Information System Security Officer – ISSO

Posted Aug 27

This is a fully remote position, open to applicants in Connecticut, +12 more states.

📋 Description

• Act as the appointed Information System Security Officer (ISSO) for systems authorized under FedRAMP.

• Oversee the organization's Authority to Operate (ATO) and assist with ongoing compliance initiatives.

• Direct FedRAMP continuous monitoring, which includes monthly, quarterly, and annual reporting duties.

• Organize annual evaluations, independent audits, penetration testing, and security assessments with Third Party Assessment Organizations (3PAOs).

• Handle security-related communications with federal agencies, sponsoring organizations, and various stakeholders.

• Execute security risk assessments and vulnerability evaluations.

• Review, analyze, and monitor Plans of Action and Milestones (POA&M) items through their remediation process.

• Assess the security implications of system modifications and assist with Significant Change Request (SCR) submissions.

• Ensure the implementation and effectiveness of NIST 800-53 security controls.

• Facilitate security evaluations for architecture modifications, new technologies, and cloud deployments.

• Maintain FedRAMP security documentation and authorize updates due to system changes.

• Ensure the collection of evidence and compliance artifacts is thorough and ready for audits.

• Oversee security events, incidents, and compliance metrics.

• Validate remediation actions and monitor compliance KPIs for leadership teams.

• Take part in security incident inquiries and response activities.

• Collaborate with security operations teams on threat detection and remediation efforts.

• Aid in root cause analysis and the planning of corrective actions.

• Enhance security monitoring tools and processes.

• Work alongside Engineering and DevOps to embed compliance into development and deployment processes.

• Provide security guidance throughout the Software Development Life Cycle (SDLC).

• Support initiatives related to cloud migration, modernization, and technology transformation.

• Ensure that compliance and security awareness training align with FedRAMP requirements.

• Matrix manage resources involved in the FedRAMP Program.


⛳️ Requirements

• Bachelor’s degree in Cybersecurity, Information Systems, Computer Science, Engineering, or a related area.

• Equivalent professional experience may be accepted in place of formal degree requirements.

• Over 5 years of experience in information security, cybersecurity, or compliance roles.

• More than 3 years of experience supporting FedRAMP, FISMA, or federal compliance programs.

• Experience in maintaining environments authorized under FedRAMP Moderate or High standards.

• Background in supporting security assessments, audits, and continuous monitoring operations.

• Familiarity with cloud platforms such as AWS, Azure, or Google Cloud.

• Strong comprehension of FedRAMP requirements, NIST SP 800-53, NIST 800-37 Risk Management Framework (RMF), FISMA, NIST 800-171, Zero Trust Architecture principles, vulnerability management processes, security operations, and incident response.

• Knowledge of SIEM platforms, vulnerability scanning tools, endpoint detection and response (EDR), Identity and Access Management (IAM), and cloud-native security services.

• Preferred: CISSP, CISM, GSLC, CAP, or an equivalent cybersecurity certification.

• Preferred: Specific experience with FedRAMP in roles such as ISSO, Security Compliance Manager, or FedRAMP Program Manager.

• Preferred: Experience working with federal agencies or government contractors.

• Preferred: Understanding of automated compliance platforms and Governance, Risk, and Compliance (GRC) tools.

• Preferred: Experience utilizing AI and automation to optimize compliance reporting, evidence gathering, and POA&M management.

• Preferred: Familiarity with AWS GovCloud or Azure Government environments.


🏝️ Benefits

• Annual incentive bonus.

• Country-specific benefits.

• Disability accommodation/support during the hiring process.

People also viewed

Sony Interactive Entertainment20 hours ago

Senior Security AI Risk Analyst

US flagCalifornia OnlyFull-timeCybersecurity / Security Engineer$167.5k – $251.3k/year
ApplyView job
Squads21 hours ago

Security Engineer

North AmericaFull-timeCybersecurity / Security Engineer$175k – $220k/year
ApplyView job
Neo4j21 hours ago

Senior Director, Product, Security and Privacy

US flagUnited States OnlyFull-timeCybersecurity / Security Engineer$260k – $300k/year
ApplyView job
PingWind Inc. (SDVOSB)22 hours ago

Cloud Security Architect – Engineer

US flagAlabama, +1 more stateFull-timeCybersecurity / Security Engineer
ApplyView job
CSCI Consulting22 hours ago

SAP S/4HANA Defense & Security Functional Lead

US flagUnited States OnlyFull-timeCybersecurity / Security Engineer
ApplyView job
Strategic Systems International23 hours ago

AI Security Engineer – AI, Agentic Security

MX flagMexico, +4 more countriesFreelanceCybersecurity / Security Engineer
ApplyView job

Never miss a great job!

Get handpicked remote jobs straight to your inbox weekly.

Trusted by 7,400+ designers