Senior Information Systems Security Officer (ISSO)
New
K
Keeper SecurityCybersecurity
Remote, USFull-TimeSenior
Salary not disclosed
Apply NowOpens the employer's application page
Job Details
- Experience
- 5+ years
- Required Skills
- AWSProject Management
Requirements
- 5+ years of experience in information security, information assurance, cybersecurity compliance, system security or a related role
- Experience serving as an ISSO, system security analyst, compliance engineer or similar role for regulated information systems
- Strong knowledge of NIST SP 800-53 security controls and the Risk Management Framework
- Experience supporting FedRAMP, GovRAMP, DoD Impact Level requirements or similar government authorization programs
- Hands-on experience developing and maintaining System Security Plans, control narratives, Plans of Action and Milestones and assessment evidence
- Experience supporting Authorization to Operate activities, continuous monitoring and recurring security assessments
- Ability to understand cloud and application architectures and translate technical implementations into clear security control documentation
- Working knowledge of AWS cloud environments and cloud security concepts
- Strong project management, documentation and organizational skills
- Excellent written and verbal communication skills
- U.S. Citizen
- Ability to pass an enhanced security background check, including a financial vulnerability assessment
Responsibilities
- Serve as the Information Systems Security Officer for assigned systems and environments
- Maintain a comprehensive understanding of system architecture, data flows, boundaries, dependencies and security controls
- Develop, review and maintain system security documentation, including System Security Plans, control implementation statements, policies, procedures and supporting evidence
- Support initial and ongoing authorization activities, including FedRAMP High, GovRAMP High, DoD Impact Level 5 and related government security requirements
- Coordinate security control implementation and validation with Engineering, DevOps, IT, Security and other system owners
- Manage Plans of Action and Milestones, including documenting findings, assigning ownership, tracking remediation and validating closure evidence
- Support continuous monitoring activities, including vulnerability findings, configuration compliance, control evidence, system changes and risk exceptions
- Review proposed system, infrastructure and application changes to identify security and compliance impacts
View Full Description & ApplyYou'll be redirected to the employer's site