
Information System Security Officer – ISSO
Posted 1 day ago

Posted 1 day ago
This is a fully remote position, open to applicants in Alabama, +42 more states.
• Act as the appointed Information System Security Officer (ISSO) for systems authorized under FedRAMP.
• Ensure the organization's Authority to Operate is maintained and compliance is consistently upheld.
• Oversee the monthly, quarterly, and annual reporting for FedRAMP continuous monitoring.
• Organize annual assessments, independent audits, penetration testing, and security reviews in collaboration with Third Party Assessment Organizations (3PAOs).
• Manage security-related communications with federal agencies, sponsoring entities, and stakeholders.
• Perform security risk assessments and vulnerability evaluations.
• Review and track Plan of Actions and Milestones (POA&M) items until remediation is complete.
• Assess security implications of system modifications and assist in submitting Significant Change Requests.
• Ensure the implementation and efficacy of NIST 800-53 controls.
• Facilitate security evaluations for changes in architecture, technologies, and cloud implementations.
• Maintain documentation related to FedRAMP security and ensure audit-ready compliance artifacts are available.
• Monitor security events, incidents, and compliance metrics effectively.
• Validate efforts to remediate issues and track key performance indicators (KPIs) related to compliance.
• Engage in investigations and responses to security incidents.
• Collaborate with Engineering and DevOps teams to embed compliance within development and deployment processes.
• Provide security guidance throughout the Software Development Life Cycle (SDLC).
• Assist with cloud migration, modernization, and technology transformation initiatives.
• Ensure that security awareness training aligns with FedRAMP requirements.
• Matrix manage personnel involved in the FedRAMP Program.
• A Bachelor's degree in Cybersecurity, Information Systems, Computer Science, Engineering, or a related discipline; equivalent professional experience may be accepted in lieu of degree.
• Over 5 years of experience in information security, cybersecurity, or compliance.
• At least 3 years of experience supporting FedRAMP, FISMA, or federal compliance initiatives.
• Experience in maintaining environments authorized as FedRAMP Moderate or High.
• Background in supporting security assessments, audits, and continuous monitoring efforts.
• Familiarity with cloud services such as AWS, Azure, or Google Cloud.
• In-depth understanding of FedRAMP requirements, NIST SP 800-53, NIST 800-37 Risk Management Framework (RMF), FISMA, NIST 800-171, Zero Trust Architecture, vulnerability management, security operations, and incident response.
• Knowledge of Security Information and Event Management (SIEM) platforms, vulnerability scanners, Endpoint Detection and Response (EDR), Identity Access Management (IAM), and cloud-native security solutions.
• Preferred qualifications include CISSP, CISM, GSLC, CAP, or similar cybersecurity certifications.
• Preferred experience in roles such as ISSO, Security Compliance Manager, or FedRAMP Program Manager.
• Preferred experience supporting federal agencies or government contractors.
• Preferred knowledge of automated compliance platforms and Governance, Risk, and Compliance (GRC) tools.
• Preferred familiarity with leveraging AI and automation for compliance reporting, evidence collection, and POA&M management.
• Preferred experience with AWS GovCloud or Azure Government environments.
• Annual incentive bonus.
• Benefits specific to the country.
• Accommodation or adjustment support during the hiring process.
Sony Interactive Entertainment
Squads
Neo4j
PingWind Inc. (SDVOSB)
Get handpicked remote jobs straight to your inbox weekly.