Mid-Level Information System Security Officer, ISSO

Posted Sep 15

This is a fully remote position, open to applicants in United States.

📋 Description

• Take ownership of the security posture for designated systems.

• Provide guidance on architecture, authorization boundaries, and risk-related decisions.

• Lead efforts in control compliance and prepare for assessments.

• Keep the System Security Plan and other essential security documents updated.

• Organize audits and assessments, managing scheduling, evidence preparation, and responses to findings from assessors.

• Conduct ongoing monitoring and generate reports.

• Establish security metrics and escalate significant risks and issues.

• Facilitate vulnerability remediation and the development of Plan of Actions and Milestones (POA&M) corrective measures, including exceptions, compensating controls, and risk acceptances.

• Implement Risk Management Framework activities including categorization, control selection, implementation, assessment, and authorization according to NIST SP 800-37.

• Assist in the transition to and management of an Ongoing Authorization program.

• Offer cybersecurity advice to Business Owners and System Owners.

• Serve as a liaison between stakeholders and the cybersecurity team.

• Aid System Owners with system access reviews and ensure account management compliance.

• Utilize automation and AI tools to enhance RMF documentation, control assessments, and continuous monitoring tasks.


⛳️ Requirements

• A Bachelor’s degree in cybersecurity, information technology, or a related discipline.

• A minimum of 4 years of experience as an Information System Security Officer (ISSO), with responsibility for the security posture of one or more systems.

• Proven experience in maintaining System Security Plans (SSPs) and guiding systems through assessment or authorization processes.

• Practical experience overseeing Plans of Action and Milestones (POA&Ms), including handling exceptions, compensating controls, and risk acceptances.

• Familiarity with NIST SP 800-37, NIST SP 800-53, and practices for continuous monitoring.

• Experience in advising system owners or engineering teams on risk-related decisions.

• Must be a U.S. citizen or Permanent Resident.

• All work must be conducted within the continental United States.

• Ability to successfully pass a federal agency suitability or background investigation.

• Preferred prior experience as an ISSO in federal contracting at a civilian agency.

• Experience with Ongoing Authorization or continuous Authority to Operate (ATO) programs is preferred.

• Familiarity with Governance, Risk, and Compliance (GRC) platforms such as Xacta, eMASS, CSAM, Archer, or ServiceNow IRM is preferred.

• Preferred experience in cloud authorization, including FedRAMP inheritance and interconnection agreements.

• Experience in defining security metrics and communicating posture to non-technical stakeholders is preferred.

• Relevant certifications such as CISSP, CGRC, CISM, or CCSP are preferred.

• Ability to communicate clearly in writing and verbally with both technical and non-technical audiences.

• Capability to work independently as well as collaboratively within a distributed team.

• Comfort in a fully remote work environment with a culture of camera-on meetings.

• Sound judgment in deciding when to act independently and when to escalate issues.

• Cooperative approach with system owners, business owners, developers, and assessors.

• Strong attention to the quality of documentation and commitment follow-through.


🏝️ Benefits

• Various health plan options, including a plan compatible with Health Savings Accounts (HSA).

• Dental PPO coverage for preventive, basic, and major services.

• Vision coverage that includes an annual exam, frames, lenses, and an allowance for contact lenses.

• 401(k) employer matching up to 5% of eligible compensation.

• 100% employer-funded long-term disability insurance covering 50% of pre-disability earnings.

• 100% employer-funded life insurance and Accidental Death & Dismemberment (AD&D) coverage valued at $10,000 each.

• Annual PTO ranging from 15 to 25 days, depending on tenure.

• Paid observance of all 11 federal holidays.

People also viewed

WorkOS1 day ago

Product Security Engineer

US flagUnited States, +1 more countryFull-timeCybersecurity / Security Engineer$175k – $275k/year
ApplyView job
Fortive1 day ago

Information Security Engineer

US flagUnited States OnlyFull-timeCybersecurity / Security Engineer
ApplyView job
Brown and Caldwell1 day ago

Cybersecurity, OT-IT Security Consultant

US flagUnited States OnlyFull-timeCybersecurity / Security Engineer$129k – $212k/year
ApplyView job
Galileo1 day ago

IT and Security Generalist

US flagUnited States OnlyFull-timeCybersecurity / Security Engineer$110k – $120k/year
ApplyView job
Mercor1 day ago

Cybersecurity Practitioner – SOC, Incident Response, Detection, AppSec

US flagUnited States OnlyFreelanceCybersecurity / Security Engineer$125 – $175/hour
ApplyView job
Peek1 day ago

Security and Compliance Analyst

MX flagMexico OnlyFull-timeCybersecurity / Security Engineer$80k – $90k/month
ApplyView job

Never miss a great job!

Get handpicked remote jobs straight to your inbox weekly.

Trusted by 7,400+ designers