Information System Security Officer (ISSO)

FedTec

Baltimore (MD)

On-site

USD 90,000 - 150,000

Full time

14 days+
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Job summary

Prudent Technology LLC seeks an Information System Security Officer (ISSO) to support SSA RMF activities, including RMF lifecycle documentation, control implementation, and evidence gathering. You will help prepare SSPs, SARs, and POA&Ms, coordinate with ISSOs and stakeholders, and contribute to continuous monitoring and remediation efforts.

Responsibilities include assisting with ATO packages, maintaining SI-2 and RA-5 reporting, and supporting semi-annual QA reviews while staying abreast of

Qualifications

  • Bachelor’s degree in cybersecurity, information systems, information technology, computer science, or related field.
  • 3–4 years of experience supporting federal information security programs, including NIST RMF (SP 800-37) and security control implementation (SP 800-53).
  • Experience assisting with Security Control Assessments (SCAs) and producing SSPs, SARs, and POA&Ms.
  • Knowledge of regulatory frameworks: FISMA, FedRAMP, OMB A-130, FIPS, HIPAA where applicable to federal systems.
  • Ability to gather requirements, assess security-related requests, and communicate with ISSOs and stakeholders.
  • Experience authoring or contributing to SSPs with stakeholder input and mapping to baselines.
  • Familiarity with SA&A tools (ServiceNow, Xacta, eMASS) for RMF lifecycle.
  • Proficiency in MS Office 365 for documentation and reporting.
  • Strong written and verbal communication skills.

Responsibilities

  • Assist ISSO, SAM, and DSR with RMF documentation in SSA SA&A tools, supporting Planning, Categorization, Control Selection, Implementation, Assessment, Authorization, and Monitoring.
  • Support completion of Authorization to Operate (ATO) packages including SSPs and security artifacts.
  • Help establish SI-2 and RA-5 reports for each security boundary in coordination with ISSO and stakeholders.
  • Provide support during Targeted Control Assessments and Continuous Monitoring Assessments, gathering required evidence.
  • Review SARs, understand risks, and suggest mitigating strategies.
  • Coordinate POA&M remediation with technical stakeholders and ensure timely closure.
  • Track and report POA&M remediation status to supervisor and ISSOs.
  • Conduct semi-annual QA reviews of assigned security boundaries and report results.
  • Analyze new/federal laws and directives impacting SSA information security operations.
  • Assist with remediation of agency audit findings and evidence collection.
  • Communicate task status, risks, and schedule changes promptly to supervision.
  • Document all contractor activities in SSA reporting requirements.

Skills

RMF lifecycle
NIST SP 800-37
Security control implementation
SSP/SAR/POA&M development
FISMA/FedRAMP/HIPAA familiarity
SA&A tools
ServiceNow
Xacta
eMASS
MS Office 365
Communication skills

Education

Bachelor’s degree in cybersecurity or related field

Tools

ServiceNow
Xacta
eMASS
JIRA
Confluence

Job description

Information System Security Officer (ISSO)

Location : Woodlawn , MD

Prudent is seeking to supports the Social Security Administration (SSA) Risk Management Framework (RMF) program by assisting the Information System Security Officer (ISSO), Security Authorization Manager (SAM), Designated SAM Representative (DSR), and system stakeholders with the development and maintenance of security authorization documentation. Leverages SSA s Security Assessment & Authorization (SA&A) tool to complete, update, and track all required system security artifacts across assigned system boundaries, supporting activities spanning the full NIST RMF lifecycle from categorization through continuous monitoring.

Key Responsibilities
  • Assist the ISSO, SAM, and DSR with RMF documentation development and maintenance in SSA s Security Authorization Tool (e.g., ServiceNow), supporting Planning, Categorization, Control Selection, Implementation, Assessment, Authorization, and Monitoring activities.
  • Support the completion of Authorization to Operate (ATO) packages, including System Security Plans (SSPs), security control documentation, and supporting artifacts for assigned information systems.
  • Assist with establishing and maintaining SI-2 (Flaw Remediation) and RA-5 (Vulnerability Scanning) reports for each assigned security boundary in coordination with the ISSO and technical stakeholders.
  • Provide support to the ISSO and stakeholders during Targeted Control Assessments and Continuous Monitoring Assessments, including gathering and organizing required evidence and artifacts.
  • Assist the ISSO and stakeholders in reviewing Security Assessment Reports (SARs), understanding identified risks, and recommending potential mitigation strategies.
  • Facilitate the remediation of Plan of Actions and Milestones (POA&Ms) by coordinating with technical stakeholders to address vulnerabilities identified through audits, assessments, continuous monitoring, and system maintenance activities.
  • Track and report POA&M remediation status to the supervisor and ISSOs on a regular basis, ensuring timely closure and accurate documentation of mitigation activities.
  • Conduct semi-annual quality assurance reviews of assigned security boundaries and deliver results to the ISSO and relevant stakeholders.
  • Analyze new and emerging federal laws, directives, regulations, and standards (e.g., OMB A-130, FIPS, NIST Special Publications, DHS Binding Operational Directives, Executive Orders) for their impact on SSA information security operations.
  • Assist the ISSO team with the support and remediation of agency audit findings, coordinating corrective action documentation and evidence collection as required.
  • Communicate task status, risks, and schedule changes to the appropriate supervisor or Work Order Manager in a timely and professional manner.
  • Document all contractor activities and deliverables in accordance with SSA reporting requirements.
Required Qualifications
  • Bachelor s degree in cybersecurity, information systems, information technology, computer science, or a related field.
  • 3 4 years of experience supporting federal information security programs, including direct involvement with the NIST Risk Management Framework (NIST SP 800-37) and security control implementation based on NIST SP 800-53.
  • Demonstrated experience assisting with or conducting Security Control Assessments (SCAs) and supporting preparation of security authorization documentation such as System Security Plans (SSPs), Security Assessment Reports (SARs), and POA&Ms.
  • Working knowledge of federal information security regulatory frameworks and standards, including FISMA, FedRAMP, OMB A-130, FIPS publications, and HIPAA as they apply to federal systems.
  • Ability to gather requirements, assess security-related requests, and communicate effectively with ISSOs, technical stakeholders, and agency personnel to support documentation and remediation efforts.
  • Experience authoring or contributing to System Security Plans with limited oversight, incorporating stakeholder input and aligning documentation to applicable security control baselines.
  • Familiarity with SA&A tools (e.g., ServiceNow, Xacta, eMASS, or equivalent) used to create, maintain, and track system security documentation throughout the RMF lifecycle.
  • Proficiency with Microsoft Office 365 products, including Word, Excel, PowerPoint, Teams, and SharePoint, for documentation, reporting, and stakeholder collaboration.
  • Strong written and verbal communication skills, with the ability to independently facilitate stakeholder meetings and present security-related findings and recommendations clearly.
Preferred Qualifications
  • Prior experience supporting information security programs at a federal civilian agency, particularly within an environment subject to FISMA continuous monitoring requirements.
  • Familiarity with SSA security operations, including SSA s SA&A processes, security boundary structure, or agency-specific RMF implementation guidance.
  • Experience facilitating POA&M remediation efforts and coordinating with technical teams to develop and implement risk mitigation strategies.
  • Knowledge of OMB Security and Privacy Memoranda and DHS Binding Operational Directives and their operational impact on federal agency security programs.
  • Experience supporting or participating in Targeted Control Assessments or third-party security assessments in a preparation or coordination capacity.
  • Relevant certifications such as CompTIA Security+, Certified Authorization Professional (CAP/CGRC), CISSP, or equivalent information security certifications.
  • Experience using JIRA, Confluence, or similar platforms for task tracking, documentation, and reporting in support of security program operations.

Prudent Technology LLC is a Women Owned Small Business company providing innovative IT Automation and Data solutions to our federal clients. We are a team of self-starters, innovators and consultants providing cutting edge technologies for the federal government. We help our clients achieve their business and operational goals by solving complex problems through experience and intellect and build sustainable solutions that last.

At Prudent Technology, we value our employees and are committed to supporting their professional growth, well-being, and work-life balance. We offer a competitive benefits package that may include comprehensive medical, dental, and vision coverage, 401(k) retirement plans with company support, paid time off, paid holidays, training and certification opportunities, career advancement programs, and flexible work arrangements based on program needs. Our collaborative and employee-focused culture empowers team members to grow their careers while contributing to meaningful federal and commercial technology initiatives.

Commitment to Non-Discrimination

As an Equal Opportunity Employer, we consider all qualified applicants without regard to disability, protected veteran status, or any other status protected by law. We are committed to a fair and inclusive workplace where advancement is based on merit, skills, and contributions.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Sr. Information Systems Security Officer (ISSO)
Sr. Information Systems Security Officer (ISSO)

Power3 • Laurel (MD)

On-site
USD 120,000 - 180,000
Competitive health, dental, and vision
401k retirement contributions
Time off: holidays + PTO
+2
Senior Information Systems Security Officer
Senior Information Systems Security Officer

Bamboo Solutions • Washington

Hybrid
USD 130,000 - 180,000
Profit sharing
15 days PTO and 10 holidays
401(k) with employer matching
+2
Information Systems Security Officer (ISSO) Mid Level (TS w/ SCI Eligibility) -
Information Systems Security Officer (ISSO) Mid Level (TS w/ SCI Eligibility) -

RedTrace Technologies • Washington

On-site
USD 80,000 - 100,000
Competitive salary
401(k) plan
Annual performance bonus
+5
Sr. Information Systems Security Officer (ISSO)
Sr. Information Systems Security Officer (ISSO)

Power3 Solutions • Laurel (MD)

On-site
USD 120,000 - 180,000
Health plans
401k with company contribution
Paid time off and holidays
+2
ME00673-Senior Information System Security Officer (ISSO)
ME00673-Senior Information System Security Officer (ISSO)

Momentum Engineering, Inc. • Washington

On-site
USD 120,000 - 180,000
11 paid holidays
3 weeks PTO
Company-sponsored group medical plan
+2
Senior Information Systems Security Officer
Senior Information Systems Security Officer

Bamboo Solutions • Washington

Hybrid
USD 120,000 - 180,000
Profit sharing
PTO and holidays
401(k) with employer matching
+1
Information System Security Officer (ISSO)
Information System Security Officer (ISSO)

ASSYST • Maryland

On-site
USD 120,000 - 160,000
Information System Security Officer
Information System Security Officer

Hiring Our Heroes • Arlington (VA)

Hybrid
USD 90,000 - 130,000
ME00673-Senior Information System Security Officer (ISSO)
ME00673-Senior Information System Security Officer (ISSO)

Momentum Engineering, Inc. • Washington

On-site
USD 120,000 - 180,000
11 paid holidays
3 weeks PTO
Company medical plan
+4
ME00673-Senior Information System Security Officer (ISSO)
ME00673-Senior Information System Security Officer (ISSO)

Momentum Engineering, Inc • Washington, Northern (KY)

Hybrid
USD 120,000 - 165,000
Paid holidays
3 weeks PTO
Group medical plan
+4