ISSO / Cybersecurity Analyst
ARCHIVED
We can't find an active application page for this role right now. It may reopen or be listed elsewhere. Use Next Steps to search for an active apply link and similar live jobs.
Farfield Systems is hiring two ISSO / Cybersecurity Analysts to join our DFC cybersecurity support team. If you want to do work that matters — protecting an agency whose mission is mobilizing private capital to address the most critical development challenges of our time — this is your opportunity.
Working under the direction of the Lead and Senior ISSOs, you will perform the practical, outcome-driven cybersecurity work that keeps DFC's 32 information systems authorized and operationally secure. Your responsibilities will span the ISSO support spectrum: creating and updating POA&M entries in CSAM after finding identification; preparing Security Impact Assessments for standard and significant system changes; supporting continuous monitoring activities; producing vulnerability assessment data from Tenable Nessus or Qualys; contributing to audit and assessment evidence packages; documenting corrective actions and RCA findings; and supporting incident response by providing affected-system context from CSAM to incident responders. You will work within defined SLA timelines and contribute to the team's quality-first delivery culture. This is a full-time, direct-support role — not a coordination function.
Requirements:
U.S. citizenship required
Eligible for and capable of obtaining a Tier 4 High-Risk Public Trust background investigation; suitability adjudication must be completed before being granted privileged or administrative system access
Hands-on experience supporting ISSO functions, RMF activities, or cybersecurity operations in a federal IT environment
Working familiarity with: CSAM (GRC/authorization-package platform), Splunk (SIEM/log analytics), ServiceNow ITSM modules, Tenable Nessus or Qualys vulnerability scanners, Microsoft Defender for Endpoint/Identity/Cloud/M365, Microsoft Intune and BigFix, Microsoft Azure and M365 security and compliance centers, Microsoft Entra ID, Okta, Palo Alto Panorama, and Zscaler administration consoles
Experience creating and managing POA&Ms, supporting vulnerability management workflows, and preparing cybersecurity documentation in a federal GRC platform
Ability to meet defined response and deliverable timelines in a fast-paced, audit-sensitive environment
Strong attention to detail and commitment to accurate, complete recordkeeping