Information System Security Officer Sr. (Cloud)

ECS

Washington (District of Columbia)

On-site

USD 120,000 - 150,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

ECS in Washington, D.C. is seeking an experienced Information System Security Officer Sr. (Cloud) to support key cybersecurity activities for federal information systems. The role involves managing security risk assessments, compliance documentation, and developing System Security Plans across various cloud environments.

The ideal candidate will have extensive experience in cybersecurity and strong communication skills. A Top Secret clearance and relevant certifications are required. ECS offers a dynamic work environment focused on national security.

Qualifications

  • At least 7 years of experience as an Information System Security Officer.
  • U.S. citizenship required; no dual citizenship.
  • Experience supporting cloud security in AWS, Azure, or similar.

Responsibilities

  • Execute the Security Assessment and Authorization program for federal information systems.
  • Maintain security authorization documentation and RMF artifacts.
  • Support cloud security documentation and compliance activities.

Skills

Active Top Secret clearance
Experience in cybersecurity
Strong written and verbal communication skills
Familiarity with Tenable Nessus
Experience supporting RMF

Education

Bachelor’s or advanced degree in a related discipline

Tools

AWS Certified Security - Specialty
CCSP - Certified Cloud Security Professional

Job description

Job Description

Everforth ECS Federal is seeking an experienced Information System Security Officer Sr. (Cloud) to support cybersecurity, risk management, and Security Assessment and Authorization activities for federal information systems in cleared law enforcement and national security environments.

Please Note: This position is contingent upon contract award.

The successful candidate will provide senior‑level ISSO support for complex, mission‑critical systems, with an emphasis on cloud security, RMF execution, security documentation, continuous monitoring, vulnerability management, audit readiness, and authorization support. This role will work closely with system owners, security managers, security engineers, cloud teams, technical stakeholders, and government leadership to help systems obtain and maintain compliant authorizations.

Responsibilities
  • Responsible for executing the Security Assessment and Authorization program for assigned federal information systems.
  • Provide full system lifecycle ISSO support for federal information systems to obtain and maintain compliant authorizations.
  • Prepare, review, update, and maintain security authorization documentation and RMF artifacts in accordance with federal standards and customer policies.
  • Develop and maintain System Security Plans, control implementation descriptions, Plans of Action and Milestones, risk assessments, contingency planning artifacts, data flow diagrams, network diagrams, hardware/software inventories, and assessment evidence.
  • Support cloud security documentation and compliance activities for systems hosted in or connected to AWS, Azure, Google Cloud Platform, or other approved cloud environments.
  • Review cloud security considerations such as control inheritance, shared responsibility, identity and access management, encryption, logging, monitoring, configuration management, and secure cloud architecture.
  • Conduct risk assessments, document security findings, develop POA&Ms, and ensure remediation actions are tracked to closure.
  • Keep system documentation, inventories, diagrams, and authorization artifacts current in support of audits, vulnerability reporting, emergency directives, and continuous monitoring requirements.
  • Coordinate proactively with system owners, security managers, security engineers, technical teams, cloud teams, and authorizing officials to avoid authorization delays or lapses.
  • Support vulnerability and patch management activities by reviewing scan results, documenting findings, coordinating remediation status, and helping ensure corrective actions are completed within required timelines.
  • Support annual control assessments, compliance reviews, audit readiness activities, continuity planning, resiliency documentation, and security documentation reviews.
  • Prepare clear, accurate, and defensible responses for government reviewers, auditors, security managers, and authorizing officials.
  • Provide technical input and ISSO support for post‑incident recovery activities, as needed, including documentation updates, remediation tracking, and return‑to‑service security considerations.
  • Mentor junior and mid‑level cybersecurity personnel by providing technical guidance, reviewing work products, sharing RMF and cloud security best practices, and helping improve team execution quality.
  • Contribute to portfolio and program improvements by identifying recurring risks, documentation gaps, cloud security concerns, process inefficiencies, automation opportunities, and lessons learned.
  • Identify and recommend tools, workflows, templates, and process improvements that improve speed, quality, consistency, and audit readiness across authorization and continuous monitoring activities.
  • Track, report, and communicate security risks, compliance status, remediation progress, documentation quality issues, and improvement recommendations to program leadership and government stakeholders.
  • Maintain current knowledge of NIST RMF, NIST SP 800‑53 Rev. 5, NIST SP 800‑53A, FISMA, CNSS, DOJ, IC, FedRAMP, and other applicable federal cybersecurity and cloud security guidance.
Required Skills
  • Active Top Secret clearance required; SCI eligibility may be required based on assignment.
  • Ability to meet federal law enforcement and national security suitability, access, and polygraph requirements.
  • U.S. citizenship required; no dual citizenship.
  • Possess at least one of the following certifications:
    • CISSP - Certified Information Systems Security Professional
    • GISP - Global Information Security Professional
    • CASP+ - CompTIA Advanced Security Practitioner
    • Other certification demonstrating skills comparable to DoD 8570 IAM Level III proficiency
  • At least 7 years of experience serving as an Information System Security Officer at a cleared facility.
  • Minimum of 9 years of work experience in a computer science, cybersecurity, information technology, or related technical field.
  • Experience supporting RMF, Security Assessment and Authorization, ATO, POA&M management, vulnerability management, continuous monitoring, audit readiness, and security control implementation activities.
  • Experience developing, reviewing, and maintaining security authorization documentation for federal information systems.
  • Experience supporting cloud security or cloud compliance activities in AWS, Azure, Google Cloud Platform, or similar cloud environments.
  • Familiarity with the use and operation of security and vulnerability management tools, including Tenable Nessus and/or SecurityCenter, Splunk, IBM Guardium, HP WebInspect, Network Mapper, Nmap, and/or similar applications.
  • Strong written and verbal communication skills, including the ability to document technical security issues, brief risks, and communicate remediation recommendations to technical and non-technical stakeholders.
  • Hold at least one security certification from AWS, Azure, Google Cloud, or a comparable cloud security body, such as: AWS Certified Security - Specialty; CCSP - Certified Cloud Security Professional; AWS Certified Solutions Architect - Associate; AZ-500 - Microsoft Certified: Azure Security Engineer Associate;
Desired Skills
  • Bachelor’s or advanced degree in computer science, cybersecurity, information technology, business management, engineering, or a related discipline.
  • Experience supporting federal law enforcement, intelligence, defense, national security, or other cleared federal environments.
  • Experience working within JCAM and/or CSAM.
  • Experience working with Xacta.
  • Experience interpreting and applying NIST SP 800‑53 Rev. 5 controls in cloud, hybrid, and enterprise environments.
  • Experience supporting FedRAMP-authorized cloud services, cloud control inheritance, customer responsibility matrices, or shared responsibility models.
  • Experience coordinating with cloud architects, DevSecOps teams, infrastructure teams, security assessors, and system owners.
  • Experience preparing systems for FISMA audits, security control assessments, continuous monitoring reviews, and authorization package submissions.

ECS Federal LLC is an equal opportunity employer and does not discriminate or allow discrimination on the basis any characteristic protected by law. All qualified applicants will receive consideration for employment without regard to disability, status as a protected veteran or any other status protected by applicable federal, state, or local jurisdiction law.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

ISSO - Information Systems Security Officer
ISSO - Information Systems Security Officer

Anavationllc • Huntsville (AL)

On-site
USD 95,000 - 150,000
Senior Information Systems Security Engineer
Senior Information Systems Security Engineer

ECS • Washington

On-site
USD 120,000 - 150,000
Cleared Onsite Information Systems Security Officer (ISSO) – Sr (Cloud) (5274)
Cleared Onsite Information Systems Security Officer (ISSO) – Sr (Cloud) (5274)

3M HEALTHCARE • Washington

On-site
USD 140,000 - 180,000
Information System Security Officer (ISSO) – TS/SCI
Information System Security Officer (ISSO) – TS/SCI

Strategic Business Systems (SBS) • Herndon (VA)

On-site
USD 140,000 - 190,000
Medical, dental, vision coverage
401(k) retirement plan with company匹配
Paid time off and holidays
+2
Information System Security Officer (ISSO) - Cloud Data Platform
Information System Security Officer (ISSO) - Cloud Data Platform

Omniscius Consulting • Washington

On-site
USD 110,000 - 140,000
Information Systems Security Engineer SME
Information Systems Security Engineer SME

ECS • Stafford (VA)

On-site
USD 120,000 - 150,000
Information System Security Officer (ISSO) – TS/SCI
Information System Security Officer (ISSO) – TS/SCI

Strategic Business Systems (SBS) • Arlington (VA)

On-site
USD 140,000 - 190,000
Telework options
401(k) with match
Paid time off & holidays
+2
Information Systems Security Officer
Information Systems Security Officer

Peraton • Maryland

On-site
USD 100,000 - 130,000
Senior Information System Security Officers (ISSO)
Senior Information System Security Officers (ISSO)

Global Solutions Consulting LLC. • Baltimore (MD)

Hybrid
USD 80,000 - 110,000
Competitive salary and benefits package
Flexible work arrangements
Professional development opportunities
Senior Cloud ISSO - RMF & Federal Security Expert
Senior Cloud ISSO - RMF & Federal Security Expert

ECS • Washington

On-site
USD 120,000 - 150,000