Information Systems Security Officer (ISSO), Senior

2 hours, 40 minutes ago
Full-time
Senior
Cybersecurity
Lever

Lever

Lever is a leading Talent Acquisition Suite that provides modern hiring and talent management solutions. Their applicant tracking system (ATS) with candidate relationship management capabilities empowers hiring teams to streamline recruiting efforts an...

Professional Services
251-1K
Founded 2012
$123M raised

Description

  • Lead all RMF activities, including categorization, control selection, implementation, assessment, authorization, and continuous monitoring.
  • Oversee implementation and validation of NIST SP 800-53 Rev. 5 security and privacy controls.
  • Develop and maintain SSPs, SARs, POA&Ms, incident response plans, and continuous monitoring strategies.
  • Coordinate security control assessments, penetration tests, vulnerability scans, and compliance audits.
  • Guide engineering teams in implementing and documenting security controls and control enhancements.
  • Evaluate system changes, architecture updates, and integrations for security impacts and control modifications.
  • Lead risk assessments, document findings, and track remediation through POA&M management.
  • Manage continuous monitoring, vulnerability management, patch tracking, log reviews, and configuration validation.
  • Act as the primary security liaison for system owners, engineers, assessors, auditors, and authorizing officials.
  • Mentor junior ISSOs and analysts on RMF, control interpretation, documentation, and security practices.

Requirements

  • Bachelor’s degree in cybersecurity, information assurance, or a related field.
  • 10+ years of hands-on experience in an ISSO or security compliance role.
  • U.S. citizenship and ability to obtain or hold a Public Trust clearance.
  • Deep knowledge of NIST SP 800-53 Rev. 5 controls, enhancements, baselines, and assessment procedures.
  • Hands-on experience managing RMF packages and maintaining ongoing authorization.
  • Understanding of enterprise IT systems, networks, operating systems, identity platforms, and cloud environments including Azure, AWS, or GCP.
  • Experience creating SSPs, SARs, POA&Ms, continuous monitoring plans, and related RMF documentation.
  • Familiarity with SIEMs, vulnerability scanners, endpoint protection, identity governance, and configuration management tools.
  • Strong communication skills and ability to translate control requirements into technical implementations.
  • Preferred: CISSP, CISM, CAP, CCSP, federal/FedRAMP experience, NIST 800-series knowledge, cloud control inheritance, DevSecOps, or automated compliance experience.

Benefits

  • Remote work with occasional travel to Washington, DC.
  • Competitive pay.
  • Medical insurance with generous employee and dependent cost sharing.
  • Company-paid dental, vision, short-term disability, and long-term disability insurance.
  • 401(k) plan with generous match and immediate 100% vesting.
  • Generous paid leave and holiday package.
  • Tuition and training reimbursement.
  • Life and AD&D insurance.

Interested in this position?

Apply directly on the company website

Apply Now

Similar Roles

Senior Detection Engineering & Threat Hunting Analyst

Huntress 251-1K Professional Services

Huntress is hiring a remote US Senior Detection Engineering and Threat Hunting Analyst to develop scalable detections and proactively identify stealthy threats across millions of endpoints and identities supporting its 24/7 SOC.

Azure Cybersecurity Git Linux macOS
1 day, 1 hour ago

Binance Accelerator Program - Internal Audit (Technology)

Binance 5K-10K Capital Markets

Binance is hiring a Technology Audit Intern for its Internal Audit team to support technology control assessments, data analysis, and audit automation across its global blockchain ecosystem.

AWS Blockchain CI/CD Cybersecurity Encryption Kubernetes Python SQL
1 day, 2 hours ago

Information System Security Officer (ISSO)

Lever 251-1K Professional Services

Spry Methods is seeking a remote Information System Security Officer (ISSO) to support the Department of the Interior’s ISSLoB Cybersecurity Program by managing NIST RMF activities, security assessments, and authorization services for customer information systems.

Cybersecurity Encryption
1 day, 2 hours ago

Security & Technology Risk Analyst

Moniepoint 1K-5K Diversified Financial Services

Moniepoint is seeking a Security & Technology Risk Analyst to assess and manage security and technology risks across its fintech ecosystem, supporting regulatory compliance, operational resilience, and informed executive decision-making.

Network Security
3 days, 1 hour ago

You're on a roll! Sign up now to keep applying.

Sign Up

Already have an account? Log in

Used by 14,729+ remote workers