Remotery

Senior Information System Security Officer – ISSO

Posted Jul 31

This is a fully remote position, open to applicants in Virginia.

📋 Description

• Act as the main advisor for cybersecurity and privacy matters to System Owners for designated systems.

• Oversee RMF processes, including the creation and upkeep of System Security and Privacy Plans (SSPPs), authorization packages, risk documentation, and supporting artifacts.

• Ensure that systems retain their Authorization to Operate (ATO) by providing assessment support, continuous monitoring, and adhering to NIST RMF, FISMA, and federal security standards.

• Evaluate security risks, verify the effectiveness of security controls, and coordinate the remediation of vulnerabilities along with Plans of Action and Milestones (POA&Ms).

• Maintain inventories of systems, security documentation, contingency plans, configuration management plans, and privacy-related documents.

• Work in conjunction with ISSMs, System Owners, Security Control Assessors, and technical teams to embed security within the system development lifecycle.

• Monitor the security posture of systems, analyze vulnerability and compliance scan outcomes, and assist with continuous authorization efforts.

• Offer cybersecurity guidance, formulate security policies and procedures, and conduct security awareness training.

• Assist with security engineering, certification and accreditation tasks, and the implementation of security controls across various systems.

• Suggest process enhancements and automation opportunities to improve RMF and cybersecurity operations.


⛳️ Requirements

• Bachelor's degree in Cybersecurity, Information Assurance, Computer Science, Information Technology, or a related discipline.

• At least 5–7 years of experience in information assurance, cybersecurity, RMF, or information system security, or an equivalent combination of education and experience.

• Proven experience in supporting federal cybersecurity initiatives and the NIST Risk Management Framework (RMF).

• Demonstrated ability to develop and maintain RMF documentation, authorization packages, and Governance, Risk, and Compliance (GRC) tools.

• Comprehensive understanding of NIST SP 800-37, NIST SP 800-53, FISMA, FIPS 199, and federal privacy regulations.

• Experience in supporting Authorization to Operate (ATO), Continuous ATO (cATO), or Continuous Authorization initiatives.

• Excellent analytical, communication, documentation, and stakeholder engagement abilities.


🏝️ Benefits

• Comprehensive health and wellness benefits.

• Opportunities for professional development and growth.

• Flexible work arrangements.

• Collaborative and inclusive work environment.

People also viewed

Legacy Community Health1 day ago

IT Security Engineer

US flagTexas OnlyFull-timeCybersecurity / Security Engineer
ApplyView job
NeoGuardian1 day ago

Cyber Security Engineer I – Blue Team

BR flagBrazil OnlyFull-timeCybersecurity / Security Engineer
ApplyView job
Fresh Consulting1 day ago

Staff Software Engineer – Security, Cryptography

US flagUnited States OnlyFull-timeCybersecurity / Security Engineer
ApplyView job
CrowdStrike1 day ago

Staff AI Security Scientist

US flagUnited States OnlyFull-timeCybersecurity / Security Engineer$235k – $350k/year
ApplyView job
CrowdStrike1 day ago

Security Advisor, Falcon Complete

AU flagAustralia OnlyFull-timeCybersecurity / Security Engineer
ApplyView job
Supply Chimp1 day ago

Cybersecurity Specialist

PH flagPhilippines OnlyFull-timeCybersecurity / Security EngineerPHP 62.5k/month
ApplyView job

Never miss a great job!

Get handpicked remote jobs straight to your inbox weekly.

Trusted by 7,400+ designers