
Information System Security Officer, ISSO
Posted Aug 6

Posted Aug 6
This is a fully remote position, open to applicants in United States.
• Provide support for designated information systems throughout all stages of the Risk Management Framework (RMF) lifecycle.
• Keep System Security Plans (SSPs), security documentation, and authorization artifacts updated to accurately represent the operational environment.
• Collaborate with System Owners to ensure that security requirements are integrated into system operations and lifecycle processes.
• Gather, organize, and verify evidence that supports the implementation of security controls and continuous monitoring efforts.
• Monitor vulnerabilities, Plans of Action and Milestones (POA&Ms), remediation efforts, risk acceptance decisions, and corrective actions to guarantee timely resolution and precise documentation.
• Work alongside vulnerability management, penetration testing, and incident response teams to incorporate cybersecurity findings into authorization documentation and ongoing monitoring activities.
• Assist with annual assessments, Security Control Assessments (SCAs), audits, and authorization reviews by managing evidence collection, documentation updates, and stakeholder involvement.
• Observe system changes to recognize potential impacts on authorization status and coordinate necessary documentation modifications.
• Aid in contingency planning, incident response planning, interconnection security agreements, privacy documentation, and other essential cybersecurity artifacts.
• Generate regular authorization status reports, remediation updates, and security summaries for Government stakeholders.
• Engage in change management, configuration management, governance meetings, and continuous monitoring activities.
• Collaborate with engineering teams to ensure that security controls are effectively implemented and documented.
• Contribute to continuous improvement initiatives that enhance authorization quality, improve accuracy of documentation, and boost operational efficiency.
• Bachelor’s degree in Cybersecurity, Information Systems, Information Technology, Computer Science, or a related field.
• A minimum of three years’ experience in Federal cybersecurity, RMF, Assessment and Authorization (A&A), or information assurance programs.
• Proficient understanding of NIST SP 800-37, NIST SP 800-53 Rev. 5, FISMA, and Federal cybersecurity regulations.
• Experience in the development and maintenance of authorization packages.
• Background in coordinating with System Owners, engineers, cybersecurity operations teams, and Government stakeholders.
• Strong organizational, analytical, and technical writing skills.
• Exceptional communication skills with the capability to coordinate activities across various organizations.
• Preferred: Experience working with NIH, HHS, or other Federal civilian agencies.
• Preferred: Familiarity with JCAM, eMASS, ServiceNow GRC, Archer, or similar governance platforms.
• Preferred: Experience with continuous monitoring, vulnerability management, POA&M management, and cybersecurity assessments.
• Preferred: Knowledge of cloud environments, Zero Trust initiatives, and enterprise security operations.
• Preferred: Experience in FISMA reporting, audit preparation, and ongoing authorization programs.
• Preferred certifications: Security+, CGRC, CAP, CISSP, or CISM.
• Competitive salary, paid twice a month.
• Top-tier medical coverage.
• True Zero covers 100% of medical premiums.
• Company-wide new business incentive programs.
• Contribution Incentives (e.g., white papers, blog posts, internal webinars, etc.).
• Starting with 3 weeks of PTO + 11 Paid Holidays Annually.
• 401k Program with a 100% company match on the first 4%.
• Monthly reimbursement for Cell Phone and Home Internet expenses.
• Paternity/Maternity Leave.
• Investment in training and certifications to enhance and expand your technical expertise.
OCHIN, Inc.
Dynanet Corporation
Solutions for Information Design, Inc.
Fuze Health
Get handpicked remote jobs straight to your inbox weekly.