
Mid-Level Information System Security Officer, ISSO
Posted Sep 15

Posted Sep 15
This is a fully remote position, open to applicants in United States.
• Take ownership of the security posture for designated systems.
• Provide guidance on architecture, authorization boundaries, and risk-related decisions.
• Lead efforts in control compliance and prepare for assessments.
• Keep the System Security Plan and other essential security documents updated.
• Organize audits and assessments, managing scheduling, evidence preparation, and responses to findings from assessors.
• Conduct ongoing monitoring and generate reports.
• Establish security metrics and escalate significant risks and issues.
• Facilitate vulnerability remediation and the development of Plan of Actions and Milestones (POA&M) corrective measures, including exceptions, compensating controls, and risk acceptances.
• Implement Risk Management Framework activities including categorization, control selection, implementation, assessment, and authorization according to NIST SP 800-37.
• Assist in the transition to and management of an Ongoing Authorization program.
• Offer cybersecurity advice to Business Owners and System Owners.
• Serve as a liaison between stakeholders and the cybersecurity team.
• Aid System Owners with system access reviews and ensure account management compliance.
• Utilize automation and AI tools to enhance RMF documentation, control assessments, and continuous monitoring tasks.
• A Bachelor’s degree in cybersecurity, information technology, or a related discipline.
• A minimum of 4 years of experience as an Information System Security Officer (ISSO), with responsibility for the security posture of one or more systems.
• Proven experience in maintaining System Security Plans (SSPs) and guiding systems through assessment or authorization processes.
• Practical experience overseeing Plans of Action and Milestones (POA&Ms), including handling exceptions, compensating controls, and risk acceptances.
• Familiarity with NIST SP 800-37, NIST SP 800-53, and practices for continuous monitoring.
• Experience in advising system owners or engineering teams on risk-related decisions.
• Must be a U.S. citizen or Permanent Resident.
• All work must be conducted within the continental United States.
• Ability to successfully pass a federal agency suitability or background investigation.
• Preferred prior experience as an ISSO in federal contracting at a civilian agency.
• Experience with Ongoing Authorization or continuous Authority to Operate (ATO) programs is preferred.
• Familiarity with Governance, Risk, and Compliance (GRC) platforms such as Xacta, eMASS, CSAM, Archer, or ServiceNow IRM is preferred.
• Preferred experience in cloud authorization, including FedRAMP inheritance and interconnection agreements.
• Experience in defining security metrics and communicating posture to non-technical stakeholders is preferred.
• Relevant certifications such as CISSP, CGRC, CISM, or CCSP are preferred.
• Ability to communicate clearly in writing and verbally with both technical and non-technical audiences.
• Capability to work independently as well as collaboratively within a distributed team.
• Comfort in a fully remote work environment with a culture of camera-on meetings.
• Sound judgment in deciding when to act independently and when to escalate issues.
• Cooperative approach with system owners, business owners, developers, and assessors.
• Strong attention to the quality of documentation and commitment follow-through.
• Various health plan options, including a plan compatible with Health Savings Accounts (HSA).
• Dental PPO coverage for preventive, basic, and major services.
• Vision coverage that includes an annual exam, frames, lenses, and an allowance for contact lenses.
• 401(k) employer matching up to 5% of eligible compensation.
• 100% employer-funded long-term disability insurance covering 50% of pre-disability earnings.
• 100% employer-funded life insurance and Accidental Death & Dismemberment (AD&D) coverage valued at $10,000 each.
• Annual PTO ranging from 15 to 25 days, depending on tenure.
• Paid observance of all 11 federal holidays.
WorkOS
Fortive
Brown and Caldwell
Galileo
Get handpicked remote jobs straight to your inbox weekly.