Senior Information System Security Officer (ISSO)

Erp International

$145K — $185K *
Information Technology
5 - 7 years of experience
Job Overview by Ladders

Qualifications

  • Bachelor's degree in Cybersecurity or related field
  • 5+ years of cybersecurity experience in regulated environments
  • 3+ years in an ISSO or similar role
  • Experience with NIST Risk Management Framework activities
  • Proficiency with NIST SP 800-53 and FISMA compliance
  • Ability to develop security documentation and compliance artifacts
  • Strong communication skills, both written and verbal

Responsibilities

  • Support implementation of NIST Risk Management Framework (RMF)
  • Develop and review security authorization documentation
  • Conduct cybersecurity risk assessments and control analyses
  • Monitor security posture through continuous monitoring
  • Engage with stakeholders to provide cybersecurity guidance
  • Assist with incident response and post-incident reviews
  • Evaluate proposed system changes for cybersecurity impacts

Benefits

  • Remote work flexibility with occasional travel
  • Opportunity to work with federal and highly regulated organizations
  • Engagement in enterprise-level cybersecurity initiatives
  • Participation in security governance forums and technical reviews
  • Professional development opportunities with focus on compliance and risk management
Full Job Description
Overview

Location

Remote (U.S.) | Occasional Travel May Be Required

 

The selected candidate will serve as a trusted cybersecurity advisor responsible for supporting the security authorization lifecycle, ensuring compliance with federal security requirements, conducting risk assessments, supporting continuous monitoring activities, and collaborating with technical and business stakeholders to strengthen organizational security posture.

This position is ideal for professionals with experience supporting federal civilian agencies, healthcare organizations, or other highly regulated environments that require rigorous security, privacy, and compliance oversight.

 

Pay Range: $145,000 – $185,000

 

The salary range for this position is determined based on a variety of factors, including but not limited to, experience, qualifications, skill level, and location. The final salary offer will fall within this range and will be commensurate with the candidate’s background and the specific demands of the role.

 

Responsibilities

Key Responsibilities

Security Authorization & Compliance

  • Support the implementation and execution of the NIST Risk Management Framework (RMF).
  • Develop, review, and maintain security authorization documentation including:
    • System Security Plans (SSPs)
    • Security Assessment Reports (SARs)
    • Plans of Action and Milestones (POA&Ms)
    • Contingency Plans
    • Security and privacy supporting artifacts
  • Support system authorization, reauthorization, and continuous authorization activities.
  • Ensure compliance with applicable federal cybersecurity and privacy requirements.

Risk Management & Continuous Monitoring

  • Perform cybersecurity risk assessments and control analyses.
  • Monitor security posture through continuous monitoring activities.
  • Track vulnerabilities, remediation activities, and corrective action plans.
  • Support security reporting and risk communication activities.
  • Identify control deficiencies and recommend mitigation strategies.

Governance & Stakeholder Engagement

  • Participate in security governance forums and technical reviews.
  • Coordinate with system owners, engineers, developers, operations teams, and security personnel.
  • Provide cybersecurity guidance to government and contractor stakeholders.
  • Support audit readiness, compliance reviews, and independent assessments.
  • Develop executive briefings, status reports, and cybersecurity metrics.

Security Operations Support

  • Assist with incident response coordination and post-incident reviews.
  • Support security control testing and validation efforts.
  • Evaluate proposed system changes for cybersecurity impacts.
  • Participate in contingency planning and continuity activities.
Qualifications

Required Qualifications

  • Bachelor's degree in Cybersecurity, Information Systems, Computer Science, Engineering, or related field.
  • 5+ years of cybersecurity experience supporting federal, healthcare, defense, or highly regulated environments.
  • 3+ years serving as an ISSO, Information Security Specialist, Security Analyst, Security Engineer, or similar role.
  • Experience supporting NIST Risk Management Framework (RMF) activities.
  • Experience with:
    • NIST SP 800-53
    • NIST SP 800-37
    • FISMA compliance
    • Continuous Monitoring
    • Security Control Assessments
    • POA&M Management
  • Experience developing security documentation and compliance artifacts.
  • Strong written and verbal communication skills.

Preferred Qualifications

  • Experience supporting enterprise cybersecurity programs.
  • Experience working in cloud or hybrid-cloud environments.
  • Experience supporting audit readiness activities.
  • Experience working with security automation and vulnerability management platforms.
  • Experience supporting Zero Trust initiatives.
  • Experience supporting large-scale digital modernization efforts.

Preferred Certifications

One or more of the following:

  • CISSP
  • CGRC (formerly CAP)
  • CISM
  • CRISC
  • Security+
  • CEH
  • GSEC
  • GSLC

Desired Skills

  • Cybersecurity Governance
  • Risk Management
  • Continuous Monitoring
  • Vulnerability Management
  • Security Assessments
  • Compliance Monitoring
  • Security Documentation
  • Executive Reporting
  • Audit Readiness
  • Incident Response
  • Cloud Security
  • Security Architecture
  • Privacy Compliance

Clearance Requirements:

  • Must be able to obtain a government publc trust Clearance/background check

 

Standard Interview & Selection Process:

  • Recruiter Pre-Screen
  • If selected, Interview with Hiring Manager and/or Technical Lead

Similar Jobs

More Jobs at Erp International

More Information Technology Jobs

Find similar Senior Information System Security Officer (ISSO) jobs: