Information Systems Security Officer (ISSO), Senior

Anavationllc

Washington (District of Columbia)

Hybrid

USD 140,000 - 170,000

Full time

3 days ago
Be an early applicant
Application generator

A complete application in a minute — tailored resume and cover letter, ready to send.

Get past ATS filters

Benefits offered by this job

Medical insurance
Dental insurance
Disability insurance
Vision insurance
401k match
Paid leave
Tuition reimbursement
Life insurance
AD&D insurance

Job summary

AnaVation is seeking a Senior ISSO to own RMF activities for a federal contract, preparing accreditation to obtain ATT/ATO for a digital evidence platform. Remote work with occasional travel to Washington DC. Must have 10+ years in ISSO/security roles, strong NIST 800-53 Rev 5 expertise, and a US Public Trust clearance.

You will develop SSPs, SARs, POA&Ms, and coordinate assessments, SCAs, and audits while mentoring junior staff. Strong communication and cloud experience are essential.

Qualifications

  • Bachelor's degree in Cybersecurity or Information Assurance.
  • 10+ years of ISSO or security compliance experience.
  • US Citizenship with Public Trust clearance.
  • Deep knowledge of NIST SP 800-53 Rev 5.
  • Hands-on RMF package management.
  • Cloud experience across Azure, AWS, GCP.
  • Experience producing SSPs, SARs, POA&Ms, and Continuous Monitoring.
  • Familiarity with SIEMs and vulnerability tools.
  • Excellent communication with stakeholders.
  • Certifications: CISSP, CISM, CAP, CCSP, or equivalent.
  • Federal agencies, regulated industries, or FedRAMP experience.
  • Knowledge of NIST 800-30/800-37/800-53A/800-137.
  • Hybrid or cloud-native environments with security inheritance.

Responsibilities

  • Lead RMF activities across all phases.
  • Design, implement, and validate NIST 800-53 Rev 5 controls.
  • Develop and maintain SSPs, SARs, POA&Ms, and related plans.
  • Coordinate security control assessments, pen tests, vulnerability scans, audits.
  • Guide engineering on implementing controls per Rev 5.
  • Evaluate changes for security impact and control updates.
  • Lead risk assessments and track remediation via POA&M.
  • Manage continuous monitoring, logs, patches, baselines.
  • Serve as security liaison to owners, assessors, AOs.
  • Mentor junior ISSOs and analysts.
  • Stay current on NIST updates.

Skills

RMF
NIST SP 800-53 Rev 5
SSP
SAR
POA&Ms
Cloud environments
CISSP
CISM
FedRAMP
RMF documentation

Education

Bachelor's degree in Cybersecurity/Information Assurance

Tools

SIEMs
Vulnerability scanners
Endpoint protection
Identity governance
Configuration management

Job description

Be Challenged and Make a Difference

In a world of technology, people make the difference. We believe if we invest in great people, then great things will happen. At AnaVation, we provide unmatched value to our customers and employees through innovative solutions and an engaging culture.

Description of Task to be Performed:

AnaVation is seeking a Senior-level ISSO to support a newly-awarded contract. The selected candidate must be able toexcel as the sole ISSO to prepare a full accreditation package to quickly obtain ATT/ATO for a new digital evidenceplatform in support of our Federal Government client. This is a full-time position that can be performed remotely withoccasional travel to Washington DC as needed.

What you will be doing

  • Lead all RMF activities for the assigned system, including Categorization, Selection, Implementation,Assessment, Authorization, and Continuous Monitoring.
  • Oversee the design, implementation, and validation of NIST 800-53 Rev 5 security and privacy controls acrosstechnical, operational, and management domains.
  • Develop, maintain, and update key security artifacts including System Security Plans (SSPs), SecurityAssessment Reports (SARs), POA&Ms, Incident Response Plans, and Continuous Monitoring strategies.
  • Coordinate and support security control assessments (SCAs), penetration tests, vulnerability scans, andcompliance audits.
  • Guide engineering teams on implementing and documenting new or updated security controls, ensuring theyalign with Rev 5 enhancements and control baselines.
  • Evaluate system changes, architecture updates, and new integrations for security impact and required control modifications.
  • Lead risk assessments, document findings, and track remediation through POA&M management.
  • Manage continuous monitoring activities, including log review, vulnerability management, patch tracking, and configuration baseline validation.
  • Serve as the primary security liaison for system owners, internal stakeholders, external assessors, and authorizing officials (AOs).
  • Assist in developing security control inheritance strategies from enterprise common controls, and ensure proper documentation and alignment.
  • Mentor junior ISSOs and analysts in RMF, control interpretation, documentation quality, and security best practices.
  • Stay current on updates to NIST SP 800-53 Rev 5, 800-37, 800-30, and emerging federal cybersecurity guidance.
  • Bachelors Degree in a relevant field such as Cybersecurity or Information Assurance
  • 10+ years of relevant, hands‑on experience in an ISSO or security compliance role
  • Clearance:
  • Public Trust; US Citizenship is required
  • Other Required Skills & Qualifications:
  • Deep knowledge of NIST SP 800-53 Rev 5 controls, enhancements, baselines, and assessment procedures.
  • Hands‑on experience managing RMF packages and maintaining ongoing authorization.
  • Strong understanding of enterprise IT systems, networks, operating systems, identity platforms, and cloudenvironments (Azure, AWS, GCP).
  • Experience producing and maintaining SSPs, SARs, POA&Ms, Continuous Monitoring Plans, andsupporting RMF documentation.
  • Familiarity with security tools such as SIEMs, vulnerability scanners, endpoint protection, identitygovernance platforms, and configuration management solutions.
  • Strong communication skills for interfacing with system owners, engineers, auditors, and executiveleadership.
  • Ability to articulate control requirements and translate them into technical implementations.
  • Professional certifications such as CISSP, CISM, CAP, CCSP, or equivalent.
  • Prior experience supporting federal agencies, regulated industries, or FedRAMP systems.
  • Knowledge of NIST 800-30 (Risk Assessment), 800-37 (RMF), 800-53A (Control Assessments), and 800-137(Continuous Monitoring).
  • Experience working in hybrid or cloud-native environments with security control inheritance patterns.
  • Background in DevSecOps or automated compliance tooling.
Benefits
  • Generous cost sharing for medical insurance for the employee and dependents
  • 100% company paid dental insurance for employees and dependents
  • 100% company paid long-term and short-term disability insurance
  • 100% company paid vision insurance for employees and dependents
  • 401k plan with generous match and 100% immediate vesting
  • Competitive Pay
  • Generous paid leave and holiday package
  • Tuition and training reimbursement
  • Life and AD&D Insurance
About AnaVation

AnaVation is the leader in solving the most complex technical challenges for collection and processing in the U.S. Federal Intelligence Community. We are a US owned company headquartered in Chantilly, Virginia. We deliver groundbreaking research with advanced software and systems engineering that provides an information advantage to contribute to the mission and operational success of our customers. We offer complex challenges, a top‑notch work environment, and a world‑class, collaborative team.

If you want to grow your career and make a difference while doing it, AnaVation is the perfect fit for you!

AnaVation is an equal opportunity employer. All qualified applicants will receive consideration for employment without regard to sex, race, color, religion, national origin, disability, protected Veteran status, age, or any other characteristic protected by law.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Information System Security Officer (ISSO)
Information System Security Officer (ISSO)

Anavationllc • Washington

On-site
USD 135,000 - 180,000
Medical insurance
Dental insurance
Vision insurance
+4
Information System Security Officer (ISSO)
Information System Security Officer (ISSO)

AnaVation, LLC • Washington

On-site
USD 140,000 - 190,000
Medical insurance
Dental insurance
Vision insurance
+5
Information System Security Officer (ISSO)
Information System Security Officer (ISSO)

AnaVation • Washington

On-site
USD 86,000 - 202,000
Medical insurance
Dental insurance
Disability insurance
+5
Information System Security Officer (ISSO)
Information System Security Officer (ISSO)

Nava • Washington, Northern (KY)

Hybrid
USD 86,000 - 202,000
Medical insurance
Dental insurance
Disability insurance
+5
Information System Security Officer (ISSO)
Information System Security Officer (ISSO)

AnaVation LLC • Washington

On-site
USD 120,000 - 190,000
Medical insurance
Dental insurance
Vision insurance
+2
Information System Security Officer (ISSO)
Information System Security Officer (ISSO)

Lever, Inc. • Huntsville (AL)

On-site
USD 120,000 - 160,000
Medical insurance (employee + depend.)
Dental insurance (employee + depend.)
Disability insurance (short/long-term)
+5
Information Systems Security Officer (ISSO)
Information Systems Security Officer (ISSO)

AnaVation, LLC • San Antonio (TX)

On-site
USD 110,000 - 170,000
Medical insurance
Dental insurance
Vision insurance
+3
Information Systems Security Officer (ISSO)
Information Systems Security Officer (ISSO)

AnaVation LLC • San Antonio (TX)

On-site
USD 130,000 - 180,000
Health insurance
Dental insurance
Disability insurance
+5
Information Systems Security Manager (ISSM)
Information Systems Security Manager (ISSM)

AnaVation, LLC • San Antonio (TX)

On-site
USD 140,000 - 190,000
Medical insurance
Dental insurance
Disability insurance
+5
Cybersecurity Systems Engineer / ISSM
Cybersecurity Systems Engineer / ISSM

AnaVation, LLC • Chantilly (VA)

On-site
USD 120,000 - 160,000
401k plan with generous match
Tuition and training reimbursement
Competitive Pay