Summit Technologies, Inc. (Hartford, CT)

Sr. ISSO (Information Systems Security Officer) - 6835

Summit Technologies, Inc. (Hartford, CT)  •  Washington, DC (Hybrid)  •  2 months ago
Apply
AI can make mistakes so check important info. Chat history is never stored.

Job Description

Summit Technologies, Inc. is looking for a Senior Information Systems Security Officer (ISSO) to support a critical U.S. government agency in the National Capital Region. This senior-level role is responsible for ensuring the security and compliance of agency information systems by implementing and managing security controls aligned with federal cybersecurity frameworks, including the NIST Risk Management Framework (RMF), FISMA, and NIST SP 800-53.

This is an excellent opportunity for an experienced cybersecurity professional to contribute to the secure provisioning, authorization, and ongoing monitoring of systems across both on-premise and cloud environments. The contractor ISSO will collaborate with Information System Security & Privacy Officers (ISSPOs), system owners, engineers, and governance teams to maintain the confidentiality, integrity, and availability of government systems. This is a hybrid role based in Washington, D.C. Candidates must be eligible for a Public Trust clearance.

Responsibilities:

  • Develop, implement, and maintain IT security controls in accordance with NIST SP 800-53, RMF, and agency security policies.
  • Support the preparation, review, and submission of Security Authorization packages, including the System Security Plan (SSP), Security Assessment Report (SAR), and Plan of Action and Milestones (POA&M).
  • Coordinate and prepare systems for Security Control Assessments (SCA), ensuring all artifacts are accurate and complete.
  • Conduct and document Security Impact Analyses (SIAs) for changes to hardware, software, cloud infrastructure, or connectivity.
  • Participate in configuration and change control processes, ensuring secure baselines are maintained and reflected in documentation.
  • Assist in system categorization and validate asset inventories to ensure appropriate control baselines are applied.
  • Assess control implementation effectiveness and identify deficiencies for remediation or risk acceptance.
  • Document business justifications and mitigation strategies for risk acceptance proposals for Authorizing Officials.
  • Support Continuous Monitoring by reviewing security alerts, system changes, and compliance evidence to ensure ongoing authorization.
  • Contribute to the development, revision, and enforcement of security policies, procedures, and technical guidelines.
  • Participate in internal IT governance processes, including exception handling, standards reviews, and control waivers.
  • Support security awareness and training compliance for personnel with system access.
  • Monitor evolving threats and recommend adaptive security controls in response to risk landscape changes.
  • Prepare high-quality technical documentation, status reports, and risk briefings for internal and external stakeholders.

Requirements:

  • Bachelor’s degree and 9+ years of IT security or systems security engineering experience, or Master’s degree with 7+ years of experience.
  • Hands-on experience implementing and managing security controls in enterprise or federal IT environments.
  • Strong understanding of the NIST RMF, NIST SP 800-53, FISMA, and federal security policies including EO 14028 and OMB M-22-09.
  • Experience performing risk assessments, preparing ATO documentation, and tracking control deficiencies in POA&Ms.
  • Working knowledge of cloud security (AWS, Azure, GCP) and hybrid environments.
  • Familiarity with enterprise platforms such as Microsoft 365, Azure AD, Cisco, and Oracle.
  • Proficient in network and system security concepts, including IDS/IPS, VPNs, encryption, secure baselining, and OS hardening.
  • Experience supporting third-party security assessments or audits.
  • Strong documentation, reporting, and communication skills, including the ability to convey complex technical issues to non-technical audiences.
  • Proficient in Microsoft Office (Word, Excel, PowerPoint, SharePoint).

Preferred Qualifications:

  • Current cybersecurity certification such as CISSP, CISM, or Security+.
  • Experience with GRC and SA&A tools such as Archer, eMASS, CSAM, or Xacta.
  • Familiarity with FedRAMP, cloud compliance requirements, and federal privacy regulations.
  • Knowledge of OWASP Top 10 and modern application security best practices.
  • Understanding of adversary TTPs and frameworks such as MITRE ATT&CK.
  • Ability to work independently and manage priorities in a fast-paced, dynamic environment.

Clearance Requirement:

  • All candidates must be eligible to obtain and maintain a U.S. Public Trust clearance


Security Clearance:

  • Must be eligible to obtain and maintain a Public Trust clearance.

If you feel you are qualified and want to be considered for this position, please supply the following to: 46rdw5rypz1bnr567weeid4trw@crelate.net , and please put the job number ‘ 6835’ in the subject line:

  • Updated resume including MM/YYYY for each employer.
  • Best times/dates to interview (plus phone # you can best be contacted at).
  • Availability to start once given formal offers.

Summit Technologies Inc. appreciates your interest. We will contact the best matching prospects and will consider you for future opportunities. We will not submit your resume without your prior knowledge and consent. We are an equal opportunity employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, gender, sexual orientation, gender identity, national origin, disability or veteran status.

Summit Technologies, Inc. (Hartford, CT)

About Summit Technologies, Inc. (Hartford, CT)

Simply put, we roll up our sleeves and get the job done.

As a U.S. Federal Government contractor, Summit has been providing information technology services and solutions to the Department of Defense and Federal Civilian agencies since 2002. Providing services throughout the United States and overseas via prime contracts and subcontracts, our reliable organization has a stable management and technical team which produces consistent results.

At Summit, our culture of team empowerment is our most valuable asset when it comes to supporting our customers. We’re a company with the tools and drive to forge lasting impacts on your organizations’ success, and the dedication to see it through to completion. We pride ourselves on our ability to deliver our innovative, cost-effective technical services and solutions with both the streamlined, professional approach of a large company and the considerate, personable touch of a small business.

Our Federally recognized SBA socio-economic designations include Small Business, HUBZone and Women Owned Small Business (WOSB). Summit’s CAGE code is 3FKG0.

Since 1997, Summit Technologies, Inc. has served Federal and Commercial customers in 40+ countries, providing cybersecurity, knowledge management, infrastructure and development services and solutions. Our customer base includes the Department of Defense, Department of Homeland Security, and Department of Transportation, as well as Fortune 1000 companies such as AIG, Aetna, Avery-Dennison, Barings, CIGNA, Compaq, HP, Leidos, Lockheed Martin, Pfizer, SAIC, Starbucks and UNISYS.

Industry
IT & Software
Company Size
51-200 employees
Headquarters
Hartford, Connecticut
Year Founded
1997
Social Media