Mid-Level Federal ISSO & RMF Control Evaluator

Koniag Services, Inc.

Washington (District of Columbia)

On-site

USD 90,000 - 130,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Koniag Data Solutions, LLC, a Koniag Government Services company, is seeking a Mid-Level Information Systems Security Officer (ISSO) / Control Evaluator to support SBA and SBA systems in Washington, DC. The role requires building and maintaining RMF artifacts, performing security control assessments, and working with SBA stakeholders to ensure compliance with federal standards.

Qualified candidates will have 4+ years in information security, be able to obtain a Public Trust, and hold relevant

Qualifications

  • Bachelor's degree in Cybersecurity, Information Technology, Computer Science, Information Assurance, or a related field from an accredited college or university.
  • 4+ years of progressive experience in information security, with at least 2 years of dedicated experience as an ISSO, security control assessor, or security authorization specialist supporting federal information systems.
  • One or more of the following certifications: CISSP, CAP/CGRC, Security+, GSEC, CISM.
  • Master's degree in Cybersecurity, Information Assurance, Information Technology, or a related field.
  • 6+ years of information security experience, with strong background supporting federal civilian agency ISSO and security authorization activities.
  • Prior experience supporting SBA or other federal civilian agency ISSO or security control assessment programs.

Responsibilities

  • Serve as the Information Systems Security Officer (ISSO) for assigned SBA information systems, providing day-to-day information security support, guidance, and oversight to system owners, program teams, and IT staff responsible for the operation and maintenance of those systems.
  • Support the full NIST RMF lifecycle for assigned systems, including security categorization, security control selection and tailoring, security control implementation review, security control assessment, security authorization package development, and continuous monitoring activities.
  • Develop, maintain, and update security authorization documentation for assigned systems, including SSPs, SARs, POA&Ms, RARs, and other ATO package artifacts in accordance with NIST SP 800-53/800-53A and SBA requirements.
  • Conduct security control assessments and evaluations for assigned systems, applying NIST SP 800-53A assessment procedures to evaluate design, implementation, and operational effectiveness of controls.
  • Support development and maintenance of POA&M items, tracking weaknesses and remediation activities, updating status regularly.
  • Perform continuous monitoring activities, reviewing vulnerability scans, configuration compliance, and other security-relevant data to assess ongoing posture.
  • Review vulnerability scan results from Nessus, Tenable.io, or equivalent platforms, assess severity and coordinate remediation with owners.
  • Support preparation and submission of security authorization packages to the AO/AODR, ensuring completeness and compliance.
  • Collaborate with owners, developers, and IT operations to ensure security requirements are implemented throughout the lifecycle.
  • Review proposed changes for security impact and document findings and recommendations.
  • Support third-party assessments, OIG audits, and external evaluations with required evidence.
  • Provide security guidance to system owners and program teams on evolving federal requirements.
  • Contribute to continuous improvement of SBA's security authorization and monitoring program.

Skills

Strong communication skills
RMF lifecycle knowledge
Public Trust readiness
Security control assessment experience
Federal information systems awareness

Education

Bachelor's degree in Cybersecurity/IT/CS/IA
Master's degree in Cybersecurity/IA/IT or related field

Tools

Nessus
Tenable.io
CSAM
Archer
ServiceNow GRC

Job description

Koniag Data Solutions, LLC, a Koniag Government Services company, is seeking a Mid-Level Information Systems Security Officer (ISSO) / Control Evaluator to support SBA and SBA systems in Washington, DC. The role requires building and maintaining RMF artifacts, performing security control assessments, and working with SBA stakeholders to ensure compliance with federal standards.

Qualified candidates will have 4+ years in information security, be able to obtain a Public Trust, and hold relevant

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Junior ISSO & Security Controls Evaluator
Junior ISSO & Security Controls Evaluator

Koniag Services, Inc. • Washington

On-site
USD 70,000 - 110,000
Health insurance
Dental insurance
Vision insurance
+4
Senior ISSO & Controls Evaluator RMF Expert
Senior ISSO & Controls Evaluator RMF Expert

Koniag Services, Inc. • Washington, Northern (KY)

Hybrid
USD 120,000 - 180,000
Health, dental, vision insurance
401K with company match
Paid holidays
+1
ISSO & Control Evaluator — RMF & FISMA (Hybrid/Remote)
ISSO & Control Evaluator — RMF & FISMA (Hybrid/Remote)

Viateq Corporation • Washington

Hybrid
USD 115,000 - 145,000
Medical, dental, and vision insurance
401(k) plan
Paid time off + 12 federal holidays
+2
Security Control Assessor - Federal RMF/NIST Expert
Security Control Assessor - Federal RMF/NIST Expert

Koniag Government Services • Washington

Hybrid
USD 120,000 - 180,000
Health, dental, and vision insurance
401K with company matching
Flexible spending accounts
+2
Mid-Level Information Systems Security Officer (ISSO) / Control Evaluator
Mid-Level Information Systems Security Officer (ISSO) / Control Evaluator

Koniag Services, Inc. • Washington

On-site
USD 90,000 - 130,000
Junior Federal RMF Compliance & Audit Specialist (Hybrid)
Junior Federal RMF Compliance & Audit Specialist (Hybrid)

Koniag Government Services • Washington

Hybrid
USD 65,000 - 85,000
Health, dental, and vision insurance
401K with company matching
Flexible spending accounts
+2
Senior ISSO & RMF Lead — Federal Cybersecurity Expert
Senior ISSO & RMF Lead — Federal Cybersecurity Expert

E Logic • Washington

On-site
USD 120,000 - 180,000
ISSO for National Security Cyber | RMF & Security Lead
ISSO for National Security Cyber | RMF & Security Lead

KBR Careers • Washington

On-site
USD 108,000 - 164,000
ISSO – Federal InfoSec Specialist (Mid-Level)
ISSO – Federal InfoSec Specialist (Mid-Level)

Saliense Consulting LLC • Arlington (VA)

On-site
USD 110,000 - 150,000
20 Days PTO
Health insurance
Dental insurance
+4
Mission-Driven ISSO: Secure Federal Systems & RMF Expert
Mission-Driven ISSO: Secure Federal Systems & RMF Expert

Credence Management Solutions, LLC • Arlington (VA)

On-site
USD 120,000 - 170,000