Information System Security Officer – ISSO

Posted Aug 27

This is a fully remote position, open to applicants in Connecticut, +12 more states.

📋 Description

• Act as the appointed Information System Security Officer (ISSO) for FedRAMP-authorized systems

• Oversee the Authority to Operate and ongoing compliance efforts

• Lead the reporting for FedRAMP continuous monitoring on a monthly, quarterly, and annual basis

• Organize annual evaluations, independent audits, penetration tests, and security reviews with Third Party Assessment Organizations (3PAOs)

• Manage security communications with federal agencies, sponsoring organizations, and stakeholders

• Perform security risk assessments and vulnerability evaluations

• Track and address items within the Plan of Action and Milestones (POA&M)

• Assess the security implications of system modifications and assist with Significant Change Request submissions

• Ensure the application and effectiveness of NIST 800-53 controls

• Facilitate security reviews pertaining to architecture changes, technologies, and cloud deployments

• Keep FedRAMP security documentation up to date and ensure it is audit-ready

• Observe security events, incidents, and compliance metrics

• Confirm the remediation of security findings and monitor compliance Key Performance Indicators (KPIs)

• Engage in security incident investigations and responses

• Collaborate with security operations teams on identifying and addressing threats

• Support root cause analysis and corrective action strategies

• Work alongside Engineering and DevOps to embed compliance within development and deployment processes

• Provide security advice throughout the Software Development Life Cycle (SDLC)

• Assist with cloud migration, modernization, and transformation projects

• Ensure the implementation of FedRAMP-compliant security awareness training

• Matrix manage resources involved in the FedRAMP Program


⛳️ Requirements

• Bachelor's degree in Cybersecurity, Information Systems, Computer Science, Engineering, or a related field; equivalent professional experience may be accepted in place of degree requirements

• Over 5 years of experience in information security, cybersecurity, or compliance

• More than 3 years of experience supporting FedRAMP, FISMA, or federal compliance initiatives

• Experience in maintaining FedRAMP Moderate or High authorized environments

• Background in supporting security assessments, audits, and continuous monitoring efforts

• Familiarity with AWS, Azure, or Google Cloud platforms

• Strong knowledge of FedRAMP requirements, NIST SP 800-53, NIST 800-37 Risk Management Framework (RMF), FISMA, NIST 800-171, Zero Trust Architecture, vulnerability management, security operations, and incident response

• Experience with SIEM platforms, vulnerability scanners, Endpoint Detection and Response (EDR), Identity and Access Management (IAM), and cloud-native security services

• Preferred: CISSP, CISM, GSLC, CAP, or similar cybersecurity certification

• Preferred: experience serving as an ISSO, Security Compliance Manager, or FedRAMP Program Manager

• Preferred: experience working with federal agencies or government contractors

• Preferred: knowledge of automated compliance systems and Governance, Risk, and Compliance (GRC) tools

• Preferred: experience utilizing AI and automation for compliance reporting, evidence gathering, and POA&M management

• Preferred: experience with AWS GovCloud or Azure Government environments


🏝️ Benefits

• Annual incentive bonus

• Country-specific benefits

• Reasonable accommodations and adjustments during the hiring process

People also viewed

WorkOS16 hours ago

Product Security Engineer

US flagUnited States, +1 more countryFull-timeCybersecurity / Security Engineer$175k – $275k/year
ApplyView job
Fortive17 hours ago

Information Security Engineer

US flagUnited States OnlyFull-timeCybersecurity / Security Engineer
ApplyView job
Brown and Caldwell17 hours ago

Cybersecurity, OT-IT Security Consultant

US flagUnited States OnlyFull-timeCybersecurity / Security Engineer$129k – $212k/year
ApplyView job
Galileo17 hours ago

IT and Security Generalist

US flagUnited States OnlyFull-timeCybersecurity / Security Engineer$110k – $120k/year
ApplyView job
Mercor17 hours ago

Cybersecurity Practitioner – SOC, Incident Response, Detection, AppSec

US flagUnited States OnlyFreelanceCybersecurity / Security Engineer$125 – $175/hour
ApplyView job
Peek18 hours ago

Security and Compliance Analyst

MX flagMexico OnlyFull-timeCybersecurity / Security Engineer$80k – $90k/month
ApplyView job

Never miss a great job!

Get handpicked remote jobs straight to your inbox weekly.

Trusted by 7,400+ designers