Senior Information System Security Officer (Senior ISSO)
New
T
True Zero TechnologiesCybersecurity
100% RemoteFull-TimeSenior
Salary not disclosed
Apply NowOpens the employer's application page
Job Details
- Experience
- Five or more years of experience serving as an ISSO or supporting Federal RMF and Assessment & Authorization (A&A) programs.
- Required Skills
- Cybersecurity
Requirements
- Bachelor’s degree in Cybersecurity, Information Systems, Information Technology, Computer Science, or a related discipline.
- Five or more years of experience serving as an ISSO or supporting Federal RMF and Assessment & Authorization (A&A) programs.
- Demonstrated experience supporting all phases of the NIST Risk Management Framework.
- Experience coordinating with System Owners, security engineers, vulnerability management teams, auditors, and Government stakeholders.
- Strong working knowledge of NIST SP 800-37, NIST SP 800-53 Rev. 5, NIST SP 800-53A, FISMA, and Federal cybersecurity policy.
- Experience preparing and maintaining authorization documentation including SSPs, SARs, POA&Ms, security plans, and contingency planning documentation.
- Excellent written and verbal communication skills.
Responsibilities
- Serve as the primary cybersecurity advisor for assigned information systems throughout the system lifecycle.
- Lead Risk Management Framework (RMF) activities supporting initial authorization, ongoing authorization, annual assessments, and continuous monitoring.
- Coordinate with System Owners, Authorizing Officials, business stakeholders, engineering teams, and Government personnel to maintain system authorization readiness.
- Develop, maintain, and continuously update System Security Plans (SSPs), security documentation, authorization artifacts, and supporting RMF documentation.
- Track vulnerabilities, POA&Ms, risk acceptance decisions, and remediation activities to ensure cybersecurity risks are appropriately managed and documented.
- Support annual security assessments, Security Control Assessments (SCAs), and independent assessments by coordinating evidence collection and stakeholder participation.
- Review assessment findings, validate remediation activities, and coordinate corrective actions with technical teams and system owners.
View Full Description & ApplyYou'll be redirected to the employer's site