Information System Security Officer (ISSO) (R-00183)

3 days, 16 hours ago
Full-time
Mid Level
Cybersecurity
True Zero Technologies

True Zero Technologies

True Zero Technologies specializes in cybersecurity programs and software solutions, focusing on proactive defense and IT engineering services.

Internet Software & Services
11-50
Founded 2016

Description

  • Support assigned information systems through all phases of the Risk Management Framework (RMF) lifecycle.
  • Maintain System Security Plans (SSPs), security documentation, and authorization artifacts.
  • Coordinate with System Owners to incorporate security requirements into system operations and lifecycle activities.
  • Collect, organize, and validate evidence for security control implementation and continuous monitoring.
  • Track vulnerabilities, POA&Ms, remediation activities, risk acceptance decisions, and corrective actions.
  • Coordinate with vulnerability management, penetration testing, and incident response teams on findings and documentation.
  • Support annual assessments, Security Control Assessments (SCAs), audits, and authorization reviews.
  • Monitor system changes and coordinate updates that may affect authorization status.
  • Assist with contingency planning, incident response planning, interconnection security agreements, and privacy documentation.
  • Prepare recurring authorization status reports, remediation updates, and security summaries for Government stakeholders.

Requirements

  • Bachelor’s degree in Cybersecurity, Information Systems, Information Technology, Computer Science, or a related discipline.
  • 3+ years of experience supporting Federal cybersecurity, RMF, Assessment and Authorization (A&A), or information assurance programs.
  • Working knowledge of NIST SP 800-37, NIST SP 800-53 Rev. 5, FISMA, and Federal cybersecurity requirements.
  • Experience supporting authorization package development and maintenance.
  • Experience coordinating with System Owners, engineers, cybersecurity operations teams, and Government stakeholders.
  • Strong organizational, analytical, and technical writing skills.
  • Excellent communication skills and ability to coordinate across multiple organizations.
  • Experience supporting NIH, HHS, or other Federal civilian agencies (preferred).
  • Experience using JCAM, eMASS, ServiceNow GRC, Archer, or similar governance platforms (preferred).
  • Experience supporting continuous monitoring, vulnerability management, POA&M management, and cybersecurity assessments (preferred).
  • Familiarity with cloud environments, Zero Trust initiatives, and enterprise security operations (preferred).
  • Experience supporting FISMA reporting, audit preparation, and ongoing authorization programs (preferred).
  • Security+, CGRC, CAP, CISSP, or CISM certification (preferred).

Benefits

  • Competitive salary, paid twice per month.
  • Best-in-class medical coverage with 100% of medical premiums covered by True Zero.
  • Company-wide new business incentive programs.
  • Contribution incentives for white papers, blog posts, internal webinars, and similar activities.
  • 3 weeks of PTO starting plus 11 paid holidays annually.
  • 401(k) program with 100% company match on the first 4%.
  • Monthly reimbursement for cell phone and home internet costs.
  • Paternity/maternity leave.
  • Investment in training and certifications.

Interested in this position?

Apply directly on the company website

Apply Now

Similar Roles

Sr. Cyber Analyst, Digital Forensics Incident Response

At-Bay 251-1K Insurance

At-Bay is hiring a Digital Forensics and Incident Response (DFIR) team member to support incident investigation, response, and recovery for insured small businesses.

AWS Azure GCP Linux Unix
1 day, 15 hours ago

Cyber Analyst, Digital Forensics Incident Response

At-Bay 251-1K Insurance

At-Bay is hiring a Cybersecurity Analyst focused on digital forensics and incident response to investigate and help recover from security incidents for its insured small-business customers.

AWS Azure Cybersecurity GCP
1 day, 15 hours ago

Manager, Governance, Risk & Compliance

Ultimate Medical Academy is hiring a remote Manager, Governance, Risk & Compliance to lead its institution-wide GRC and information security programs in support of a national higher-education environment.

Cybersecurity HIPAA Network Security Penetration Testing
2 days, 16 hours ago

Sr. Insider & Data Risk Analyst

Alpaca 51-250 Capital Markets

Alpaca is hiring a Senior Insider & Data Risk Analyst to lead insider risk investigations and strengthen data loss prevention and risk management across its global brokerage infrastructure.

AWS Azure Cybersecurity Elasticsearch GCP Python SIEM Splunk SQL
3 days, 15 hours ago

You're on a roll! Sign up now to keep applying.

Sign Up

Already have an account? Log in

Used by 14,729+ remote workers