We are seeking an experienced Senior Information System Security Officer (ISSO) to drive Risk Management Framework (RMF) activities, security documentation, control validation, and ongoing compliance efforts across assigned enterprise systems. The ideal candidate will possess deep experience managing authorization packages, executing continuous monitoring strategies, and leading corrective action tracking in a federal environment. The Sr. ISSO role takes full ownership of maintaining system security plans, updating risk databases, and directing remediation actions with technical and operational stakeholders. This is a unique opportunity to shape the growth, development and culture of an exciting and fast-growing company in the cybersecurity market. Employment for this position is dependent on the successful award of the contract.
What you'll be doing:
- Lead the development, review, and maintenance of system security plans, risk assessments, and related authorization artifacts.
- Drive continuous monitoring activities and conduct rigorous validation of implemented security controls across complex environments.
- Develop or support Plans of Action and Milestones (POA&Ms), directing remediation activities with technical and operational stakeholders to ensure timely deficiency resolution.
- Execute system self-assessments and lead the systematic collection and verification of compliance evidence for authorization reviews.
- Manage enterprise asset, vulnerability, and compliance information within designated governance and risk tools.
- Ensure documentation quality, completeness, and alignment with federal and organizational requirements.
What you need to know:
- Strong experience as an ISSO or RMF lead in a federal cybersecurity environment.
- Familiarity with ATO processes, continuous monitoring, POA&M lifecycle management, and security documentation requirements.
- Strong organizational and documentation skills.
- Ability to coordinate effectively with government stakeholders and technical staff.
- Strong understanding of cybersecurity controls, risk management, and compliance practices.
Must have's:
- Bachelor's degree from an accredited university; a postgraduate degree from an accredited university may substitute for 6 years of experience.
- 10+ years of relevant work experience.
- Proven ability to analyze complex requirements and translate them into clear, actionable tasks and processes through critical thinking.
- Applicants must currently be a U.S. citizen and eligible to obtain and maintain a security clearance, in compliance with federal contract requirements.
Beneficial to have:
- Active DOE Q or equivalent DoD Top Secret clearance.
Where it's done:
- Onsite (Albuquerque, NM).