Information Systems Security Officer (ISSO), Senior

AnaVation

• $123K — $255K *
Information Technology
8 - 10 years of experience
Job Overview by Ladders

Qualifications

  • Bachelor's Degree in Cybersecurity or Information Assurance
  • 10+ years of hands-on experience in an ISSO or security compliance role
  • Active Public Trust clearance; US citizenship required
  • In-depth knowledge of NIST SP 800-53 Rev 5 controls and assessment procedures
  • Experience managing RMF packages and maintaining authorization
  • Strong understanding of enterprise IT systems and cloud environments (Azure, AWS, GCP)
  • Excellent communication skills for engaging with stakeholders and translating security controls

Responsibilities

  • Lead RMF activities for the system, including assessment and continuous monitoring
  • Oversee design and implementation of NIST 800-53 Rev 5 security controls
  • Develop and maintain critical security documentation and artifacts
  • Coordinate security assessments, penetration tests, and compliance audits
  • Guide engineering teams in implementing security controls and modifications
  • Evaluate system changes for security impacts and necessary updates
  • Mentor junior team members in RMF and best practices

Benefits

  • Generous cost-sharing for medical insurance for employees and dependents
  • 100% company-paid dental, vision, long-term and short-term disability insurance
  • 401k plan with generous match and immediate vesting
  • Competitive pay with a generous leave and holiday package
  • Tuition and training reimbursement
  • Life and AD&D Insurance
Full Job Description
AnaVation is seeking a Senior-level ISSO to support a newly-awarded contract. The selected candidate must be able to excel as the sole ISSO to prepare a full accreditation package to quickly obtain ATT/ATO for a new digital evidence platform in support of our Federal Government client. This is a full-time position that can be performed remotely with occasional travel to Washington DC as needed.

What you will be doing
  • Lead all RMF activities for the assigned system, including Categorization, Selection, Implementation, Assessment, Authorization, and Continuous Monitoring.
  • Oversee the design, implementation, and validation of NIST 800-53 Rev 5 security and privacy controls across technical, operational, and management domains.
  • Develop, maintain, and update key security artifacts including System Security Plans (SSPs), Security Assessment Reports (SARs), POA&Ms, Incident Response Plans, and Continuous Monitoring strategies.
  • Coordinate and support security control assessments (SCAs), penetration tests, vulnerability scans, and compliance audits.
  • Guide engineering teams on implementing and documenting new or updated security controls, ensuring they align with Rev 5 enhancements and control baselines.
  • Evaluate system changes, architecture updates, and new integrations for security impact and required control modifications.
  • Lead risk assessments, document findings, and track remediation through POA&M management.
  • Manage continuous monitoring activities, including log review, vulnerability management, patch tracking, and configuration baseline validation.
  • Serve as the primary security liaison for system owners, internal stakeholders, external assessors, and authorizing officials (AOs).
  • Assist in developing security control inheritance strategies from enterprise common controls, and ensure proper documentation and alignment.
  • Mentor junior ISSOs and analysts in RMF, control interpretation, documentation quality, and security best practices.
  • Stay current on updates to NIST SP 800-53 Rev 5, 800-37, 800-30, and emerging federal cybersecurity guidance.


Required Qualifications:

  • Bachelors Degree in a relevant field such as Cybersecurity or Information Assurance
  • 10+ years of relevant, hands-on experience in an ISSO or security compliance role
  • Clearance:
    • Public Trust; US Citizenship is required
  • Other Required Skills & Qualifications:
    • Deep knowledge of NIST SP 800-53 Rev 5 controls, enhancements, baselines, and assessment procedures.
    • Hands-on experience managing RMF packages and maintaining ongoing authorization.
    • Strong understanding of enterprise IT systems, networks, operating systems, identity platforms, and cloud environments (Azure, AWS, GCP).
    • Experience producing and maintaining SSPs, SARs, POA&Ms, Continuous Monitoring Plans, and supporting RMF documentation.
    • Familiarity with security tools such as SIEMs, vulnerability scanners, endpoint protection, identity governance platforms, and configuration management solutions.
    • Strong communication skills for interfacing with system owners, engineers, auditors, and executive leadership.
    • Ability to articulate control requirements and translate them into technical implementations.


Preferred Qualifications:

  • Professional certifications such as CISSP, CISM, CAP, CCSP, or equivalent.
  • Prior experience supporting federal agencies, regulated industries, or FedRAMP systems.
  • Knowledge of NIST 800-30 (Risk Assessment), 800-37 (RMF), 800-53A (Control Assessments), and 800-137 (Continuous Monitoring).
  • Experience working in hybrid or cloud-native environments with security control inheritance patterns.
  • Background in DevSecOps or automated compliance tooling.


$123,206.06 - $255,318.53 a year

Please note: The listed salary range reflects our market-based compensation structure. Final compensation will depend on business needs, local market conditions, internal equity, and the selected candidate's skills, education, and experience.

Benefits
  • Generous cost sharing for medical insurance for the employee and dependents
  • 100% company paid dental insurance for employees and dependents
  • 100% company paid long-term and short-term disability insurance
  • 100% company paid vision insurance for employees and dependents
  • 401k plan with generous match and 100% immediate vesting
  • Competitive Pay
  • Generous paid leave and holiday package
  • Tuition and training reimbursement
  • Life and AD&D Insurance

Similar Jobs

More Jobs at AnaVation

More Information Technology Jobs

Find similar Information Systems Security Officer (ISSO), Senior jobs: