurity Services (ECS)
Position Overview
The ISSO / Control Evaluator – Senior shall provide cybersecurity governance, Risk Management Framework (RMF), continuous monitoring, and security controls assessment support services for the U.S. Small Business Administration (SBA) Enterprise Cybersecurity Services (ECS) program.
Key Responsibilities
Serve as the senior ISSO and security compliance advisor for assigned SBA systems, applications, services, and cloud environments.
Provide leadership and technical oversight for RMF assessment, authorization, and continuous monitoring activities in accordance with NIST SP 800-37 Rev. 2.
Conduct and oversee testing and validation of NIST SP 800-53 Rev. 5 security and privacy controls in accordance with NIST SP 800-53A assessment procedures.
Develop, review, update, and maintain cybersecurity and privacy documentation including SSPs, CMPs, ISCPs, ISCP Test Reports, ERAs, POA&Ms, and architecture diagrams.
Support SBA Ongoing Authorization (OA) activities including development and execution of OA Playbooks, positive testing, and negative testing methodologies.
Document Determine If Statements (DISs), assessment evidence, and technical findings to demonstrate security control effectiveness.
Coordinate vulnerability management activities including validation of remediation actions, mapping vulnerabilities to NIST controls, and tracking POA&M closure activities.
Support FISMA reporting, cybersecurity metrics collection, dashboard reporting, and Governance Risk and Compliance (GRC) tool updates.
Provide audit support for IG, GAO, FISMA, and internal assessments by coordinating artifact collection, walkthroughs, and audit response activities.
Support High Value Asset (HVA) assessment activities and FedRAMP Continuous Monitoring (CONMON) management activities.
Review system architectures, network topologies, cloud environments, and security configurations to identify cybersecurity risks and compliance gaps.
Participate in SBA Enterprise Change Control Board (ECCB) activities and cybersecurity governance reviews.
Provide technical guidance to system owners, ISSMs, engineers, administrators, and program stakeholders regarding cybersecurity compliance and remediation strategies.
Ensure all deliverables are peer reviewed, aligned with SBA implementation procedures, Section 508 compliant, and submitted within required timelines.
Support enterprise cybersecurity continuous monitoring, risk analysis, and automation/visualization initiatives.
Required Qualifications
Bachelor’s degree in Cybersecurity, Information Assurance, Information Technology, Computer Science, Engineering, or related discipline.
Minimum of eight (8) years of experience supporting federal cybersecurity, RMF, ISSO, or information assurance activities.
Minimum of five (5) years of experience conducting security controls assessments, compliance evaluations, or continuous monitoring activities for federal systems.