Quzara LLC · 4 hours ago
Information System Security Officer
Quzara LLC is a company focused on federal support, and they are seeking a Federal Support Information System Security Officer (FSISSO) to implement and manage an information security program. The role involves ensuring compliance with federal frameworks, leading risk management efforts, and safeguarding federal IT systems and data.
Internet
Responsibilities
Develop, implement, and maintain cybersecurity policies, standards, and procedures aligned with federal regulations (e.g., NIST 800.53, FISMA, FedRAMP)
Conduct ongoing risk assessments, vulnerability assessments, and compliance audits to ensure proper security posture across information systems
Lead and document security assessments and authorization (A&A) packages, working across technical and executive teams to support continuous monitoring and POA&M tracking
Manage incident response planning and execution, including forensic analysis, remediation, and root cause investigations
Oversee the execution of vulnerability scanning, penetration testing, and third-party vendor risk evaluations, using tools like Nessus
Support secure system development and cloud migration efforts (e.g., AWS, Azure), ensuring adherence to DevSecOps and secure SDLC practices
Develop and present metrics, compliance dashboards, and executive briefings to senior leadership on the current state of security programs and initiatives
Lead cross-team collaboration to align cybersecurity strategies, remediation plans, and policy enforcement with company-wide initiatives
Maintain and enhance the security of critical infrastructure systems (e.g., IoT, OT devices) where applicable
Qualification
Required
US Citizenship: Required
DoD Security Clearance: Required
Bachelor's degree in Cybersecurity, Computer Science, Information Technology, or a related field
5+ years of experience in federal information security roles, including risk management, incident response, and compliance
Proven experience in applying NIST frameworks (800.53, CSF, 800.82), FedRAMP, FISMA, CJIS, HITRUST, and other regulatory baselines
Demonstrated expertise in conducting risk and vulnerability assessments, implementing security controls, and developing policy and procedure documentation
Experience managing A&A processes, third-party risk programs, and compliance across enterprise systems
Familiarity with secure cloud operations in AWS and Azure environments
Experience collaborating across departments including engineering, CISO, legal, and audit teams
Excellent analytical, communication, and collaboration skills; ability to tailor security messages to both technical and executive audiences
Develop, implement, and maintain cybersecurity policies, standards, and procedures aligned with federal regulations (e.g., NIST 800.53, FISMA, FedRAMP)
Conduct ongoing risk assessments, vulnerability assessments, and compliance audits to ensure proper security posture across information systems
Lead and document security assessments and authorization (A&A) packages, working across technical and executive teams to support continuous monitoring and POA&M tracking
Manage incident response planning and execution, including forensic analysis, remediation, and root cause investigations
Oversee the execution of vulnerability scanning, penetration testing, and third-party vendor risk evaluations, using tools like Nessus
Support secure system development and cloud migration efforts (e.g., AWS, Azure), ensuring adherence to DevSecOps and secure SDLC practices
Develop and present metrics, compliance dashboards, and executive briefings to senior leadership on the current state of security programs and initiatives
Lead cross-team collaboration to align cybersecurity strategies, remediation plans, and policy enforcement with company-wide initiatives
Maintain and enhance the security of critical infrastructure systems (e.g., IoT, OT devices) where applicable
Preferred
Certified Information Systems Security Professional (CISSP) – ISC 2
Microsoft Certified Systems Engineer (MCSE)
Company
Quzara LLC
Quzara is a DC-Based Cybersecurity firm. We are US Government SBA 8(a) Certified, WOSB and GSA HAC SINS approved in every category.
Funding
Current Stage
Early StageRecent News
2025-12-17
Company data provided by crunchbase