Information Systems Security Officer
Salva questo lavoro e mantieni la tua ricerca organizzata
Crea un account gratuito per salvare lavori, creare avvisi e tornare a questa inserzione dalla tua dashboard.
Si candidi ora: legga i dettagli del lavoro scorrendo verso il basso. Verifichi di possedere le competenze necessarie prima di inviare la candidatura.
Position: Information Systems Security Officer (ISSO)
Employment Type: Full Time
Location: Falls Church, VA (Hybrid role)
The Role
The Information Systems Security Officer (ISSO) is responsible for overseeing the security posture and compliance of Tesla Government customer-facing systems operating in government-regulated environments. This role ensures that systems maintain Authorization to Operate (ATO) by managing compliance activities, validating control implementation, and coordinating security efforts across engineering, DevOps, and security teams.
The ISSO is accountable for the accuracy, completeness, and audit readiness of security artifacts, as well as ongoing monitoring of system security posture. The role works closely with Cloud Security Engineers and DevOps to ensure that controls are implemented effectively and remain aligned with regulatory requirements.
The ISSO operates with a high degree of ownership over compliance outcomes and is responsible for ensuring that systems remain secure, compliant, and audit-ready throughout their lifecycle.
About Us
Tesla Government Inc. (no affiliation with the automotive company) is a rapidly growing small business, located in Falls Church, Virginia. Founded in 2009, Tesla Government seeks to improve how government agencies manage and share information internally and with government and external partners. Our proven agile, outcome-oriented approach delivers results quickly, reducing risk and driving client success.
We offer Flex PTO, flexible work schedule, health benefits, 4% matching on 401k contributions, competitive compensation, and work from home (telework). We have a friendly, active work environment, and our projects make a difference.
Key Responsibilities
ATO Ownership and Compliance Management
Own ATO sustainment activities for assigned systems, ensuring continuous compliance with applicable frameworks (e.g., NIST RMF, FedRAMP, STIGs).
Maintain and manage system security documentation, including SSPs, POA&Ms, and control implementation evidence.
Ensure traceability between system controls, implementation artifacts, and compliance requirements.
Coordinate with stakeholders to prepare for and support audits, assessments, and security reviews.
Security Control Oversight and Validation
Ensure required security controls are implemented, documented, and operating as intended.
Review control implementations across infrastructure, applications, and operational processes.
Validate control effectiveness through testing, review, and collaboration with engineering teams.
Identify gaps in control implementation and drive remediation efforts.
Vulnerability and Risk Management
Oversee vulnerability management processes, including tracking, prioritization, and remediation of findings.
Review scan results (e.g., ACAS/Nessus, STIGs, container scans) and ensure appropriate action is taken.
Maintain and manage POA&Ms, ensuring findings are documented, tracked, and resolved in a timely manner.
Assess and communicate risk posture to stakeholders.
Continuous Monitoring and Reporting
Ensure continuous monitoring activities are executed and documented appropriately.
Review system logs, alerts, and security data to validate compliance and detect anomalies.
Produce and maintain security status reports and compliance summaries.
Ensure ongoing visibility into system security posture for leadership and stakeholders.
Secure Change and Configuration Oversight
Review system and application changes to ensure security and compliance requirements are maintained.
Ensure that configuration changes align with approved baselines and do not introduce compliance gaps.
Collaborate with engineering teams to integrate security requirements into delivery workflows.
Identify and elevate risks introduced through system changes.
Incident Response and Security Operations Support
Support incident response activities, including documentation, coordination, and reporting.
Ensure incidents are properly tracked, investigated, and resolved in accordance with compliance requirements.
Validate that incident response processes meet regulatory and audit expectations.
Coordination and Stakeholder Engagement
Act as the primary point of contact for security compliance matters for assigned systems.
Coordinate with Cloud Security Engineers, DevOps, and development teams to ensure alignment on security requirements.
Engage with government stakeholders, assessors, and auditors during reviews and evaluations.
Provide guidance on compliance requirements and security expe