
Information System Security Officer – ISSO
Posted Jul 27

Posted Jul 27
This is a fully remote position, open to applicants in United States.
• Act as the Information System Security Officer (ISSO) for one or more ICAM-related information systems, ensuring continuous oversight and adherence to relevant federal security standards.
• Create, maintain, and revise System Security Plans (SSPs), Plans of Action and Milestones (POA&Ms), and other Authorization to Operate (ATO) documentation in compliance with NIST and agency-specific guidelines.
• Assist in the Assessment and Authorization (A&A) process, which includes facilitating security evaluations, coordinating with Security Control Assessors (SCAs), and preparing authorization packages.
• Oversee and manage the security posture of ICAM systems, encompassing identity proofing, credentialing, authentication, and access control measures.
• Analyze audit logs, security alerts, and system events to detect anomalies, potential threats, and compliance deficiencies.
• Collaborate with system administrators, developers, and engineers to ensure that security controls are effectively applied and operational as intended.
• Identify and document system vulnerabilities and risks, coordinating remediation efforts and tracking progress through the POA&M process.
• Assist in the implementation and governance of ICAM policies, procedures, and standards to align with federal mandates such as FICAM, HSPD-12, EO 14028, and OMB Memoranda.
• Engage in security incident response activities, including the investigation, containment, and reporting of security events related to identity and access management systems.
• Conduct regular security reviews and assessments to guarantee ongoing compliance with security requirements and ICAM best practices.
• Offer security guidance and recommendations to program teams concerning identity management, privileged access management (PAM), multi-factor authentication (MFA), and zero trust principles.
• Work collaboratively with cross-functional teams such as IT, compliance, and operations to ensure security practices align with organizational and mission objectives.
• Prepare and present security briefings, reports, and documentation for government stakeholders and leadership.
• Bachelor's degree in Cybersecurity, Information Technology, Computer Science, or a related field from an accredited college or university.
• A minimum of 5 years of experience in information security, including at least 2 years of direct experience in an ISSO role or a similar security position.
• Proven experience in supporting the NIST Risk Management Framework (RMF) and ATO processes.
• Familiarity with ICAM technologies and frameworks, including identity proofing, PKI, MFA, and access management solutions.
• Active security clearance or the capability to obtain the necessary security clearance.
• Outstanding communication skills in English—both written and verbal—with the ability to effectively interact with both technical and non-technical stakeholders, including government leadership.
• Solid understanding of the NIST Risk Management Framework (RMF), including NIST SP 800-53, NIST SP 800-37, and FIPS 199/200.
• Expertise in developing and maintaining ATO documentation, including SSPs, POA&Ms, Security Assessment Reports (SARs), and Interconnection Security Agreements (ISAs).
• Knowledge of ICAM concepts such as identity lifecycle management, credentialing, authentication protocols (MFA, PIV/CAC), privileged access management (PAM), and single sign-on (SSO).
• Health, dental, and vision insurance
• 401K with company matching
• Flexible spending accounts
• Paid holidays
• Three weeks paid time off
• Extraordinary benefits package
ASG Technologies
CrowdStrike
Culmen International
Threatscape
Get handpicked remote jobs straight to your inbox weekly.