Job Type
Full-time
Description
Position Summary:
The Information System Security Officer (ISSO) is responsible for maintaining the security posture and authorization of the system. You will manage the Risk Management Framework (RMF) lifecycle, maintain ATO documentation and continuous-monitoring artifacts, and ensure the system remains compliant with NIST 800-53 and federal security requirements.
Key Responsibilities:
- Maintain the system's Risk Management Framework (RMF) documentation and ATO package
- Manage security control implementation evidence against NIST 800-53 / FedRAMP
- Track and remediate findings via POA&Ms and coordinate continuous monitoring
- Support security assessments, audits, and authorization activities
- Coordinate with the client ISSM, security teams, and DevSecOps on compliance
- Review changes for security impact and maintain security baselines
- Report security posture, risks, and incidents to program and client stakeholders
PHYSICAL DEMANDS:
- Reasonable accommodations may be made to enable individuals with disabilities to perform the essential functions
Requirements
Non-Technical Requirements:
- Must be a U.S. Citizen.
- Must be willing to work a HYRBID Schedule (2 Days) in Reston, VA & client locations in the Washington D.C. area as required.
- Ability to pass a 7-year background check and obtain/maintain a U.S. Government Clearance
- Strong communication and presentation skills.
- Must be able to prioritize and self-start.
- Must be adaptable/flexible as priorities shift.
- Must be enthusiastic and have passion for learning and constant improvement.
- Must be open to collaboration, feedback and client asks.
- Must enjoy working with a vibrant team of outgoing personalities.
Required Qualifications:
- CISSP, CAP, or equivalent security certification
- 5+ years of information system security / ISSO experience
- Strong knowledge of RMF, NIST 800-53, and federal ATO processes
- Experience with continuous monitoring and POA&M management
Preferred Qualifications:
- FedRAMP and cloud (AWS) security experience
- Financial-regulatory security experience
- Experience with security automation and GRC tooling
Salary Description
$200,000-$220,000 (based on pertinent experience)