What are the responsibilities and job description for the ISSO Senior Security Analyst position at IT Resource Hunter?
Job Title : Senior ISSO Analyst
Work Type: Contract (W2 or 1099)
Location: Columbia, SC
Job Role: Onsite
Job Overview:
We are seeking a highly experienced Security Analyst – Consultant (Senior Information Systems Security Officer – ISSO) to support and lead cybersecurity, risk management, and compliance initiatives.
This role is critical to strengthening security governance and ensuring compliance across complex, mission-critical systems. The Senior ISSO will act as a trusted cybersecurity advisor to leadership, internal teams, vendors, and external partners.
Key Responsibilities:
Security Program Leadership
- Lead Risk Management Framework (RMF) and Assessment & Authorization (A&A) activities aligned with FISMA, CMS MARS-E, and ARC-AMPE
- Develop and maintain security documentation, including:
- System Security Plans (SSPs)
- Privacy Impact Assessments (PIAs)
- Interconnection Security Agreements (ISAs)
- Computer Matching Agreements (CMAs)
- Integrate security activities throughout the System Development Life Cycle (SDLC)
- Serve as the primary point of contact for audits and security assessments
Risk Management & Technical Review
- Perform architectural and security risk assessments, including:
- Network design and data flow analysis
- Access control models
- Firewall rule and configuration reviews
Documentation & Tools
- Utilize tools such as Archer eGRC, Microsoft Office, Atlassian, Bizagi, and System Center Service Manager
- Ensure documentation meets agency standards and quality guidelines
Desired Technical Experience
- Archer (eGRC)
- Linux & Windows server environments
- IBM System 390/zSeries
- Relational & NoSQL databases
- Firewalls, IPS, routing, and switching
- SIEM solutions
- IAM solutions
- Cloud and vendor-managed environments
Required Qualifications:
- 5 years of experience working with or auditing enterprise IT systems
- Proven experience in FISMA-compliant environments
- Experience with eGRC platforms
- Strong knowledge of FISMA, NIST, CMS MARS-E, and HIPAA
- Excellent written and verbal communication skills
- Public sector / government experience required
Required Certifications
One or more of the following:
- ISC(2)
- ISACA
- SANS GIAC
- Other recognized information security certifications
Preferred Qualifications
- Bachelor’s degree in Computer Science, Information Systems, or related field or 10 years of equivalent experience
- Health Information Technology experience
- ITIL experience related to Information Security Management
- Cloud security and third-party/vendor risk management experience