ASRC

Senior Information System Security Officer (ISSO)

ASRC$110K — $130K *
Information Technology
5 - 7 years of experience
Job Overview by Ladders

Qualifications

  • Bachelor's degree in Cybersecurity, Information Assurance, Computer Science, Information Technology, or related field.
  • 5-7 years of experience in information assurance, cybersecurity, RMF, or information system security.
  • Experience with federal cybersecurity programs and NIST RMF.
  • Proficient in developing RMF documentation and authorization packages.
  • Strong knowledge of NIST SP 800-37, NIST SP 800-53, FISMA, and privacy requirements.
  • Experience with Authorization to Operate (ATO) and Continuous ATO processes.
  • Excellent analytical, communication, and stakeholder engagement skills.

Responsibilities

  • Advise System Owners on cybersecurity and privacy requirements for assigned systems.
  • Lead and manage RMF activities including documentation and risk assessments.
  • Ensure ongoing ATO compliance through thorough assessments and continuous monitoring.
  • Assess security risks, validate controls, and coordinate remediation of vulnerabilities.
  • Maintain comprehensive security documentation and plans for the system lifecycle.
  • Collaborate with various security and technical teams to enhance system security integration.
  • Monitor the security posture and review compliance with vulnerabilities and initiatives.

Benefits

  • Competitive health care, dental, and vision insurance.
  • Life insurance options.
  • 401(k) retirement plan.
  • Education assistance to support professional development.
  • Generous paid time off including vacations, holidays, and other legally mandated leaves.
Full Job Description
ASRC Federal Data Networx is seeking a Senior Information System Security Officer (ISSO) to support federal cybersecurity and Risk Management Framework (RMF) activities for enterprise information systems. The ISSO serves as the primary cybersecurity and privacy advisor to System Owners (SOs), ensuring security and privacy requirements are integrated throughout the system lifecycle while maintaining compliance with federal regulations and Authorization to Operate (ATO) requirements.

Key Responsibilities
  • Serve as the primary cybersecurity and privacy advisor to System Owners for assigned systems.
  • Lead RMF activities, including development and maintenance of System Security and Privacy Plans (SSPPs), authorization packages, risk documentation, and supporting artifacts.
  • Ensure systems maintain Authorization to Operate (ATO) through assessment support, continuous monitoring, and compliance with NIST RMF, FISMA, and federal security requirements.
  • Assess security risks, validate security controls, and coordinate remediation of vulnerabilities and Plans of Action and Milestones (POA&Ms).
  • Maintain system inventories, security documentation, contingency plans, configuration management plans, and privacy documentation.
  • Collaborate with ISSMs, System Owners, Security Control Assessors, and technical teams to integrate security throughout the system lifecycle.
  • Monitor system security posture, review vulnerability and compliance scan results, and support continuous authorization initiatives.
  • Provide cybersecurity guidance, develop security policies and procedures, and deliver security awareness training.
  • Support security engineering, certification and accreditation activities, and implementation of security controls across systems.
  • Recommend process improvements and automation opportunities to enhance RMF and cybersecurity operations.

Required Qualifications
  • Bachelor's degree in Cybersecurity, Information Assurance, Computer Science, Information Technology, or a related field.
  • Minimum 5-7 years of experience supporting information assurance, cybersecurity, RMF, or information system security, or an equivalent combination of education and experience.
  • Experience supporting federal cybersecurity programs and the NIST Risk Management Framework (RMF).
  • Experience developing and maintaining RMF documentation, authorization packages, and Governance, Risk, and Compliance (GRC) tools.
  • Strong knowledge of NIST SP 800-37, NIST SP 800-53, FISMA, FIPS 199, and federal privacy requirements.
  • Experience supporting Authorization to Operate (ATO), Continuous ATO (cATO), or Continuous Authorization efforts.
  • Strong analytical, communication, documentation, and stakeholder engagement skills.

Required Certifications
  • Certified Information Systems Security Professional (CISSP)
  • Certified in Governance, Risk and Compliance (CGRC) or Certified Cloud Security Professional (CCSP)

Preferred Qualifications
  • Experience supporting U.S. federal civilian agencies, preferably the USPTO.
  • Experience with continuous monitoring, vulnerability management, and security automation.
  • Familiarity with cloud security, DevSecOps, and continuous authorization initiatives.
  • Knowledge of privacy compliance activities, including Privacy Threshold Assessments (PTAs), Privacy Impact Assessments (PIAs), and System of Records Notices (SORNs).

We invest in the lives of our employees, both in and out of the workplace, by providing competitive pay and benefits packages. Benefits offered may include health care, dental, vision, life insurance; 401(k); education assistance; paid time off including PTO, holidays, and any other paid leave required by law. The salary offered will depend on several factors including, but not limited to, relevant experience, skills, education, geographic location, internal equity, business needs, and other factors permitted by law. Posted pay ranges are a general guideline only and are not a guarantee of compensation or salary.

About ASRC

Arctic Slope Regional Corporation (ASRC) is an Alaska Native corporation that was established in 1972 under the Alaska Native Claims Settlement Act (ANCSA). The company is owned by approximately 13,000 Iñupiat shareholders who live primarily in eight villages on Alaska's North Slope. ASRC is a diversified company with subsidiaries involved in oil and gas exploration and production, government services, construction, and resource development. The company has a strong commitment to sustainability and environmental stewardship, and has implemented a number of initiatives to reduce its environmental impact.
Learn more about ASRC
Size
3,500 employees
Industry
Founded
2003

Similar Jobs

More Jobs at ASRC

More Information Technology Jobs

Find similar Senior Information System Security Officer (ISSO) jobs: