Information System Security Officer (ISSO)
New
T
True Zero TechnologiesCybersecurity
100% RemoteFull-TimeMiddle
Salary not disclosed
Apply NowOpens the employer's application page
Job Details
- Experience
- Three or more years of experience supporting Federal cybersecurity, RMF, Assessment and Authorization (A&A), or information assurance programs.
- Required Skills
- Cybersecurity
Requirements
- Bachelor’s degree in Cybersecurity, Information Systems, Information Technology, Computer Science, or a related discipline.
- Three or more years of experience supporting Federal cybersecurity, RMF, Assessment and Authorization (A&A), or information assurance programs.
- Working knowledge of NIST SP 800-37, NIST SP 800-53 Rev. 5, FISMA, and Federal cybersecurity requirements.
- Experience supporting authorization package development and maintenance.
- Experience coordinating with System Owners, engineers, and Government stakeholders.
- Strong organizational, analytical, and technical writing skills.
- Excellent communication skills with the ability to coordinate activities across multiple organizations.
- Preferred: Experience supporting NIH, HHS, or other Federal civilian agencies.
- Preferred: Experience using JCAM, eMASS, ServiceNow GRC, or Archer.
- Preferred: Familiarity with cloud environments, Zero Trust initiatives, and enterprise security operations.
- Preferred Certifications: Security+, CGRC, CAP, CISSP, or CISM.
Responsibilities
- Support assigned information systems through all phases of the Risk Management Framework (RMF) lifecycle.
- Maintain System Security Plans (SSPs), security documentation, and authorization artifacts.
- Coordinate with System Owners to incorporate security requirements into system operations.
- Collect, organize, and validate evidence supporting security control implementation.
- Track vulnerabilities, POA&Ms, remediation activities, and risk acceptance decisions.
- Coordinate with vulnerability management, penetration testing, and incident response teams.
- Support annual assessments, Security Control Assessments (SCAs), and audits.
- Monitor system changes to identify impacts to authorization status.
- Assist with contingency planning, incident response planning, and privacy documentation.
- Prepare recurring authorization status reports and security summaries for stakeholders.
View Full Description & ApplyYou'll be redirected to the employer's site