
Senior Information System Security Officer – ISSO
Posted Sep 4

Posted Sep 4
This is a fully remote position, open to applicants in District of Columbia, +1 more state.
• Take charge of the security posture for designated systems, providing guidance on architecture, authorization boundaries, and risk-related decisions.
• Lead compliance with controls and readiness for assessments, ensuring the upkeep of essential artifacts such as the System Security Plan.
• Organize audits and assessments, which includes scheduling, preparing evidence, and responding to findings from assessors.
• Conduct continuous monitoring and reporting, establishing metrics and escalating significant risks and issues.
• Propel vulnerability remediation and corrective actions within the POA&M, including exceptions, compensating controls, and risk acceptances.
• Carry out Risk Management Framework tasks for categorization, control selection, implementation, assessment, and authorization in line with NIST SP 800-37.
• Aid in the transition to and oversee an Ongoing Authorization program.
• Offer cybersecurity advice to Business Owners and System Owners, acting as a liaison between these stakeholders and the cybersecurity team.
• Assist System Owners with system access reviews and compliance in account management.
• Utilize automation and AI tools to enhance the efficiency of RMF documentation, control assessments, and continuous monitoring activities.
• A Bachelor's degree in cybersecurity, information technology, or a related discipline.
• A minimum of 4 years of ISSO experience, with responsibility for the security posture of one or more systems.
• Proven experience in maintaining SSPs and guiding a system through assessment or authorization processes.
• Practical experience in managing POA&Ms, including exceptions, compensating controls, and risk acceptances.
• Familiarity with NIST SP 800-37 and NIST SP 800-53, along with knowledge of continuous monitoring practices.
• Experience in advising system owners or engineering teams on risk-related decisions.
• Must be a U.S. Citizen or Permanent Resident, with all work conducted within the continental U.S.
• Capability to pass a federal agency suitability or background investigation.
• Preferred: Prior federal contracting experience as an ISSO at a civilian agency.
• Preferred: Experience with Ongoing Authorization or continuous ATO programs.
• Preferred: Familiarity with GRC platforms such as Xacta, eMASS, CSAM, Archer, or ServiceNow IRM.
• Preferred: Experience with cloud authorization, including FedRAMP inheritance and interconnection agreements.
• Preferred: Ability to define security metrics and report posture to non-technical stakeholders.
• Preferred: Relevant certifications such as CISSP, CGRC (formerly CAP), CISM, or CCSP.
• Proficiency in ownership of system security posture and risk-based decision support.
• Expertise in developing and maintaining SSP and authorization artifacts.
• Execution of the Risk Management Framework under NIST SP 800-37.
• Readiness for security control assessments as per NIST SP 800-53A.
• Management of POA&Ms, including compensating controls, exceptions, and risk acceptance.
• Involvement in continuous monitoring, security metrics definition, and posture reporting.
• Coordination of vulnerability management and remediation efforts.
• Knowledge of GRC tooling and cloud authorization models, including FedRAMP.
• Strong written and verbal communication skills for both technical and non-technical audiences.
• Ability to work independently and collaboratively as part of a distributed team.
• Comfortable working in a fully remote environment with a culture of video meetings.
• Sound judgment regarding when to make decisions and when to escalate issues.
• A collaborative approach with system owners, business owners, developers, and assessors.
• Strong attention to detail in documentation quality and follow-through on commitments.
• Medical: Multiple POS health plan options, including an HSA-compatible plan.
• Dental: PPO coverage for preventive, basic, and major services.
• Vision: Annual exam, frames, lenses, and contact lens allowance.
• 401(k): Employer match up to 5% of eligible compensation.
• Long-Term Disability: 100% employer-paid coverage at 50% of pre-disability earnings.
• Life Insurance & AD&D: 100% employer-paid coverage valued at $10,000 each.
• PTO: 15–25 days annually based on tenure.
• Paid Federal Holidays: All 11 federal holidays observed.
WorkOS
Fortive
Brown and Caldwell
Galileo
Get handpicked remote jobs straight to your inbox weekly.