
Senior Information System Security Officer – ISSO
Posted Jul 31

Posted Jul 31
This is a fully remote position, open to applicants in Virginia.
• Act as the main advisor for cybersecurity and privacy matters to System Owners for designated systems.
• Oversee RMF processes, including the creation and upkeep of System Security and Privacy Plans (SSPPs), authorization packages, risk documentation, and supporting artifacts.
• Ensure that systems retain their Authorization to Operate (ATO) by providing assessment support, continuous monitoring, and adhering to NIST RMF, FISMA, and federal security standards.
• Evaluate security risks, verify the effectiveness of security controls, and coordinate the remediation of vulnerabilities along with Plans of Action and Milestones (POA&Ms).
• Maintain inventories of systems, security documentation, contingency plans, configuration management plans, and privacy-related documents.
• Work in conjunction with ISSMs, System Owners, Security Control Assessors, and technical teams to embed security within the system development lifecycle.
• Monitor the security posture of systems, analyze vulnerability and compliance scan outcomes, and assist with continuous authorization efforts.
• Offer cybersecurity guidance, formulate security policies and procedures, and conduct security awareness training.
• Assist with security engineering, certification and accreditation tasks, and the implementation of security controls across various systems.
• Suggest process enhancements and automation opportunities to improve RMF and cybersecurity operations.
• Bachelor's degree in Cybersecurity, Information Assurance, Computer Science, Information Technology, or a related discipline.
• At least 5–7 years of experience in information assurance, cybersecurity, RMF, or information system security, or an equivalent combination of education and experience.
• Proven experience in supporting federal cybersecurity initiatives and the NIST Risk Management Framework (RMF).
• Demonstrated ability to develop and maintain RMF documentation, authorization packages, and Governance, Risk, and Compliance (GRC) tools.
• Comprehensive understanding of NIST SP 800-37, NIST SP 800-53, FISMA, FIPS 199, and federal privacy regulations.
• Experience in supporting Authorization to Operate (ATO), Continuous ATO (cATO), or Continuous Authorization initiatives.
• Excellent analytical, communication, documentation, and stakeholder engagement abilities.
• Comprehensive health and wellness benefits.
• Opportunities for professional development and growth.
• Flexible work arrangements.
• Collaborative and inclusive work environment.
Legacy Community Health
NeoGuardian
Fresh Consulting
CrowdStrike
Get handpicked remote jobs straight to your inbox weekly.