Information System Security Officer (ISSO), RMF & NIST
Overview
Own the security posture and authorization of a federal system as ISSO at Inadev. Manage the RMF lifecycle, maintain ATO documentation, and ensure continuous compliance with NIST 800-53 and FedRAMP. You will track findings, coordinate with DevSecOps, and report risks to stakeholders. This contract role offers a hybrid schedule in DC and Reston, VA, working with a vibrant team. You bring 5+ years of ISSO experience and a CISSP or equivalent certification.
What You'll Do7
- 1Maintain the system's RMF documentation and ATO package, updating controls and artifacts after each assessment.
- 2Manage security control implementation evidence against NIST 800-53 and FedRAMP, ensuring all required documents are current.
- 3Track and remediate findings via POA&Ms, coordinating with technical teams to close gaps within defined timelines.
- 4Support security assessments, audits, and authorization activities, preparing evidence and responding to auditor requests.
- 5Coordinate with the client ISSM, security teams, and DevSecOps on compliance issues, integrating security into the SDLC.
- 6Review system changes for security impact, updating security baselines and configuration documents as needed.
- 7Report security posture, risks, and incidents to program and client stakeholders, providing clear and actionable updates.
Requirements10
- 15+ years of information system security or ISSO experience in federal environments.
- 2Active CISSP, CAP, or equivalent security certification.
- 3Strong knowledge of RMF, NIST 800-53, and federal ATO processes.
- 4Experience with continuous monitoring and POA&M management.
- 5Must be a U.S. Citizen and willing to work a hybrid schedule (2 days) in Reston, VA and DC area.
- 6Ability to pass a 7-year background check and obtain/maintain a U.S. Government Clearance.
- 7Proven communication and presentation skills, with the ability to prioritize and self-start.
- 8Adaptable and flexible as priorities shift, with a passion for learning and constant improvement.
- 9Open to collaboration, feedback, and client asks, and enjoy working with a vibrant team.
- 10Preferred: FedRAMP and cloud (AWS) security experience, financial-regulatory security, and security automation/GRC tooling.
Salary Insight
$96 - $106k per year
Location
Required Skills
Similar open positions
Explore active roles that match your skills and interests.
GD Information Technology, Inc.
VerifiedInformation Systems Security Manager (ISSM) - RMF & XACTA
Information Systems Security Management (ISSM), you will own the RMF workflow and A&A process for a premier cyber security risk management platform supporting DoD and Intelligence Community customers. You will ensure operational IT capabilities deliver timeliness, accuracy, and security of information across multiple fabrics and centers. Your days involve coordinating with stakeholders, managing system vulnerabilities, and maintaining compliance with NIST standards. This role stands out because you'll directly impact national security while working with leading-edge tools like XACTA 360 and STIGs. You will be the go-to expert for all security authorizations, guiding systems from concept to Authority to Operate (ATO).
1805 KBR Wyle Services, LLC
VerifiedSenior Information System Security Officer (ISSO)
Lead cybersecurity approval and compliance processes while supporting system owners and project managers. Review technical architectures and integrate security requirements throughout the system lifecycle. Ensure cybersecurity compliance and provide guidance to engineers and non-technical partners.
Peraton
VerifiedSenior Information System Security Officer Peraton
Peraton seeks a Senior ISSO to lead IT architecture support in Annapolis Junction MD. You will lead or co-lead ATO/reauthorization efforts mentor junior staff drive security engineering outcomes execute RMF activities maintain security artifacts operate continuous monitoring support incident response ensure least privilege governance translate security requirements provide qualifications required and preferred list.
02 CACI, INC.-FEDERAL
VerifiedInformation System Security Manager
Lead and oversee Risk Management Framework lifecycle activities for classified DoD systems supporting SAP SCI NSA missions. Manage system authorizations and cybersecurity compliance while serving as senior cybersecurity authority. Ensure systems remain secure compliant and fully authorized to operate.
TSTC
VerifiedInformation Systems Security Officer
TSTC seeks a contingent full-time Information Systems Security Officer to support a new contract at Customs & Border Patrol. The ISSO will create revise document and maintain security policies while developing and implementing security plans to protect sensitive data. Review client information security systems and recommend improvements. This role differs by focusing on federal agency collaboration and compliance with NIST standards.
Xpect Solutions
VerifiedInformation Systems Security Officer - Xpect Solutions
Lead compliance and security operations for government information systems. Navigate the full NIST Risk Management Framework and ensure adherence to NIST 800-53 controls and DHS 4300A requirements. Partner with Government Security Assurance Management teams to protect critical systems and maintain compliance posture.