Mid-Level Information System Security Officer, ISSO
Posted 2ds ago
Employment Information
Report this job
Job expired or something wrong with this job?
Job Description
ISSO owning cybersecurity posture and RMF compliance for systems supporting a large federal agency. Leading assessments, continuous monitoring, POA&M remediation, and authorization readiness.
Responsibilities:
- Own the security posture for assigned systems
- Advise on architecture, authorization boundaries, and risk decisions
- Lead control compliance and assessment readiness
- Maintain the System Security Plan and other key security artifacts
- Coordinate audits and assessments, including scheduling, evidence readiness, and responses to assessor findings
- Run continuous monitoring and reporting
- Define security metrics and escalate material risks and issues
- Drive vulnerability remediation and POA&M corrective actions, including exceptions, compensating controls, and risk acceptances
- Execute Risk Management Framework tasks across categorization, control selection, implementation, assessment, and authorization in accordance with NIST SP 800-37
- Support transition to and management of an Ongoing Authorization program
- Provide cybersecurity guidance to Business Owners and System Owners
- Liaise between stakeholders and cybersecurity staff
- Support System Owner system access reviews and account management compliance
- Apply automation and AI tooling to streamline RMF documentation, control assessments, and continuous monitoring activities
Requirements:
- Bachelor's degree in cybersecurity, information technology, or a related field
- 4 years of ISSO experience, including ownership of security posture for one or more systems
- Demonstrated experience maintaining SSPs and leading a system through assessment or authorization
- Hands-on experience managing POA&Ms, including exceptions, compensating controls, and risk acceptances
- Working knowledge of NIST SP 800-37, NIST SP 800-53, and continuous monitoring practices
- Experience advising system owners or engineering teams on risk decisions
- U.S. Citizenship or Permanent Residency
- All work must be performed within the continental U.S.
- Ability to pass a federal agency suitability or background investigation
- Prior federal contracting experience as an ISSO at a civilian agency preferred
- Experience with Ongoing Authorization or continuous ATO programs preferred
- Experience with a GRC platform such as Xacta, eMASS, CSAM, Archer, or ServiceNow IRM preferred
- Cloud authorization experience, including FedRAMP inheritance and interconnection agreements preferred
- Experience defining security metrics and reporting posture to non-technical stakeholders preferred
- Certifications such as CISSP, CGRC, CISM, or CCSP preferred
- Clear written and verbal communication with technical and non-technical audiences
- Ability to work independently and as a contributing member of a distributed team
- Comfort operating in a fully remote setting with a camera-on meeting culture
- Sound judgment about when to decide and when to escalate
- Collaborative posture with system owners, business owners, developers, and assessors
- Attention to documentation quality and follow-through on commitments
Benefits:
- Multiple POS health plan options including an HSA-compatible plan
- Dental PPO coverage for preventive, basic, and major services
- Vision coverage including annual exam, frames, lenses, and contact lens allowance
- 401(k) employer match up to 5% of eligible compensation
- 100% employer-paid long-term disability coverage at 50% of pre-disability earnings
- 100% employer-paid life insurance and AD&D coverage valued at $10,000 each
- 15–25 days of PTO annually based on tenure
- Paid observance of all 11 federal holidays


















