Senior Information System Security Officer (Senior ISSO) (R-00185)

1 day, 12 hours ago
Full-time
Senior
Cybersecurity
True Zero Technologies

True Zero Technologies

True Zero Technologies specializes in cybersecurity programs and software solutions, focusing on proactive defense and IT engineering services.

Internet Software & Services
11-50
Founded 2016

Description

  • Serve as the primary cybersecurity advisor for assigned information systems throughout the system lifecycle.
  • Lead RMF activities for initial authorization, ongoing authorization, annual assessments, and continuous monitoring.
  • Coordinate with system owners, authorizing officials, engineering teams, government personnel, and other stakeholders to maintain authorization readiness.
  • Develop, maintain, and update SSPs, security documentation, authorization artifacts, and supporting RMF materials.
  • Coordinate security control implementation, evidence collection, documentation updates, and authorization package development.
  • Track vulnerabilities, POA&Ms, risk acceptance decisions, and remediation activities.
  • Work with vulnerability management and incident response teams to incorporate findings, corrective actions, and lessons learned into RMF documentation.
  • Support annual security assessments, SCAs, independent assessments, internal audits, and external oversight activities.
  • Review assessment findings and coordinate remediation with technical teams and system owners.
  • Support security architecture, Zero Trust initiatives, privacy, contingency planning, and interconnection security documentation.
  • Prepare recurring status updates, risk summaries, and executive-level reporting.
  • Mentor junior ISSOs and promote continuous improvement across the Information Security Program.

Requirements

  • Bachelor’s degree in Cybersecurity, Information Systems, Information Technology, Computer Science, or a related discipline.
  • 5+ years of experience as an ISSO or supporting Federal RMF and Assessment & Authorization programs.
  • Experience supporting all phases of the NIST Risk Management Framework, including categorization, control implementation, assessment, authorization, and continuous monitoring.
  • Experience coordinating with system owners, security engineers, vulnerability management teams, auditors, and government stakeholders.
  • Strong working knowledge of NIST SP 800-37, NIST SP 800-53 Rev. 5, NIST SP 800-53A, FISMA, and federal cybersecurity policy.
  • Experience preparing and maintaining SSPs, SARs, POA&Ms, security plans, contingency planning documentation, and supporting artifacts.
  • Excellent written and verbal communication skills.
  • Experience supporting NIH, HHS, or other federal civilian agencies preferred.
  • Experience with JCAM, eMASS, ServiceNow GRC, Archer, or comparable governance platforms preferred.
  • Experience supporting cloud-based systems, High Value Assets, or enterprise shared services preferred.
  • Familiarity with vulnerability management, continuous monitoring, Zero Trust implementation, and cybersecurity engineering practices preferred.
  • Experience supporting FISMA reporting, audit response activities, annual security assessments, CDM, or enterprise cybersecurity operations preferred.
  • Experience working in Agile development environments preferred.
  • Preferred certifications include CGRC, CISSP, CAP, CISM, Security+, or PMP.

Benefits

  • Competitive salary paid twice per month.
  • Best-in-class medical coverage with 100% of medical premiums covered by True Zero.
  • Company-wide new business incentive programs.
  • Contribution incentives for white papers, blog posts, internal webinars, and similar contributions.
  • 3 weeks of PTO plus 11 paid holidays annually.
  • 401(k) program with 100% company match on the first 4%.
  • Monthly reimbursement for cell phone and home internet costs.
  • Paternity/maternity leave.
  • Investment in training and certifications.

Interested in this position?

Apply directly on the company website

Apply Now

Similar Roles

Manager, Governance, Risk & Compliance

Ultimate Medical Academy is hiring a remote Manager, Governance, Risk & Compliance to lead its institution-wide GRC and information security programs in support of a national higher-education environment.

Cybersecurity HIPAA Network Security Penetration Testing
12 hours, 45 minutes ago

Sr. Insider & Data Risk Analyst

Alpaca 51-250 Capital Markets

Alpaca is hiring a Senior Insider & Data Risk Analyst to lead insider risk investigations and strengthen data loss prevention and risk management across its global brokerage infrastructure.

AWS Azure Cybersecurity Elasticsearch GCP Python SIEM Splunk SQL
1 day, 12 hours ago

French Speaking Digital Trust and Safety Analyst - Work In Sofia, Bulgaria

Mercier Consultancy Professional Services

Mercier Consultancy Group is hiring a French Speaking Digital Trust and Safety Analyst in Bulgaria to help moderate content and protect the safety and quality of a major global social media platform.

1 day, 13 hours ago

Transaction Monitoring and Fraud Analyst

Mews 251-1K Consumer Services

Mews is hiring a FinCrime professional to monitor transactions and payment activity, investigate suspicious behavior, and help reduce fraud and financial crime at scale across its growing payments platform.

Python SQL
3 days, 11 hours ago

You're on a roll! Sign up now to keep applying.

Sign Up

Already have an account? Log in

Used by 14,729+ remote workers