
Information System Security Officer – ISSO
Posted 1 day ago

Posted 1 day ago
This is a fully remote position, open to applicants in Alabama, +42 more states.
• Act as the appointed Information System Security Officer (ISSO) for FedRAMP-certified systems.
• Oversee the Authority to Operate and ensure ongoing compliance efforts.
• Lead the continuous monitoring and reporting processes for FedRAMP.
• Organize annual evaluations, audits, penetration tests, and security assessments with Third Party Assessment Organizations (3PAOs).
• Handle security communications with federal entities, sponsors, and stakeholders.
• Perform risk assessments and vulnerability evaluations.
• Oversee the remediation of Plan of Action and Milestones (POA&M) items.
• Assess security implications of system modifications and assist with Security Change Requests (SCR) submissions.
• Maintain FedRAMP security documentation and ensure audit-ready compliance artifacts.
• Track security events, incidents, compliance indicators, and key performance metrics.
• Engage in incident investigations and response activities.
• Collaborate with Engineering and DevOps to embed compliance into the development and deployment processes.
• Offer security advice throughout the Software Development Life Cycle (SDLC).
• Assist with cloud migration, modernization, and transformation projects.
• Matrix manage personnel involved in the FedRAMP Program.
• Bachelor's degree in Cybersecurity, Information Systems, Computer Science, Engineering, or a related discipline.
• Relevant work experience may be accepted in place of educational qualifications.
• Over 5 years of experience in information security, cybersecurity, or compliance.
• More than 3 years of experience supporting FedRAMP, FISMA, or federal compliance initiatives.
• Experience in managing FedRAMP Moderate or High authorized environments.
• Background in supporting security assessments, audits, and continuous monitoring operations.
• Familiarity with AWS, Azure, or Google Cloud platforms.
• In-depth knowledge of FedRAMP standards, NIST SP 800-53, NIST 800-37 Risk Management Framework (RMF), FISMA, NIST 800-171, Zero Trust Architecture, vulnerability management, security operations, and incident response.
• Experience with Security Information and Event Management (SIEM) systems, vulnerability scanning tools, Endpoint Detection and Response (EDR), Identity Access Management (IAM), and cloud-native security solutions.
• Annual incentive bonus.
• Benefits tailored to specific countries.
• Support for disability accommodations.
Sony Interactive Entertainment
Squads
Neo4j
PingWind Inc. (SDVOSB)
Get handpicked remote jobs straight to your inbox weekly.