Amazon Web Services (AWS) Security is seeking an Information System Security Officer (ISSO) to assess, authorize, and continuously defend information systems supporting a high-priority U.S. Government program.
In this role, you will develop, maintain, and continuously improve the System Security Plan (SSP), security control implementation evidence, and the supporting body of evidence. You will drive Assessment & Authorization (A&A) activities, coordinating security control assessments, managing Plans of Action & Milestones (POA&Ms), and sustaining continuous monitoring in accordance with the NIST Risk Management Framework (RMF). Working alongside the Information System Security Manager (ISSM), platform build and engineering teams, and U.S. Government counterparts, you will ensure controls are properly implemented, documented, and defensible throughout the full RMF lifecycle. You will also proactively identify security gaps, recommend remediation strategies, and help maintain the system's authorization posture.
This position requires U.S. Citizenship and an active TS/SCI security clearance with polygraph.
Key job responsibilities
- Develop, maintain, and continuously improve the System Security Plan (SSP) and all supporting authorization documentation.
- Prepare and maintain security control implementation evidence and the body of evidence required for system authorization.
- Coordinate and support security control assessments.
- Manage Plans of Action & Milestones (POA&Ms) from identification through closure, ensuring timely remediation of findings.
- Execute continuous monitoring activities in accordance with the NIST Risk Management Framework (RMF) and organizational policies.
- Partner with platform build and engineering teams to ensure security controls are properly implemented, configured, and documented.
- Collaborate with the Information System Security Manager (ISSM) and U.S. Government counterparts throughout the full RMF lifecycle.
- Proactively identify security gaps and vulnerabilities, recommend remediation strategies, and track resolution to completion.
- Support audit readiness and respond to ad hoc security inquiries from government stakeholders.
- Contribute to the development and refinement of security processes, templates, and automation to improve A&A efficiency.
BASIC QUALIFICATIONS
- 3+ years of RMF/A&A or ISSO experience.
- Working knowledge of NIST 800-53, RMF, and SSP development.
- Working knowledge of Service Now to apply the RMF
- Experience producing authorization artifacts and evidence.
- Current, active US Government Security Clearance of TS/SCI with Polygraph
PREFERRED QUALIFICATIONS
- Experience with U.S. Government/IC RMF and ICD 503 authorization.
- Familiarity with the Government-provided RMF workflow tooling.
- Security certification (e.g., CISSP, Security+).
The base salary range for this position is listed below. Your Amazon package will include sign-on payments and restricted stock units (RSUs). Final compensation will be determined based on factors including experience, qualifications, and location. Amazon also offers comprehensive benefits including health insurance (medical, dental, vision, prescription, Basic Life & AD&D insurance and option for Supplemental life plans, EAP, Mental Health Support, Medical Advice Line, Flexible Spending Accounts, Adoption and Surrogacy Reimbursement coverage), 401(k) matching, paid time off, and parental leave. Learn more about our benefits at https://amazon.jobs/en/benefits.
USA, VA, Herndon - 102,000.00 - 178,400.00 USD annually