Information Systems Security Officer (ISSO)

TDI (Tetrad Digital Integrity)

Washington (District of Columbia)

Hybrid

USD 110,000 - 135,000

Full time

15 hours ago
Be an early applicant
Application generator

Stand out for this role — generate a tailored resume and cover letter in about a minute.

Get past ATS filters

Benefits offered by this job

Hybrid work arrangement

Job summary

Tetrad Digital Integrity (TDI) is seeking an Information Systems Security Officer to align RMF processes and mature risk management for high-consequence environments.

This hybrid DC-area role requires CISSP/CISM/CRISC and 5+ years of RMF/A&A experience; you will lead A&A, SSPs, SIAs, POA&Ms, and continuous monitoring.

Travel is limited; you will collaborate with SO, ISSM, CISO and engineering teams to strengthen security posture.

Qualifications

  • 5+ years of experience performing security assessments and RMF/A&A documentation.
  • Experience creating System Security Plans (SSPs), SIAs, POA&Ms and other RMF artifacts.
  • Familiarity with NIST RMF, NIST SPs and security authorization processes.
  • Experience with Archer or similar GRC tools to support A&A activities.

Responsibilities

  • Serve as cybersecurity advisor to System Owner, ISSM, and CISO on security matters.
  • Lead RMF Security Assessment and Authorization to achieve and maintain ATO.
  • Develop and maintain RMF documentation (SSPs, SIAs, POA&Ms, etc.).
  • Perform continuous monitoring and review security controls and logs.
  • Assess impact of system changes and communicate risks to stakeholders.
  • Identify and coordinate remediation for control deficiencies and POA&M updates.
  • Collaborate with engineering and system owners to strengthen security posture.
  • Support internal/external security assessments and audits.

Skills

RMF experience
A&A documentation
Security assessment
GRC tools Archer

Education

Bachelor's degree in CS/IT/Cybersecurity
CISSP

Tools

Archer

Job description

Tetrad Digital Integrity (TDI) is a cybersecurity firm built for high-consequence environments where mission, complexity, and trust intersect. Our single focus has been delivering cyber solutions to effectively manage risk & the business of cyber for 25 years!

TDI is seeking an Information Systems Security Officer (ISSO) to provide expertise needed to align and help mature the organization and technology-specific risk management plans and processes, through the implementation of the Risk Management Framework (RMF).

This position is hybrid with commute to the DC area 3 times per week.

RESPOSIBILITIES:
  • Serve as the primary cybersecurity advisor to the System Owner (SO), Information Systems Security Manager (ISSM), and Chief Information Security Officer (CISO) on all security matters related to assigned information systems
  • Lead and support all phases of the Risk Management Framework (RMF) Security Assessment and Authorization (A&A) process, ensuring assigned systems achieve and maintain a compliant Authority to Operate (ATO)
  • Develop, maintain, and update all required RMF security documentation, including System Security Plans (SSPs), Security Impact Analyses (SIAs), Plans of Action and Milestones (POA&Ms), Risk Acceptances, Configuration Management Plans, Supply Chain Risk Management Plans, Interconnection Security Agreements (ISAs), Memorandums of Understanding (MOUs), Information Exchange Agreements (IEAs), vulnerability reports, authorization letters, and other required security artifacts
  • Perform continuous monitoring activities to verify security controls are implemented correctly, operating effectively, and meeting cybersecurity requirements by conducting security control self-assessments, reviewing vulnerability and compliance scan results, validating system log reviews, and ensuring periodic user account reviews are completed
  • Assess the cybersecurity impact of system changes, document findings through Security Impact Analyses, and communicate associated risks and recommendations to stakeholders
  • Identify security control deficiencies, manage the POA&M process, and coordinate remediation efforts with system owners and technical teams to resolve vulnerabilities identified through assessments, audits, inspections, and continuous monitoring activities
  • Collaborate with engineering, operations, and system owners to strengthen the security posture of assigned systems while ensuring compliance with organizational cybersecurity policies and RMF requirements
  • Support internal and external security assessments, audits, and authorization activities by providing required system access, documentation, evidence, and technical guidance
QUALIFICATIONS:
  • U.S. Citizenship is required
  • Active CISSP, CISM, CRISC, or equivalent cybersecurity certification required
  • Bachelor's degree in Computer Science, Information Technology, Cybersecurity, or a related technical field
  • 5+ years of experience performing security assessments, developing RMF/A&A documentation, and supporting the authorization of enterprise systems, networks, servers, databases, or cloud environments
  • Working knowledge of NIST Risk Management Framework (RMF), NIST security and privacy publications, and security authorization processes
  • Experience using Archer or a similar governance, risk, and compliance (GRC) platform to support Assessment and Authorization (A&A) activities
  • Understanding of cloud service models (IaaS, PaaS, SaaS), hybrid cloud environments, financial applications, and mobile security technologies
PAY RANGE:

The anticipated salary range for this position is $110,000 - $135,000. This range is a good-faith estimate and not a guarantee of compensation. Final compensation will be based on factors including experience, education, skills, geographic location, internal equity, market data and applicable contract requirements, and may fall outside the posted range.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Information Systems Security Officer (ISSO)
Information Systems Security Officer (ISSO)

TDI (Tetrad Digital Integrity) • Alexandria (VA)

Hybrid
USD 80,000 - 110,000
Information System Security Officer, (ISSO)
Information System Security Officer, (ISSO)

Cinteot Inc. • Fort Meade (MD)

On-site
USD 120,000 - 150,000
Complete Insurance Coverage
401k with Company Contribution
Tuition Reimbursement
+1
Information Systems Security Officer (Technical ISSO / RMF Assessor)
Information Systems Security Officer (Technical ISSO / RMF Assessor)

Peraton • Riverdale Park (MD)

On-site
USD 112,000 - 179,000
Heavily subsidized employee benefits
25 days of PTO annually
Eligibility for bonus plan
Information Systems Security Officer (ISSO)
Information Systems Security Officer (ISSO)

Dynamic Solutions Technology LLC • Washington

Hybrid
USD 120,000 - 170,000
Information Systems Security Officer
Information Systems Security Officer

Kids for the Future • Foster (VA)

Hybrid
USD 120,000 - 185,000
Information Systems Security Officer (ISSO)
Information Systems Security Officer (ISSO)

CACI International Inc • Albuquerque (NM)

On-site
USD 71,000 - 151,000
Comprehensive health benefits
Continuing education support
Flexible time off
Senior Information Systems Security Officer (ISSO)
Senior Information Systems Security Officer (ISSO)

Mission Technologies, a division of HII • Springfield (VA)

On-site
USD 102,000 - 154,000
Information System Security Officer, (ISSO)
Information System Security Officer, (ISSO)

SCALIS • Fort Meade (FL)

Hybrid
USD 120,000 - 180,000
Health Insurance
Vision Insurance
401(k) Matching
+5
Information Systems Security Officer
Information Systems Security Officer

The Hawaii Pacific Foundation • Hanahan (SC)

On-site
USD 250,000 - 300,000
Information Systems Security Officer (ISSO) - Senior
Information Systems Security Officer (ISSO) - Senior

Astrion • Boulder (CO)

On-site
USD 102,000 - 138,000