Senior Information System Security Officer – ISSO

Posted Sep 4

This is a fully remote position, open to applicants in District of Columbia, +1 more state.

📋 Description

• Take charge of the security posture for designated systems, providing guidance on architecture, authorization boundaries, and risk-related decisions.

• Lead compliance with controls and readiness for assessments, ensuring the upkeep of essential artifacts such as the System Security Plan.

• Organize audits and assessments, which includes scheduling, preparing evidence, and responding to findings from assessors.

• Conduct continuous monitoring and reporting, establishing metrics and escalating significant risks and issues.

• Propel vulnerability remediation and corrective actions within the POA&M, including exceptions, compensating controls, and risk acceptances.

• Carry out Risk Management Framework tasks for categorization, control selection, implementation, assessment, and authorization in line with NIST SP 800-37.

• Aid in the transition to and oversee an Ongoing Authorization program.

• Offer cybersecurity advice to Business Owners and System Owners, acting as a liaison between these stakeholders and the cybersecurity team.

• Assist System Owners with system access reviews and compliance in account management.

• Utilize automation and AI tools to enhance the efficiency of RMF documentation, control assessments, and continuous monitoring activities.


⛳️ Requirements

• A Bachelor's degree in cybersecurity, information technology, or a related discipline.

• A minimum of 4 years of ISSO experience, with responsibility for the security posture of one or more systems.

• Proven experience in maintaining SSPs and guiding a system through assessment or authorization processes.

• Practical experience in managing POA&Ms, including exceptions, compensating controls, and risk acceptances.

• Familiarity with NIST SP 800-37 and NIST SP 800-53, along with knowledge of continuous monitoring practices.

• Experience in advising system owners or engineering teams on risk-related decisions.

• Must be a U.S. Citizen or Permanent Resident, with all work conducted within the continental U.S.

• Capability to pass a federal agency suitability or background investigation.

• Preferred: Prior federal contracting experience as an ISSO at a civilian agency.

• Preferred: Experience with Ongoing Authorization or continuous ATO programs.

• Preferred: Familiarity with GRC platforms such as Xacta, eMASS, CSAM, Archer, or ServiceNow IRM.

• Preferred: Experience with cloud authorization, including FedRAMP inheritance and interconnection agreements.

• Preferred: Ability to define security metrics and report posture to non-technical stakeholders.

• Preferred: Relevant certifications such as CISSP, CGRC (formerly CAP), CISM, or CCSP.

• Proficiency in ownership of system security posture and risk-based decision support.

• Expertise in developing and maintaining SSP and authorization artifacts.

• Execution of the Risk Management Framework under NIST SP 800-37.

• Readiness for security control assessments as per NIST SP 800-53A.

• Management of POA&Ms, including compensating controls, exceptions, and risk acceptance.

• Involvement in continuous monitoring, security metrics definition, and posture reporting.

• Coordination of vulnerability management and remediation efforts.

• Knowledge of GRC tooling and cloud authorization models, including FedRAMP.

• Strong written and verbal communication skills for both technical and non-technical audiences.

• Ability to work independently and collaboratively as part of a distributed team.

• Comfortable working in a fully remote environment with a culture of video meetings.

• Sound judgment regarding when to make decisions and when to escalate issues.

• A collaborative approach with system owners, business owners, developers, and assessors.

• Strong attention to detail in documentation quality and follow-through on commitments.


🏝️ Benefits

• Medical: Multiple POS health plan options, including an HSA-compatible plan.

• Dental: PPO coverage for preventive, basic, and major services.

• Vision: Annual exam, frames, lenses, and contact lens allowance.

• 401(k): Employer match up to 5% of eligible compensation.

• Long-Term Disability: 100% employer-paid coverage at 50% of pre-disability earnings.

• Life Insurance & AD&D: 100% employer-paid coverage valued at $10,000 each.

• PTO: 15–25 days annually based on tenure.

• Paid Federal Holidays: All 11 federal holidays observed.

People also viewed

WorkOS1 day ago

Product Security Engineer

US flagUnited States, +1 more countryFull-timeCybersecurity / Security Engineer$175k – $275k/year
ApplyView job
Fortive1 day ago

Information Security Engineer

US flagUnited States OnlyFull-timeCybersecurity / Security Engineer
ApplyView job
Brown and Caldwell1 day ago

Cybersecurity, OT-IT Security Consultant

US flagUnited States OnlyFull-timeCybersecurity / Security Engineer$129k – $212k/year
ApplyView job
Galileo1 day ago

IT and Security Generalist

US flagUnited States OnlyFull-timeCybersecurity / Security Engineer$110k – $120k/year
ApplyView job
Mercor1 day ago

Cybersecurity Practitioner – SOC, Incident Response, Detection, AppSec

US flagUnited States OnlyFreelanceCybersecurity / Security Engineer$125 – $175/hour
ApplyView job
Peek1 day ago

Security and Compliance Analyst

MX flagMexico OnlyFull-timeCybersecurity / Security Engineer$80k – $90k/month
ApplyView job

Never miss a great job!

Get handpicked remote jobs straight to your inbox weekly.

Trusted by 7,400+ designers