Senior Information Systems Security Officer (ISSO)

New
A
AnaVationFederal Law Enforcement
This is a full-time position that can be performed remotely with occasional travel to Washington DC as needed.Full-TimeSenior
Salary123,206.06 - 255,318.53 USD per year
Apply NowOpens the employer's application page

Job Details

Experience
10+ years of relevant, hands-on experience in an ISSO or security compliance role
Required Skills
Cloud ComputingCybersecurity

Requirements

  • Bachelor's degree in a relevant field such as Cybersecurity or Information Assurance.
  • 10+ years of relevant, hands-on experience in an ISSO or security compliance role.
  • Deep knowledge of NIST SP 800-53 Rev 5 controls, enhancements, baselines, and assessment procedures.
  • Hands-on experience managing RMF packages and maintaining ongoing authorization.
  • Strong understanding of enterprise IT systems, networks, operating systems, identity platforms, and cloud environments (Azure, AWS, GCP).
  • Experience producing and maintaining SSPs, SARs, POA&Ms, and Continuous Monitoring Plans.
  • Familiarity with security tools such as SIEMs, vulnerability scanners, endpoint protection, and configuration management solutions.
  • Ability to articulate control requirements and translate them into technical implementations.

Responsibilities

  • Lead all RMF activities for the assigned system, including Categorization, Selection, Implementation, Assessment, Authorization, and Continuous Monitoring.
  • Oversee the design, implementation, and validation of NIST 800-53 Rev 5 security and privacy controls.
  • Develop, maintain, and update key security artifacts including System Security Plans (SSPs), Security Assessment Reports (SARs), POA&Ms, and Incident Response Plans.
  • Coordinate and support security control assessments (SCAs), penetration tests, vulnerability scans, and compliance audits.
  • Guide engineering teams on implementing and documenting new or updated security controls.
  • Lead risk assessments, document findings, and track remediation through POA&M management.
  • Manage continuous monitoring activities, including log review, vulnerability management, and patch tracking.
  • Serve as the primary security liaison for system owners, internal stakeholders, external assessors, and authorizing officials.
  • Mentor junior ISSOs and analysts in RMF, control interpretation, and documentation quality.
View Full Description & ApplyYou'll be redirected to the employer's site
123,206.06 - 255,318.53 USD per year
Apply Now