Tobias Mensah
Information System Security Officer (Isso) @Xor Security, An Agile Defense Company
Signup · Get unlimited contacts
WORK HISTORY
Information System Security Officer (Isso) @Xor Security, An Agile Defense Company
Washington, DC, US
I ensure systems are assessed and accredited to receive an Authority to Operate (ATO) Develop and maintain the System Security Plan (SSP), and update Plan of Action & Milestones (POA & M) status. Review and analyze all system artifacts for accuracy and completeness in support of authorization to operate requests I ensure all assessment and audit reports are uploaded properly in CSAM Develop and support the Ongoing Authorization (OA) process that includes continuous monitoring activities using CFTC’s GRC tools; I support SCA’s as they conduct security controls assessments (automated and manual) at different frequencies specific to a system based on an established core control assessment schedule, and provide results to include control gaps or weaknesses, risk level, cost benefit analysis, and impact. I participate in the process to support Security Impact Analysis (SIA) for changes affecting their system to evaluate the risk levels as it impacts their system I own the process of drafting security document, reviewing and providing feedback on the application of security requirements. Monitor and execute any Information Assurance related operations and maintenance of the Information system Monitor CFTC information systems utilizing available CFTC tools and applications to ensure compliance with the Commission’s cybersecurity requirements. Report on current CFTC information systems risk levels to stakeholders on a monthly basis (POA & Ms and Monthly Scan Results). Work to remediate POAMs identified and officially recognized within CSAM and presented to SCAs and CSS leadership to conduct reviews of closed POA & Ms for completeness and compliance. Execute activities within the information system contingency planning process Develop and ensure the completeness, quality, and planning documentation including but not limited to the business impact analysis, backup and recovery strategies and requirements analysis, Information System Contingency Plan(s) and (ISCP) test.
EDUCATION
University of Maryland Baltimore County
Bachelor's Degree
University of Maryland University College
Master's Degree
Howard Community College
Associate's Degree
University of Maryland Global Campus
Certificate in Information Assurance
ABOUT TOBIAS MENSAH
As a Senior Information System Security Officer (ISSO) with over 9 years of experience, I specialize in cybersecurity risk management, compliance, and the implementation of frameworks such as NIST RMF and FedRAMP. My background includes managing key cybersecurity functions, from conducting thorough risk assessments to developing security documentation and leading systems through the Authorization to Operate (ATO) process. I have extensive experience ensuring that organizations meet federal regulations, with a focus on continuous monitoring and the safeguarding of sensitive information systems. Throughout my career, I have been responsible for leading cybersecurity initiatives that enhance organizational security and compliance. I have guided teams in achieving ATO for complex systems, managed the tracking and resolution of Change Requests and CIMs, and provided critical security insights to stakeholders through monthly risk assessments. My expertise with NIST SP 800 publications and the implementation of the Risk Management Framework has enabled me to create robust security plans that address evolving threats and protect critical data. Holding certifications such as AWS Certified Developer Associate, CompTIA Security+, and Certified Information Security Manager (CISM), I bring a comprehensive understanding of cybersecurity governance and risk mitigation I am passionate about applying my knowledge to solve complex security challenges, and I am always seeking opportunities to strengthen organizations’ defenses and ensure compliance with evolving regulations.
This profile is compiled from publicly available professional sources. Unifers is not affiliated with or endorsed by LinkedIn. Request removal of this profile.