Remotery

Senior Information System Security Officer – Senior ISSO

Posted Aug 6

This is a fully remote position, open to applicants in United States.

📋 Description

• Act as the primary cybersecurity consultant for designated information systems throughout their lifecycle.

• Lead activities under the Risk Management Framework (RMF) that support initial authorization, ongoing authorization, annual evaluations, and continuous monitoring.

• Collaborate with System Owners, Authorizing Officials, business stakeholders, engineering teams, and Government personnel to ensure system authorization readiness.

• Create, maintain, and consistently update System Security Plans (SSPs), security documentation, authorization artifacts, and related RMF documentation.

• Oversee the implementation of security controls, evidence gathering, documentation updates, and the development of authorization packages.

• Monitor vulnerabilities, Plans of Action and Milestones (POA&Ms), risk acceptance decisions, and remediation efforts.

• Work alongside vulnerability management personnel to prioritize and address security findings.

• Coordinate with incident response teams to integrate incidents, corrective actions, and lessons learned into RMF documentation and continuous monitoring efforts.

• Assist in annual security evaluations, Security Control Assessments (SCAs), independent assessments, internal audits, and external oversight activities.

• Review assessment results, validate remediation efforts, and coordinate corrective measures.

• Contribute to security architecture, Zero Trust initiatives, and strategies for continuous monitoring.

• Manage privacy, contingency planning, incident response planning, interconnection security agreements, and other essential documentation.

• Prepare regular authorization status updates, risk summaries, and executive-level reports.

• Mentor junior Information System Security Officers (ISSO) and promote consistent RMF processes and cybersecurity best practices.

• Engage in governance meetings, risk reviews, change management, and operational planning.

• Identify opportunities to enhance authorization activities, improve documentation quality, and bolster operational coordination.


⛳️ Requirements

• Bachelor’s degree in Cybersecurity, Information Systems, Information Technology, Computer Science, or a related field.

• A minimum of five years of experience as an ISSO or in support of Federal RMF and Assessment & Authorization (A&A) programs.

• Experience with all stages of the NIST Risk Management Framework.

• Proficiency in coordinating with System Owners, security engineers, vulnerability management teams, auditors, and Government stakeholders.

• Solid understanding of NIST SP 800-37, NIST SP 800-53 Rev. 5, NIST SP 800-53A, FISMA, and Federal cybersecurity policies.

• Experience in preparing and maintaining SSPs, Security Assessment Reports (SARs), POA&Ms, security plans, contingency planning documentation, and supporting artifacts.

• Exceptional written and verbal communication skills.

• Preferred: experience in supporting NIH, HHS, or other Federal civilian agencies.

• Preferred: familiarity with JCAM, eMASS, ServiceNow GRC, Archer, or similar governance platforms.

• Preferred: experience with cloud-based systems, High Value Assets, or enterprise shared services.

• Preferred: knowledge of vulnerability management, continuous monitoring, Zero Trust implementation, and cybersecurity engineering.

• Preferred: background in FISMA reporting, audit responses, and annual security evaluations.

• Preferred: experience in supporting Continuous Diagnostics and Mitigation (CDM), continuous monitoring, or enterprise cybersecurity operations.

• Preferred: experience working within Agile development environments.

• Preferred certifications: CGRC, CISSP, CAP, CISM, Security+, or PMP.


🏝️ Benefits

• Competitive salary, paid bi-monthly.

• Top-tier medical coverage.

• 100% of medical premiums covered by True Zero.

• Company-wide new business incentive programs.

• Contribution incentives (e.g., white papers, blog posts, internal webinars, etc.).

• Three weeks of paid time off (PTO) plus 11 paid holidays annually.

• 401k program with 100% company match on the first 4%.

• Monthly reimbursement for cell phone and home internet expenses.

• Paternity/Maternity leave.

• Investment in training and certifications to enhance and expand your technical skills.

People also viewed

OCHIN, Inc.10 hours ago

Security Application Analyst

US flagUnited States OnlyFull-timeCybersecurity / Security Engineer$85.7k – $137.1k/year
ApplyView job
Dynanet Corporation10 hours ago

AI Security Engineer

US flagMaryland OnlyFull-timeCybersecurity / Security Engineer
ApplyView job
Solutions for Information Design, Inc.10 hours ago

Infrastructure & Security Engineer

US flagUnited States OnlyFull-timeCybersecurity / Security Engineer$110k – $130k/year
ApplyView job
Fuze Health11 hours ago

Senior Security Engineer

US flagArizona, +4 more statesFull-timeCybersecurity / Security Engineer$156.8k – $196k/year
ApplyView job
LG Energy Solution Vertech, Inc.12 hours ago

Cybersecurity Specialist III

US flagMassachusetts OnlyFull-timeCybersecurity / Security Engineer$98k – $110k/year
ApplyView job
Coupa Software18 hours ago

Senior Security Engineer – Red Team

IN flagIndia OnlyFull-timeCybersecurity / Security Engineer
ApplyView job

Never miss a great job!

Get handpicked remote jobs straight to your inbox weekly.

Trusted by 7,400+ designers