Senior Information System Security Officer (Senior ISSO)

New
100% RemoteFull-TimeSenior
Salary not disclosed
Apply NowOpens the employer's application page

Job Details

Experience
Five or more years of experience serving as an ISSO or supporting Federal RMF and Assessment & Authorization (A&A) programs.
Required Skills
Cybersecurity

Requirements

  • Bachelor’s degree in Cybersecurity, Information Systems, Information Technology, Computer Science, or a related discipline.
  • Five or more years of experience serving as an ISSO or supporting Federal RMF and Assessment & Authorization (A&A) programs.
  • Demonstrated experience supporting all phases of the NIST Risk Management Framework.
  • Experience coordinating with System Owners, security engineers, vulnerability management teams, auditors, and Government stakeholders.
  • Strong working knowledge of NIST SP 800-37, NIST SP 800-53 Rev. 5, NIST SP 800-53A, FISMA, and Federal cybersecurity policy.
  • Experience preparing and maintaining authorization documentation including SSPs, SARs, POA&Ms, security plans, and contingency planning documentation.
  • Excellent written and verbal communication skills.

Responsibilities

  • Serve as the primary cybersecurity advisor for assigned information systems throughout the system lifecycle.
  • Lead Risk Management Framework (RMF) activities supporting initial authorization, ongoing authorization, annual assessments, and continuous monitoring.
  • Coordinate with System Owners, Authorizing Officials, business stakeholders, engineering teams, and Government personnel to maintain system authorization readiness.
  • Develop, maintain, and continuously update System Security Plans (SSPs), security documentation, authorization artifacts, and supporting RMF documentation.
  • Track vulnerabilities, POA&Ms, risk acceptance decisions, and remediation activities to ensure cybersecurity risks are appropriately managed and documented.
  • Support annual security assessments, Security Control Assessments (SCAs), and independent assessments by coordinating evidence collection and stakeholder participation.
  • Review assessment findings, validate remediation activities, and coordinate corrective actions with technical teams and system owners.
View Full Description & ApplyYou'll be redirected to the employer's site
View details
Apply Now