
Information System Security Officer – ISSO
Posted Aug 27

Posted Aug 27
This is a fully remote position, open to applicants in Connecticut, +12 more states.
• Act as the appointed Information System Security Officer (ISSO) for systems authorized under FedRAMP.
• Oversee the organization's Authority to Operate (ATO) and assist with ongoing compliance initiatives.
• Direct FedRAMP continuous monitoring, which includes monthly, quarterly, and annual reporting duties.
• Organize annual evaluations, independent audits, penetration testing, and security assessments with Third Party Assessment Organizations (3PAOs).
• Handle security-related communications with federal agencies, sponsoring organizations, and various stakeholders.
• Execute security risk assessments and vulnerability evaluations.
• Review, analyze, and monitor Plans of Action and Milestones (POA&M) items through their remediation process.
• Assess the security implications of system modifications and assist with Significant Change Request (SCR) submissions.
• Ensure the implementation and effectiveness of NIST 800-53 security controls.
• Facilitate security evaluations for architecture modifications, new technologies, and cloud deployments.
• Maintain FedRAMP security documentation and authorize updates due to system changes.
• Ensure the collection of evidence and compliance artifacts is thorough and ready for audits.
• Oversee security events, incidents, and compliance metrics.
• Validate remediation actions and monitor compliance KPIs for leadership teams.
• Take part in security incident inquiries and response activities.
• Collaborate with security operations teams on threat detection and remediation efforts.
• Aid in root cause analysis and the planning of corrective actions.
• Enhance security monitoring tools and processes.
• Work alongside Engineering and DevOps to embed compliance into development and deployment processes.
• Provide security guidance throughout the Software Development Life Cycle (SDLC).
• Support initiatives related to cloud migration, modernization, and technology transformation.
• Ensure that compliance and security awareness training align with FedRAMP requirements.
• Matrix manage resources involved in the FedRAMP Program.
• Bachelor’s degree in Cybersecurity, Information Systems, Computer Science, Engineering, or a related area.
• Equivalent professional experience may be accepted in place of formal degree requirements.
• Over 5 years of experience in information security, cybersecurity, or compliance roles.
• More than 3 years of experience supporting FedRAMP, FISMA, or federal compliance programs.
• Experience in maintaining environments authorized under FedRAMP Moderate or High standards.
• Background in supporting security assessments, audits, and continuous monitoring operations.
• Familiarity with cloud platforms such as AWS, Azure, or Google Cloud.
• Strong comprehension of FedRAMP requirements, NIST SP 800-53, NIST 800-37 Risk Management Framework (RMF), FISMA, NIST 800-171, Zero Trust Architecture principles, vulnerability management processes, security operations, and incident response.
• Knowledge of SIEM platforms, vulnerability scanning tools, endpoint detection and response (EDR), Identity and Access Management (IAM), and cloud-native security services.
• Preferred: CISSP, CISM, GSLC, CAP, or an equivalent cybersecurity certification.
• Preferred: Specific experience with FedRAMP in roles such as ISSO, Security Compliance Manager, or FedRAMP Program Manager.
• Preferred: Experience working with federal agencies or government contractors.
• Preferred: Understanding of automated compliance platforms and Governance, Risk, and Compliance (GRC) tools.
• Preferred: Experience utilizing AI and automation to optimize compliance reporting, evidence gathering, and POA&M management.
• Preferred: Familiarity with AWS GovCloud or Azure Government environments.
• Annual incentive bonus.
• Country-specific benefits.
• Disability accommodation/support during the hiring process.
Sony Interactive Entertainment
Squads
Neo4j
PingWind Inc. (SDVOSB)
Get handpicked remote jobs straight to your inbox weekly.