Sign up to access all features of our service.
  • Job search
  • Favorites
  • Create a CV
    New
  • Salaries
  • Subscriptions

ISSO/Control Evaluator

VIATEQ Corporation

Job Description

Job Description

VIATEQ Corporation is looking for an Information System Security Officer (ISSO) / Control Evaluator to support a comprehensive enterprise cybersecurity services engagement for a federal civilian agency. This position requires the ability to obtain and maintain a government background investigation commensurate with a Moderate Risk designation (Minimum Background Investigation or higher) and applicable system access authorizations prior to performing work. Work will be performed primarily at the client's facility located in Washington, DC, with potential for hybrid/remote arrangements as approved.

This role sits within the Information Security Division (ISD) and supports the agency's Risk Management Framework (RMF) program, FISMA compliance obligations, continuous monitoring activities, and security controls assessment and evaluation functions across a diverse portfolio of on-premises, cloud-hosted, and hybrid information systems.

The ideal candidate is a technically proficient and operationally experienced cybersecurity professional with a deep understanding of NIST security frameworks, federal information security policy, security assessment methodologies, and the practical application of security controls across complex, multi-technology enterprise environments. This individual must possess the ability to develop and maintain in-depth technical knowledge of assigned systems, build trusted relationships with system owners and stakeholders, and independently execute a broad range of ISSO responsibilities with minimal Government direction.

The ISSO / Control Evaluator is responsible for providing comprehensive information system security officer support and security controls assessment and evaluation services across an assigned portfolio of federal information systems. This individual develops and sustains in-depth technical, operational, and working-level expertise about each assigned system, advocates for system owner needs as they align to cybersecurity and privacy requirements, and ensures each system maintains its authorization to operate in accordance with federal and agency security policies and standards.

This role requires active participation in the agency's enterprise change control processes, continuous monitoring activities, Ongoing Authorization (OA) programs, and audit support functions, as well as contributions to automation, visualization, and data structure efforts that provide real-time visibility into control status and security posture across the enterprise.

Responsibilities:

ISSO Core Responsibilities

  • Develop and sustain in-depth technical, operational, and working-level expertise about all assigned information systems, including thorough knowledge of system architecture, assets, data flows, operational environment, management hierarchy, and how each system fits into the broader enterprise IT ecosystem.
  • Establish and maintain a professional rapport and trusted working relationship with system owners, program offices, and technical support personnel for all assigned systems, understanding their operational needs and advocating for those needs as they align to cybersecurity and privacy requirements.
  • Read, absorb, and maintain current familiarity with all available system documentation for assigned systems, including System Security Plans (SSPs), topology diagrams, architecture diagrams, and data flow documentation.
  • Establish access to and gain increasing proficiency with the operational tools, administrative consoles, and enterprise cybersecurity platforms used to manage and monitor assigned systems, extracting meaningful data to produce continuously updated control status visualizations and dashboards.
  • Ensure assigned systems are onboarded into enterprise tools and reporting mechanisms, including the agency's Governance, Risk, and Compliance (GRC) tool, in accordance with established procedures and timelines.
  • Actively participate in the weekly Enterprise Change Control Board (ECCB) process, ensuring security impacts of proposed changes are evaluated and documented for all assigned systems.
  • Maintain current awareness of all active Acceptance of Risk (AOR) documents for assigned systems, ensuring resubmission for approval before expiration.
  • Maintain knowledge management services for all accreditation-related artifacts, including appointment orders, Authority to Operate (ATO) documentation, AORs, Memoranda of Understanding/Agreement, and Data Sharing Agreements, ensuring all documents are organized and accessible in the designated central repository.

Documentation Support

  • Create, update, revise, and maintain cybersecurity and privacy documentation for all assigned systems across the enterprise, ensuring all documentation is aligned to applicable agency implementation procedures and reviewed for acceptance by the Office of the CIO.
  • Develop and maintain the following documentation types, among others:
    • System Security Plans (SSPs) with detailed, technology-specific control implementation descriptions for all technologies within the system boundary
    • Configuration Management Plans (CMPs)
    • Information System Contingency Plans (ISCPs) and Contingency Plan Test Reports (ISCP-TRs)
    • E-authentication Risk Assessments (ERAs)
    • User recertification documentation
    • Architecture, topology, and data flow diagrams (OV-1 and SV-1 equivalent)
  • Ensure all control implementation descriptions are written to a level of detail that demonstrates how each control is specifically implemented across all technologies within the system boundary, avoiding high-level generalizations or simple restatement of NIST control language.
  • Address all Government comments, edits, and questions on documentation within 10 business days of receipt, and escalate stakeholder unresponsiveness to the Government POC after 10 business days without response.
  • Ensure selected policy and procedure documents are delivered in both Adobe and Word formats and are Section 508 accessibility remediated as directed.

Controls Assessment and Evaluation Support

  • Provide security and privacy controls assessment and continuous monitoring assessment support for all assigned systems, including testing and validation of NIST SP 800-53 controls, documentation of NIST SP 800-53A Determine If Statements (DISs), and mapping of vulnerabilities to applicable controls.
  • Develop draft Security and Risk Assessment Plans (SAPs) for delivery not less than 10 business days prior to beginning an assessment, and draft Security and Risk Assessment Reports (SARs) and Plan of Action and Milestones (POAMs) within 30 business days from point-in-time assessment kick-off.
  • Conduct technical control assessments across all technology types within the system boundary (e.g., Windows, UNIX, Cisco, F5 Load Balancer), including sampling across in-scope devices, users, and services, ensuring assessments are comprehensive to the scope identified in the SAP and 100% aligned to the GRC tool.
  • Develop and deliver Annual Assessment Reports (AARs) per in-scope system within 120 business days from point-in-time annual assessment kick-off, and multi-year assessment reports in accordance with applicable timelines.
  • Incorporate all Government feedback into revised deliverables within 5 business days of receipt of comments, ensuring final deliverables are comprehensive, peer-reviewed, and aligned to agency templates.
  • Develop assessment reports that include visual representation against the NIST Cybersecurity Framework (CSF) and are comprehensive to the scope identified in the SAP.

Ongoing Authorization (OA) Evaluation Support

  • For systems approved for Ongoing Authorization (OA), develop and submit an OA Playbook to the agency for approval, including a documented testing methodology for each OA core control covering Test Strategy, Test Design, Test Execution, Results Evaluation, and Visualization.
  • Conduct OA Positive Testing monthly in accordance with agency implementation procedures, documenting all results in the agency GRC tool.
  • Conduct OA Negative Testing annually in accordance with agency implementation procedures, coordinating with penetration testing resources as necessary to execute negative test scenarios.
  • Perform OA testing comprehensively across the technology stack of each target system, documenting results in detail within the GRC tool in a clear and concise manner.

FISMA Reporting Support

  • Collect, compile, validate, and submit FISMA reporting metrics for all assigned systems and programs, leveraging automation to the greatest degree possible to ensure accuracy and completeness of collected data.
  • Contribute to the consolidated FISMA metrics reports, ensuring data is mathematically accurate and representative of the total agency FISMA inventory, delivered for Government review no later than 10 business days prior to submission due dates.
  • Support the development and maintenance of dynamically updatable FISMA metrics visualizations and dashboards that pull data directly or indirectly from collected metrics.

Audit Support

  • Support and facilitate internal and external audits of assigned FISMA systems, including audits conducted by the Inspector General (IG), General Accountability Office (GAO), and internal auditors.
  • Facilitate audit meetings and walkthroughs, coordinate with relevant support personnel, supply auditors with requested artifacts, and respond to follow-up questions in accordance with auditors' schedules and timelines.
  • Ensure SOC reports are received from program offices for audit purposes as required, and that all audit artifacts are delivered on time, reviewable by the Government, and minimizing repeated requests from auditors.

High Value Asset (HVA) Assessment Support

  • Complete CISA's on-demand High Value Assets Assessment 3.0 (HVA 3.0) Training and provide course completion certificate to the Information System Security Manager (ISSM).
  • Develop, maintain, and regularly update the agency HVA inventory list at least annually, and incorporate HVA activities into broader IT and information security and privacy management planning activities.
  • Identify, categorize, and prioritize HVAs, implement and validate required security controls, identify HVA connections and dependencies, and support timely remediation of HVA assessment findings in accordance with established plans, milestones, and timelines.

FedRAMP Continuous Monitoring (CONMON) Support

  • Facilitate monthly FedRAMP CONMON meetings with applicable stakeholders for assigned systems, maintaining a general understanding of each system to provide appropriate guidance and comments to Cloud Service Providers (CSPs).
  • Review vulnerability, penetration test, and ad hoc reporting from CSPs, ensuring vendor actions pose no security risks to the enterprise, and review and approve major changes when required by the vendor.

Automation, Visualization, and Data Structures Support

  • Design, construct, automate, and maintain visualizations (dashboards) and underlying data structures that reflect the status or effectiveness of security controls, monitoring status, capabilities, and metrics for assigned systems.
  • Intake continuous feeds from enterprise cybersecurity tools (typically in .csv format), using scripting or other automation techniques to construct visualizations that reflect the status or effectiveness of monitored capabilities.
  • Build, maintain, and document the underlying data structures supporting all visualizations, including all Extract-Transform-Load (ETL) requirements, data intake, and data normalization processes.
  • Make approved visualizations available via the agency intranet portal, ensuring they are updated automatically on a continual basis or refreshed on at least a weekly schedule as appropriate.

Enterprise Risk Management (ERM) Support

  • Maintain cybersecurity and privacy risk registers for assigned systems, ensuring they are updated monthly and available via online visualization and internal web portal.
  • Leverage the Factor Analysis of Information Risk (FAIR) methodology to assist in quantifying risk, and support the integration of cybersecurity and privacy risks into the agency ERM Risk Register as directed.
  • Evaluate major risks related to cybersecurity, privacy, theft of information, and sensitive information protection (both internal and external threats), and collaborate on building out risk register entries with associated controls and planned mitigations.

Security & Compliance

  • Ensure all ISSO activities comp
Vacancy posted 3 days ago
Similar jobs that could be interesting for youBased on the ISSO/Control Evaluator in Washington DC vacancy
  •  .... Learn More About ProSidian Consulting at DescriptionProSidian Seeks a Enterprise Assessment Protection System Performance Test Evaluator (SCA Code: -) in CONUS - Mid Atlantic Washington Metropolitan Area (Northern Virginia | Washington DC | Maryland) to support an engagement... 
    Suggested
    Full time
    Temporary work
    For contractors
    Work at office
    Flexible hours

    Prosidian Consultng

    Washington DC
    3 days ago
  •  ...Transportation, Federal and State Government Agencies. Learn More About ProSidian Consulting at DescriptionProSidian Seeks a External Evaluator | Evaluation Support [DOEOP049054] - DPLH Est.: 480 Hrs. ST | 0 Hrs. OT on a Exempt 1099 Contract: No Overtime Pay Contract... 
    Suggested
    Full time
    Contract work
    Temporary work
    For contractors
    H1b
    Work at office
    Flexible hours

    Prosidian Consultng

    Washington DC
    2 days ago
  •  ...Birdwatch Home Evaluation Specialist Birdwatch exists to simplify the lives of modern homeowners. We put people at the center of all we do – our clients, our staff, and our communities. It's a recipe for success. Our one-of-a-kind service takes the hassle out of homeownership... 
    Suggested
    Part time
    Immediate start
    Monday to Friday
    Flexible hours

    Birdwatch

    Washington DC
    3 days ago
  •  ...Home Inspector/Home Evaluator - Northern Virginia Role Overview This position exists to be the trusted first point of in-person connection between Birdwatch and our members, setting the tone for a long‑term relationship built on expertise, empathy, and care. Home Evaluation... 
    Suggested
    Immediate start
    Monday to Friday
    Flexible hours

    Birdwatch

    Washington DC
    4 days ago
  •  ...Luxury Brand Evaluator Turn your passion for luxury into a career opportunity. Explore the world of premium brands and make a lasting impact in fashion, beauty, jewelry, or automobiles. Join CXG, the global leader in customer experience, and work alongside iconic brand... 
    Suggested
    Worldwide
    Flexible hours

    CXG

    Washington DC
    4 days ago
  • Join the HJF Team! HJF is seeking a Program Evaluator II - Pre- and Post-Crash Care to conduct and provide technical assistance for research and evaluation activities, as well as operations and logistics support. The position will be in support of National Institute for... 
    Hourly pay
    For contractors
    Work at office

    The Henry M. Jackson Foundation for the Advancement of Milit...

    Bethesda, MD
    2 days ago
  • CXG is seeking a luxury brand evaluator to discreetly assess customer experiences across boutiques, online stores, and product returns. You will provide firsthand feedback to help premium brands refine their services, all while enjoying flexible missions and the freedom... 
    Flexible hours

    CXG

    Arlington, VA
    1 day ago
  • CXG group is seeking a luxury brand evaluator to assess customer experiences with premium brands. This role offers the flexibility to choose assignments that suit your interests, from visiting stores to online evaluations, ensuring your input shapes the future of luxury... 
    Flexible hours

    CXG group

    Arlington, VA
    4 days ago
  • R3 Continuum LLC is looking for Neuropsychologists in Washington, DC to join their network for Psychological Evaluations. This unique role offers the flexibility of an Independent Consultant, allowing you to work on a case-by-case basis to provide evaluations for concierge... 
    Flexible hours

    R3 Continuum LLC

    Washington DC
    4 days ago
  • CXG invites you to join a global network of evaluators shaping premium brand experiences. As a luxury brand evaluator, you discreetly assess in-store and online interactions, providing insightful feedback to help luxury brands refine their services. Each assignment is... 

    CXG group

    Bethesda, MD
    15 hours ago
  • $45 - $85 per hour

    Ixolabs is seeking an Animation Quality Evaluator to refine AI-generated animations. The ideal candidate will evaluate motion fluidity and naturalness, ensuring animations convey believable narratives. The role is part-time (15-25 hours/week) and offers competitive compensation... 
    Remote job
    Part time

    Ixolabs

    Washington DC
    15 hours ago
  • Henry M. Jackson Foundation for the Advancement of Military Medicine (HJF) seeks a Program Evaluator II - Pre- and Post-Crash Care to conduct and provide technical assistance for research and evaluation activities, as well as operations and logistics support in Bethesda... 

    Federallabs

    Bethesda, MD
    2 days ago
  • $125k - $140k

    Amentum seeks Analytic Tradecraft Specialists to support an Office of Naval Intelligence (ONI) contract in Suitland, MD. You will evaluate intelligence products for ICD 203 analytic tradecraft compliance and develop metrics to improve assessment rigor. Required: TS/SCI... 
    Contract work
    Work at office

    Amentum

    Suitland, MD
    3 days ago
  • This Program Evaluator, GS-0101-14 position is located in the Office of Award Management (OAM), Performance, Evaluation, and Systems Branch. OAM ensures accountable and efficient stewardship of NSF financial assistance across the full award lifecycle. OAM partners with... 
    Work at office

    National Science Foundation

    Alexandria, VA
    1 day ago
  • The Henry M. Jackson Foundation for the Advancement of Military Medicine (HJF) seeks a Program Evaluator II to provide technical assistance for research and evaluation activities and to support operations and logistics. The role supports the National Institute for Defense... 

    The Henry M. Jackson Foundation for the Advancement of Milit...

    Bethesda, MD
    2 days ago
  • A global leader in customer experience is seeking luxury brand evaluators to provide feedback on customer experiences with premium brands. Join a community of evaluators to assess the quality of service, both in-store and online, for leading luxury brands like Louis Vuitton... 
    Flexible hours

    CXG

    Arlington, VA
    4 days ago
  •  ...automobiles. Join CXG, the global leader in customer experience, and work alongside iconic brand names. About the Role: As a luxury brand evaluator, you will step into the world of luxury to discreetly assess customer experiences, providing critical feedback that helps brands... 
    Contract work
    Worldwide
    Flexible hours

    CXG group

    Arlington, VA
    4 days ago
  •  ...R3 Continuum is looking for Neuropsychologists to join our Evaluation and IPEs network in Washington, DC. This role involves providing in-office psychological evaluations to concierge-level clients. Candidates must have a doctorate in neuropsychology or clinical psychology... 
    Work at office
    Flexible hours

    R3 Continuum

    Washington DC
    3 days ago
  • $120k - $150k

    Visa sponsorship provided: No Location: West Perth, WA Remote Status: no remote Pay Type: Annual Salary Salary: 120000-150000/Australian Dollars Occupational Categories: Real Estate/ Leasing/ Property Management Industry(ies): Real Estate/ Mortgage Are you a Licensed Valuer...
    Local area
    Remote work
    Visa sponsorship
    Free visa

    NPAworldwide

    Washington DC
    6 days ago
  • The National Science Foundation in the United States is seeking a Program Evaluator (GS-0101-14) assigned to the Office of Award Management, Performance, Evaluation, and Systems Branch. This role focuses on designing and advising on program evaluations to strengthen the... 
    Work at office

    National Science Foundation

    Alexandria, VA
    1 day ago
  • Position Overview Innovative Therapeutic Services seeks a Licensed Psychologist for the role as a Neuropsychological Evaluator. The successful candidate will conduct comprehensive, in-person neuropsychological evaluations for adolescent males located in three juvenile detention... 
    Hourly pay
    Contract work
    For contractors
    Trial period
    Flexible hours

    Innovative Therapeutic Services, LLC

    Cheltenham, MD
    4 days ago
  • A mental health service provider seeks a Licensed Psychologist to conduct in-person neuropsychological evaluations for adolescents in Maryland detention facilities. The role involves preparing court-compliant reports, providing expert testimony, and collaborating with legal... 
    Flexible hours

    Innovative Therapeutic Services, LLC

    Cheltenham, MD
    1 day ago
  • $135k - $216k

    ResponsibilitiesPeraton is seeking a Tradecraft Evaluator to provide expert-level insights and guidance to editorial and production activities that inform internal and external customers as well as executive-level policymakers. The evaluator will collaborate with authors... 
    Contract work
    Shift work

    Peraton Corporation

    McLean, VA
    6 days ago
  • Responsibilities Peraton is seeking a Tradecraft Evaluator to provide expert-level insights and guidance to editorial and production activities that inform internal and external customers as well as executive-level policymakers. The evaluator will collaborate with authors... 

    Peraton

    Mc Lean, VA
    4 days ago
  • Peraton seeks a Tradecraft Evaluator to provide expert-level insights guiding editorial and production activities for internal/external customers and policymakers. The role collaborates with authors to inform evaluations, conduct reviews, brief results to stakeholders,... 

    Peraton

    Mc Lean, VA
    4 days ago
  • CXG is seeking a luxury brand evaluator to discreetly assess customer experiences across premium brands. You will visit boutiques or evaluate online, providing feedback to help brands refine their services. You can complete missions from home or on-site, with assignments... 

    CXG

    Mc Lean, VA
    1 day ago
  • $34.58 - $45 per hour

     ...partner for health solutions in the public sector. Job Summary and Responsibilities Acentra Health is looking for a PASRR Clinical Evaluator - PRN to join our growing team. Job Summary: This position is responsible for PASRR evaluations, making level of care... 
    Relief
    Work at office
    Local area
    Flexible hours

    Acentra Health

    Washington DC
    3 days ago
  •  ...Job Description Job Description Senior-Level (12 to 18 years experience) Seeking a highly motivated Intelligence Analysis Evaluator to provide the following expert support to an Intelligence Community (IC) client: Evaluate the application of IC Analytic Standards... 
    Work experience placement
    Work at office
    Flexible hours

    Analytic Solutions Group

    McLean, VA
    2 days ago

Do you want to receive more vacancies?

Subscribe and receive similar vacancies to ISSO/Control Evaluator. Be the first to apply!