
Senior Information Systems Security Officer
Posted 3 days ago

Posted 3 days ago
This is a fully remote position, open to applicants in Virginia, +1 more state.
• Act as the primary Senior ISSO for a recently awarded contract.
• Create a comprehensive accreditation package to secure ATT/ATO for a new digital evidence platform catering to a Federal Government client.
• Direct all RMF activities, encompassing Categorization, Selection, Implementation, Assessment, Authorization, and Continuous Monitoring.
• Supervise the design, implementation, and validation of NIST 800-53 Rev 5 security and privacy controls.
• Formulate, maintain, and revise SSPs, SARs, POA&Ms, Incident Response Plans, and Continuous Monitoring strategies.
• Coordinate security control assessments, penetration testing, vulnerability scanning, and compliance audits.
• Provide guidance to engineering teams in implementing and documenting security controls.
• Assess system modifications, architectural updates, and integrations for security implications.
• Conduct risk assessments, document results, and manage remediation through POA&M oversight.
• Oversee continuous monitoring activities, including log analysis, vulnerability management, patch tracking, and configuration baseline validation.
• Serve as the main security point of contact for system owners, stakeholders, assessors, and authorizing officials.
• Develop strategies for security control inheritance and ensure alignment of documentation.
• Mentor junior ISSOs and analysts.
• Keep abreast of federal cybersecurity directives and NIST publications.
• Bachelor’s Degree in a relevant discipline such as Cybersecurity or Information Assurance.
• Over 10 years of relevant, hands-on experience in an ISSO or security compliance capacity.
• Possess Public Trust clearance.
• Must be a US citizen.
• Extensive knowledge of NIST SP 800-53 Rev 5 controls, enhancements, baselines, and assessment methodologies.
• Practical experience with managing RMF packages and sustaining ongoing authorization.
• Strong comprehension of enterprise IT systems, networks, operating systems, identity platforms, and cloud environments (Azure, AWS, GCP).
• Experience in producing and maintaining SSPs, SARs, POA&Ms, Continuous Monitoring Plans, and supporting RMF documentation.
• Familiarity with SIEMs, vulnerability scanners, endpoint protection, identity governance platforms, and configuration management solutions.
• Capability to articulate control requirements and convert them into technical implementations.
• Excellent communication skills for interaction with system owners, engineers, auditors, and executive leadership.
• Generous cost sharing for medical insurance for both the employee and their dependents.
• 100% company-paid dental insurance for employees and their dependents.
• 100% company-funded long-term and short-term disability insurance.
• 100% company-covered vision insurance for employees and dependents.
• 401k plan with a generous match and immediate 100% vesting.
• Competitive compensation.
• Generous paid leave and holiday benefits.
• Tuition and training reimbursement.
• Life and AD&D Insurance.
• Remote work flexibility with occasional travel to Washington DC as required.
Sony Interactive Entertainment
Squads
Neo4j
PingWind Inc. (SDVOSB)
Get handpicked remote jobs straight to your inbox weekly.