Senior Information Systems Security Officer (ISSO)

New
K
Keeper SecurityCybersecurity
Remote, USFull-TimeSenior
Salary not disclosed
Apply NowOpens the employer's application page

Job Details

Experience
5+ years
Required Skills
AWSProject Management

Requirements

  • 5+ years of experience in information security, information assurance, cybersecurity compliance, system security or a related role
  • Experience serving as an ISSO, system security analyst, compliance engineer or similar role for regulated information systems
  • Strong knowledge of NIST SP 800-53 security controls and the Risk Management Framework
  • Experience supporting FedRAMP, GovRAMP, DoD Impact Level requirements or similar government authorization programs
  • Hands-on experience developing and maintaining System Security Plans, control narratives, Plans of Action and Milestones and assessment evidence
  • Experience supporting Authorization to Operate activities, continuous monitoring and recurring security assessments
  • Ability to understand cloud and application architectures and translate technical implementations into clear security control documentation
  • Working knowledge of AWS cloud environments and cloud security concepts
  • Strong project management, documentation and organizational skills
  • Excellent written and verbal communication skills
  • U.S. Citizen
  • Ability to pass an enhanced security background check, including a financial vulnerability assessment

Responsibilities

  • Serve as the Information Systems Security Officer for assigned systems and environments
  • Maintain a comprehensive understanding of system architecture, data flows, boundaries, dependencies and security controls
  • Develop, review and maintain system security documentation, including System Security Plans, control implementation statements, policies, procedures and supporting evidence
  • Support initial and ongoing authorization activities, including FedRAMP High, GovRAMP High, DoD Impact Level 5 and related government security requirements
  • Coordinate security control implementation and validation with Engineering, DevOps, IT, Security and other system owners
  • Manage Plans of Action and Milestones, including documenting findings, assigning ownership, tracking remediation and validating closure evidence
  • Support continuous monitoring activities, including vulnerability findings, configuration compliance, control evidence, system changes and risk exceptions
  • Review proposed system, infrastructure and application changes to identify security and compliance impacts
View Full Description & ApplyYou'll be redirected to the employer's site
View details
Apply Now