Information Systems Security Officer (ISSO Lead) (R-00047)

2 weeks, 6 days ago
Full-time
Lead
DevOps and Infrastructure
True Zero Technologies

True Zero Technologies

True Zero Technologies specializes in cybersecurity programs and software solutions, focusing on proactive defense and IT engineering services.

Internet Software & Services
11-50
Founded 2016

Description

  • Maintain the overall operational security posture and manage day-to-day security operations for assigned information systems.
  • Develop, review, and maintain security and authorization documentation, including SSPs, risk assessment reports, C&A packages, and SRTMs.
  • Perform vulnerability and risk assessment analyses to support assessment and authorization activities.
  • Ensure security controls are implemented and maintained in accordance with the SSP and organizational security policies, standards, and procedures.
  • Support security authorization activities in compliance with NIST Risk Management Framework (RMF).
  • Provide configuration management for security software, hardware, and firmware, and lead Change Control Board meetings.
  • Advise the Information System Owner, Business Process Owner, and CISO/ISSM on system security matters.
  • Provide guidance and security expertise to program leadership.
  • Support ATO/ATC decision-making and operational practices.
  • Maintain awareness of emerging IT and cybersecurity technologies.

Requirements

  • 5+ years of experience in a related field, or a BA/BS in Computer Science or a related discipline from an accredited college or university.
  • CISSP and/or CISM certification is required.
  • Experience with Federal DevSecOps frameworks and processes.
  • Experience with IS accreditors, policies, and procedures supporting ATO/ATC decision making and operations.
  • Experience with RMF, NIST SP 800-53, STIGs, and/or SCAP Compliance Checker.
  • Knowledge of and experience leading the assessment and authorization (A&A) process.
  • Knowledge of IT security principles and methods such as firewalls, demilitarized zones, and encryption.
  • Experience preparing detailed SSPs to achieve ATO objectives.
  • Excellent verbal and written communication skills with the ability to influence and collaborate with leadership, peers, and team members.
  • Must be approved to work in the United States and have an active clearance, or be willing to submit to a clearance/background investigation process.

Benefits

  • Competitive salary paid twice per month.
  • Best-in-class medical coverage with 100% of medical premiums covered by the company.
  • Company-wide new business incentive programs.
  • Contribution incentives for white papers, blog posts, internal webinars, and similar activities.
  • 3 weeks of PTO to start plus 11 paid holidays annually.
  • 401(k) program with 100% company match on the first 4%.
  • Monthly reimbursement for cell phone and home internet costs.
  • Paternity and maternity leave.
  • Investment in training and certifications to expand technical skills.

Interested in this position?

Apply directly on the company website

Apply Now

Similar Roles

Staff Threat Research Engineer

Sumo Logic 251-1K Internet Software & Services

Sumo Logic’s Threat Labs is hiring a staff-level threat researcher to turn threat intelligence and original adversary research into high-quality detections for its SIEM platform.

AWS Azure Cybersecurity GCP Machine Learning PowerShell Python SIEM SOC
1 hour, 33 minutes ago

Manager, Engineering (Identity and Access Management)

Bugcrowd 1K-5K Internet Software & Services

Bugcrowd is hiring a Software Engineering Manager to lead its Identity and Access Management team in building secure, scalable authentication, authorization, and identity services across the company’s product ecosystem.

Agile AWS Azure Encryption GCP Go Java JWT Node.js OpenID Connect Ruby SAML Scrum
4 hours, 57 minutes ago

DevSecOps Engineer (TypeScript & Agentic AI)

Arize AI 51-250 IT Services

Arize AI is hiring a remote IT Support Specialist to support Mac-only endpoints, cloud systems, and compliance operations for a distributed team.

Confluence GitHub JIRA TypeScript
11 hours, 33 minutes ago

Senior Cloud Security Engineer (Kubernetes)

Form3 251-1K Diversified Financial Services

Form3 is hiring a defensive security engineer to build and operate security controls for highly available multi-cloud payment systems and advise engineering teams on managing platform risk.

AWS Azure CI/CD CockroachDB Flux GCP Go Helm Kubernetes Linux NATS Penetration Testing SIEM Terraform
12 hours, 6 minutes ago

You're on a roll! Sign up now to keep applying.

Sign Up

Already have an account? Log in

Used by 14,729+ remote workers