Senior Information Systems Security Officer

Posted 5hrs ago

Employment Information

Education
Salary
Experience
Job Type

Report this job

Job expired or something wrong with this job?

Job Description

Senior ISSO leading RMF accreditation and cybersecurity compliance for AnaVation’s federal digital evidence platform. Preparing ATT/ATO packages and managing NIST controls, assessments, and continuous monitoring.

Responsibilities:

  • Serve as the sole Senior ISSO for a newly awarded contract
  • Prepare a full accreditation package to obtain ATT/ATO for a new digital evidence platform supporting a Federal Government client
  • Lead all RMF activities, including Categorization, Selection, Implementation, Assessment, Authorization, and Continuous Monitoring
  • Oversee design, implementation, and validation of NIST 800-53 Rev 5 security and privacy controls
  • Develop, maintain, and update SSPs, SARs, POA&Ms, Incident Response Plans, and Continuous Monitoring strategies
  • Coordinate security control assessments, penetration tests, vulnerability scans, and compliance audits
  • Guide engineering teams in implementing and documenting security controls
  • Evaluate system changes, architecture updates, and integrations for security impact
  • Lead risk assessments, document findings, and track remediation through POA&M management
  • Manage continuous monitoring, including log review, vulnerability management, patch tracking, and configuration baseline validation
  • Act as primary security liaison for system owners, stakeholders, assessors, and authorizing officials
  • Develop security control inheritance strategies and ensure documentation alignment
  • Mentor junior ISSOs and analysts
  • Stay current on federal cybersecurity guidance and NIST publications

Requirements:

  • Bachelors Degree in a relevant field such as Cybersecurity or Information Assurance
  • 10+ years of relevant, hands-on experience in an ISSO or security compliance role
  • Public Trust
  • US Citizenship is required
  • Deep knowledge of NIST SP 800-53 Rev 5 controls, enhancements, baselines, and assessment procedures
  • Hands-on experience managing RMF packages and maintaining ongoing authorization
  • Strong understanding of enterprise IT systems, networks, operating systems, identity platforms, and cloud environments (Azure, AWS, GCP)
  • Experience producing and maintaining SSPs, SARs, POA&Ms, Continuous Monitoring Plans, and supporting RMF documentation
  • Familiarity with SIEMs, vulnerability scanners, endpoint protection, identity governance platforms, and configuration management solutions
  • Ability to articulate control requirements and translate them into technical implementations
  • Strong communication skills for interfacing with system owners, engineers, auditors, and executive leadership

Benefits:

  • Generous cost sharing for medical insurance for the employee and dependents
  • 100% company paid dental insurance for employees and dependents
  • 100% company paid long-term and short-term disability insurance
  • 100% company paid vision insurance for employees and dependents
  • 401k plan with generous match and 100% immediate vesting
  • Competitive Pay
  • Generous paid leave and holiday package
  • Tuition and training reimbursement
  • Life and AD&D Insurance
  • Remote work arrangement with occasional travel to Washington DC as needed