Information System Security Officer (ISSO)

AnaVation LLC

Washington (District of Columbia)

On-site

USD 120,000 - 190,000

Full time

6 days ago
Be an early applicant
Application generator

Stand out for this role — generate a tailored resume and cover letter in about a minute.

Get past ATS filters

Benefits offered by this job

Medical insurance
Dental insurance
Vision insurance
401k with company match
Paid leave

Job summary

AnaVation is seeking a seasoned security professional to join our risk assessment team in Washington, DC. You will contribute to internal audits, streamline assessment processes, and enforce security controls across multi-cloud and on-prem environments.

The role requires deep RMF and NIST expertise, a CISSP, and the ability to prepare SA&A packages, SSPs, and contingency plans while coordinating with stakeholders and ensuring continuous monitoring and ATO readiness.

Qualifications

  • 6+ years’ experience with NIST, FISMA, and Security Assessment & Authorization.
  • FedRAMP and Cloud experience (e.g., Azure, AWS, Oracle (OCI)).
  • Knowledgeable on various security-related NIST publications (e.g., SP 800-53r5, SP 800-53A, SP 800-18r1).
  • In-depth knowledge of the Risk Management Framework (RMF).
  • Ability to obtain and maintain a customer Public Trust clearance; sponsorship possible.
  • CISSP certification required.

Responsibilities

  • Support agency’s risk assessment program and internal audits.
  • Maintain security of accreditation boundary and manage system's authorization status.
  • Evaluate enterprise governance and risk across multi-cloud and on-premise environments.
  • Recommend changes to improve security posture of agency systems.
  • Provide security compliance support and audit liaison activities.
  • Develop, maintain SA&A packages resulting in an ATO for IT systems.
  • Create SSPs and supporting documentation (e.g., Contingency Plans, Incident Response Plans).
  • Coordinate Incident Response Plans and Contingency Plans; train personnel.
  • Ensure information systems are accredited and continuously monitored.
  • Perform risk assessments for cloud and on-prem systems; review vulnerability data and remediation.
  • Maintain and track POA&Ms; lead process improvements.

Skills

NIST RMF knowledge
CISSP
Security assessment & authorization
FedRAMP & cloud experience
Strong written communication
C-level presentation
PowerBI / data analysis

Tools

JCAM (CSAM) / eMASS
Nessus
BigFix
SCCM
ePO
PowerBI
Excel

Job description

Be Challenged and Make a Difference

In a world of technology, people make the difference. We believe if we invest in great people, then great things will happen. At AnaVation, we provide unmatched value to our customers and employees through innovative solutions and an engaging culture.

Description of Task to be Performed
  • Integral team member for agency’s risk assessment program that will be performing internal audits and building streamlined assessment processes
  • Having in-depth security knowledge, is highly technical, and experienced in managing the security of a system's accreditation boundary
  • Focusing on the enterprise governance and risk of exposure across a multi-cloud and on-premise environment that will include multiple vendors, customers and XaaS products
  • Evaluating agency’s current system infrastructure and recommending changes to improve its security posture
  • Providing customer support for security compliance and audit liaison activities. Focus is on improving the security posture of the agency’s Forensic and Investigative Labs
  • Developing, maintaining, and assessing Security Assessment & Authorization (SA&A) packages resulting in an Authority to Operate (ATO) for IT systems
  • Creating and maintaining SSPs and supporting documentation in accordance with agency guidelines and directives. This includes writing implementation statements, creating supporting documentation (e.g., Contingency Plans, Incident Response Plans, Account Management Plans, etc.), performing self-assessments, and/or assessing your peer’s assessment, while working with system stakeholders
  • Develop, coordinate, test, and train personnel on Incident Response Plans and Contingency Plans
  • Ensuring that information systems are accredited, maintain their ATO, and are being continuously monitored
  • Performing risk assessments for agency systems/applications, to include cloud-based systems
  • Performing security control assessments to include collecting supporting artifacts/evidence and interviewing system owner/owner representatives
  • Maintaining and tracking system POA&Ms
  • Reviewing and analyzing vulnerability scan data and providing recommendations on remediation
  • Taking ownership on various projects
  • Improving processes and procedures and making recommendations to improve the security posture of the agency's IT systems and applications.

This position is on-site in Washington, DC.

Required Qualifications
  • 6+ years’ experience with NIST, FISMA, and Security Assessment & Authorization
  • FedRAMP and Cloud experience (e.g., Azure, AWS, Oracle (OCI))
  • Knowledgeable on various security-related NIST publications (e.g., SP 800-53r5, SP 800-53A, SP 800-18r1, etc.)
  • An in-depth knowledge of the Risk Management Framework (RMF)
  • Ability to obtain and maintain a customer Public Trust clearance required. Qualified candidates can be sponsored for this clearance
  • Certifications: CISSP required
Preferred Qualifications
  • Familiarity with the security control families from the NIST guidance covered by the documents that they are responsible for evaluating
  • Ability to provide subject matter expert-level knowledge to the project team to ensure compliance with applicable requirements
  • Demonstrated knowledge of IT Security policy implementation statements, the regulatory structure of policy, the role of the Department of Homeland Security (DHS), the Office of Management and Budget (OMB), and the National Institute of Standards and Technology (NIST)
  • Hands-on experience using a Governance, Risk, and Compliance tool, such as JCAM (CSAM) or eMASS
  • Ability to conduct gap analysis on non-federated vendor audit results, such as SOC Type 2, HIPAA comparison review and analyze against NIST SP 800-53 Revision 5 security controls
  • Hands-on experience providing C-Level presentation and reporting
  • Excellent written communication skills and understand the purpose and use of the System Security Plan (SSP)
  • Possess an understanding of control inheritance as applied to the RMF implementation in the JCAM tool
  • Ability to accurately manage complex workstreams, comprehend the application of the RMF, and understand the application of security controls across the interface, application, operating system, network, and database layers of modern information systems. Understand the applicable artifacts used as evidence to assess compliance
  • Experience with multiple tools providing security functions such as vulnerability management (e.g., Nessus), configuration management (e.g., BigFix, SCCM, ePO), endpoint protection (e.g., antivirus, ATP), data loss prevention, and intrusion detection software and hardware
  • Ability to evaluate data flows, network diagrams, and logical security boundaries
  • Excellent oral and written communication skills
  • Familiarity with the use of data analysis tools, including the use of Microsoft Excel or PowerBI to combine data from multiple sources
Benefits
  • Generous cost sharing for medical insurance for the employee and dependents
  • 100% company paid dental insurance for employees and dependents
  • 100% company paid long-term and short-term disability insurance
  • 100% company paid vision insurance for employees and dependents
  • 401k plan with generous match and 100% immediate vesting
  • Competitive Pay
  • Generous paid leave and holiday package
  • Tuition and training reimbursement
  • Life and AD&D Insurance
About AnaVation

AnaVation is the leader in solving the most complex technical challenges for collection and processing in the U.S. Federal Intelligence Community. We are a US owned company headquartered in Chantilly, Virginia. We deliver groundbreaking research with advanced software and systems engineering that provides an information advantage to contribute to the mission and operational success of our customers. We offer complex challenges, a top-notch work environment, and a world-class, collaborative team.

If you want to grow your career and make a difference while doing it, AnaVation is the perfect fit for you!

AnaVation is an equal opportunity employer. All qualified applicants will receive consideration for employment without regard to sex, race, color, religion, national origin, disability, protected Veteran status, age, or any other characteristic protected by law.

Please note: The listed salary range reflects our market-based compensation structure. Final compensation will depend on business needs, local market conditions, internal equity, and the selected candidate’s skills, education, and experience.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Information System Security Officer (ISSO)
Information System Security Officer (ISSO)

Nava • Washington, Northern (KY)

Hybrid
USD 86,000 - 202,000
Medical insurance
Dental insurance
Disability insurance
+5
Information System Security Officer (ISSO)
Information System Security Officer (ISSO)

AnaVation • Washington

On-site
USD 86,000 - 202,000
Medical insurance
Dental insurance
Disability insurance
+5
Information System Security Officer (ISSO)
Information System Security Officer (ISSO)

Anavationllc • Washington

On-site
USD 135,000 - 180,000
Medical insurance
Dental insurance
Vision insurance
+4
Information System Security Officer (ISSO)
Information System Security Officer (ISSO)

AnaVation, LLC • Washington

On-site
USD 140,000 - 190,000
Medical insurance
Dental insurance
Vision insurance
+5
Information Systems Security Officer (ISSO), Senior
Information Systems Security Officer (ISSO), Senior

Anavationllc • Washington

Hybrid
USD 140,000 - 170,000
Medical insurance
Dental insurance
Disability insurance
+6
Cybersecurity Systems Engineer / ISSM
Cybersecurity Systems Engineer / ISSM

Nava • Chantilly (VA)

On-site
USD 120,000 - 190,000
Medical insurance
Dental insurance
Disability insurance
+4
Cybersecurity Systems Engineer / ISSM
Cybersecurity Systems Engineer / ISSM

AnaVation LLC • Chantilly (VA)

On-site
USD 140,000 - 190,000
Medical insurance
Dental insurance
Disability insurance
+5
Cybersecurity Systems Engineer / ISSM
Cybersecurity Systems Engineer / ISSM

AnaVation, LLC • Chantilly (VA)

On-site
USD 120,000 - 160,000
401k plan with generous match
Tuition and training reimbursement
Competitive Pay
Information Systems Security Officer (ISSO)
Information Systems Security Officer (ISSO)

AnaVation, LLC • San Antonio (TX)

On-site
USD 110,000 - 170,000
Medical insurance
Dental insurance
Vision insurance
+3
Information System Security Engineer (ISSE)
Information System Security Engineer (ISSE)

Socket.dev • Huntsville (AL)

On-site
USD 110,000 - 170,000
Medical insurance
Dental insurance
Disability insurance
+5