
Information System Security Officer – ISSO
Posted Aug 27

Posted Aug 27
This is a fully remote position, open to applicants in Connecticut, +12 more states.
• Act as the appointed Information System Security Officer (ISSO) for FedRAMP-authorized systems
• Oversee the Authority to Operate and ongoing compliance efforts
• Lead the reporting for FedRAMP continuous monitoring on a monthly, quarterly, and annual basis
• Organize annual evaluations, independent audits, penetration tests, and security reviews with Third Party Assessment Organizations (3PAOs)
• Manage security communications with federal agencies, sponsoring organizations, and stakeholders
• Perform security risk assessments and vulnerability evaluations
• Track and address items within the Plan of Action and Milestones (POA&M)
• Assess the security implications of system modifications and assist with Significant Change Request submissions
• Ensure the application and effectiveness of NIST 800-53 controls
• Facilitate security reviews pertaining to architecture changes, technologies, and cloud deployments
• Keep FedRAMP security documentation up to date and ensure it is audit-ready
• Observe security events, incidents, and compliance metrics
• Confirm the remediation of security findings and monitor compliance Key Performance Indicators (KPIs)
• Engage in security incident investigations and responses
• Collaborate with security operations teams on identifying and addressing threats
• Support root cause analysis and corrective action strategies
• Work alongside Engineering and DevOps to embed compliance within development and deployment processes
• Provide security advice throughout the Software Development Life Cycle (SDLC)
• Assist with cloud migration, modernization, and transformation projects
• Ensure the implementation of FedRAMP-compliant security awareness training
• Matrix manage resources involved in the FedRAMP Program
• Bachelor's degree in Cybersecurity, Information Systems, Computer Science, Engineering, or a related field; equivalent professional experience may be accepted in place of degree requirements
• Over 5 years of experience in information security, cybersecurity, or compliance
• More than 3 years of experience supporting FedRAMP, FISMA, or federal compliance initiatives
• Experience in maintaining FedRAMP Moderate or High authorized environments
• Background in supporting security assessments, audits, and continuous monitoring efforts
• Familiarity with AWS, Azure, or Google Cloud platforms
• Strong knowledge of FedRAMP requirements, NIST SP 800-53, NIST 800-37 Risk Management Framework (RMF), FISMA, NIST 800-171, Zero Trust Architecture, vulnerability management, security operations, and incident response
• Experience with SIEM platforms, vulnerability scanners, Endpoint Detection and Response (EDR), Identity and Access Management (IAM), and cloud-native security services
• Preferred: CISSP, CISM, GSLC, CAP, or similar cybersecurity certification
• Preferred: experience serving as an ISSO, Security Compliance Manager, or FedRAMP Program Manager
• Preferred: experience working with federal agencies or government contractors
• Preferred: knowledge of automated compliance systems and Governance, Risk, and Compliance (GRC) tools
• Preferred: experience utilizing AI and automation for compliance reporting, evidence gathering, and POA&M management
• Preferred: experience with AWS GovCloud or Azure Government environments
• Annual incentive bonus
• Country-specific benefits
• Reasonable accommodations and adjustments during the hiring process
WorkOS
Fortive
Brown and Caldwell
Galileo
Get handpicked remote jobs straight to your inbox weekly.