
Junior Information Security Officer
Posted Sep 4

Posted Sep 4
This is a fully remote position, open to applicants in District of Columbia, +1 more state.
• Create and sustain System Security Plans (SSPs) along with associated security documentation.
• Assist in efforts that facilitate systems in obtaining and retaining an Authorization to Operate (ATO).
• Provide oversight for the information systems security program pertaining to applications and systems within the ATO boundary.
• Deliver daily security support and guidance to software developers, project managers, and other team members.
• Identify effective methods to fulfill security requirements without significantly impacting delivery timelines.
• Refer intricate or unclear security concerns to the lead or senior ISSO.
• Aid in Risk Management Framework tasks such as categorization, control selection, implementation, assessment, and authorization in compliance with NIST SP 800-37.
• Support continuous monitoring efforts and ensure that authorization artifacts are kept up to date.
• Assist System Owners with system access reviews and compliance in account management.
• Contribute to automation and AI tools that enhance RMF documentation and control assessment processes.
• A Bachelor’s degree in cybersecurity, information technology, or a related discipline.
• A minimum of 2 years of ISSO experience, encompassing practical work in developing or maintaining System Security Plans.
• Proficient understanding of the Risk Management Framework and the federal authorization process (ATO).
• Familiarity with NIST SP 800-37 and NIST SP 800-53 control families.
• Capability to clearly articulate security requirements to developers and project managers.
• U.S. Citizenship or Permanent Residency, with all work conducted within the continental U.S.
• Eligibility to pass a federal agency suitability or background investigation.
• Prior federal contracting experience supporting a civilian agency ATO boundary is preferred.
• Experience with a GRC platform such as Xacta, eMASS, CSAM, Archer, or ServiceNow IRM is preferred.
• Familiarity with FedRAMP-authorized cloud services and inherited control models is preferred.
• Background in supporting POA&M tracking and remediation is preferred.
• Understanding of Ongoing Authorization or continuous ATO models is preferred.
• Certifications like Security+, CGRC (formerly CAP), or CISSP Associate are preferred.
• Strong written and verbal communication skills with both technical and non-technical audiences.
• Ability to work autonomously and as a collaborative member of a distributed team.
• Comfort in operating in a fully remote environment with a camera-on meeting culture.
• Good judgment regarding when to make decisions and when to escalate issues.
• A collaborative approach with system owners, business owners, developers, and assessors.
• Attention to detail in documentation quality and follow-through on commitments.
• Various POS health plan options including an HSA-compatible plan.
• Dental PPO coverage for preventive, basic, and major services.
• Vision coverage that includes an annual exam, frames, lenses, and a contact lens allowance.
• 401(k) employer match of up to 5% of eligible compensation.
• 100% employer-paid long-term disability coverage equating to 50% of pre-disability earnings.
• 100% employer-paid life insurance and AD&D coverage valued at $10,000 each.
• Annual PTO ranging from 15 to 25 days based on tenure.
• Observance of all 11 federal holidays.
WorkOS
Fortive
Brown and Caldwell
Galileo
Get handpicked remote jobs straight to your inbox weekly.