
Senior Information Systems Security Officer – ISSO
Posted Aug 6

Posted Aug 6
This is a fully remote position, open to applicants in Illinois.
• Act as the Information Systems Security Officer for designated systems and environments.
• Maintain a comprehensive understanding of system architecture, data flows, boundaries, dependencies, and security controls.
• Create, review, and update System Security Plans, control implementation statements, policies, procedures, and supporting documentation.
• Assist with authorization activities including FedRAMP High, GovRAMP High, DoD Impact Level 5, and other relevant government security requirements.
• Collaborate on security control implementation and validation with Engineering, DevOps, IT, Security, and system owners.
• Oversee Plans of Action and Milestones, including findings, ownership, remediation tracking, and closure evidence.
• Support ongoing monitoring efforts, including vulnerabilities, configuration compliance, control evidence, system changes, and risk exceptions.
• Evaluate system, infrastructure, and application modifications for security and compliance implications.
• Manage responses to third-party assessors, auditors, government stakeholders, and internal compliance reviews.
• Assess security findings and determine risk, impact, corrective actions, and escalation procedures.
• Aid in incident response, contingency planning, disaster recovery, and tabletop exercises.
• Keep accurate, up-to-date, and assessment-ready audit evidence and documentation.
• Monitor security metrics, risks, findings, and remediation progress while communicating status to GRC and technical leadership.
• Ensure adherence to data classification, access control, logging, encryption, configuration, and vulnerability management requirements.
• Utilize permitted AI-enabled tools such as Claude or ChatGPT to assist with control analysis, documentation, evidence review, research, and workflow efficiency.
• Over 5 years of experience in information security, information assurance, cybersecurity compliance, system security, or a related discipline.
• Experience as an ISSO, system security analyst, compliance engineer, or a similar role for regulated information systems.
• Strong familiarity with NIST SP 800-53 security controls and the Risk Management Framework.
• Experience in supporting FedRAMP, GovRAMP, DoD Impact Level requirements, or similar government authorization initiatives.
• Practical experience in developing and maintaining System Security Plans, control narratives, Plans of Action and Milestones, and assessment evidence.
• Experience in supporting Authorization to Operate activities, continuous monitoring, and recurring security evaluations.
• Ability to comprehend cloud and application architectures and translate technical implementations into security control documentation.
• Understanding of vulnerability management, configuration management, access control, logging, encryption, incident response, and system change management.
• Experience collaborating with technical teams to implement and validate security requirements.
• Proficient knowledge of AWS cloud environments and cloud security concepts.
• Strong project management, documentation, and organizational capabilities.
• Excellent written and verbal communication skills.
• Willingness and ability to use AI-enabled tools effectively and responsibly.
• Must be a U.S. Citizen.
• Capability to pass an enhanced security background check, including a financial vulnerability assessment.
• Preferred: experience in FedRAMP High, GovRAMP High, or DoD Impact Level 5 environments.
• Preferred: experience with cloud-native SaaS products and AWS-based system architectures.
• Preferred: familiarity with automated compliance, evidence collection, and continuous monitoring tools.
• Preferred: experience with NIST SP 800-37, NIST SP 800-53A, FIPS 199, FIPS 200, and related federal security guidelines.
• Preferred: experience supporting SOC 2, ISO 27001, or other commercial compliance frameworks.
• Preferred: experience participating in third-party assessments or working directly with 3PAOs.
• Preferred: relevant certifications such as CISSP, CISM, CAP/CGRC, Security+, or CCSP.
• Preferred: experience in cybersecurity, identity security, privileged access management, or another security-sensitive software environment.
• Medical, Dental & Vision (inclusive of domestic partnerships).
• Employer Paid Life Insurance & Employee/Spouse/Child Supplemental life.
• Voluntary Short/Long Term Disability Insurance.
• 401K (Roth/Traditional).
• A generous PTO plan that acknowledges your commitment and seniority (including paid Bereavement/Jury Duty, etc.).
• Above-market annual bonuses.
OCHIN, Inc.
Dynanet Corporation
Solutions for Information Design, Inc.
Fuze Health
Get handpicked remote jobs straight to your inbox weekly.