Mid-Level Information System Security Officer (ISSO) / System Owner Support

K2United

United States

On-site

USD 80,000 - 105,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

401(k) with employer matching
Medical coverage
Paid time off
Tuition assistance
Wellness stipend
Casual work environment
Training and certification support
CareerSafe online training access

Job summary

K2United is seeking an experienced Information System Security Officer to guide client systems through the RMF and ATO lifecycle, developing authorization artifacts and ensuring compliance across multiple federal systems.

You will work with system owners, engineers, privacy professionals, and leadership to deliver SSPs, ISAs, CP/IRP plans, and continuous monitoring strategies while applying AI RMF guidance where applicable.

Qualifications

  • Four+ years as ISSO or RMF package development in a federal environment.
  • Experience developing SSPs, BIAs, PTA/PIA, and CMP.

Responsibilities

  • Develop and maintain RMF artifacts (SSP, BIA, FIPS 199, PTA/PIA, CMP).
  • Create system architecture diagrams and boundary documents.
  • Assist with security control scoping, tailoring, and overlays (AI Overlay when applicable).
  • Apply NIST AI RMF 1.0 and OMB guidance for AI/ML systems.
  • Support ISAs, MOUs, and other authorization docs.
  • Validate evidence (config artifacts, scans) for SP 800-53 Rev.5 compliance.
  • Develop Contingency Plans, IRP, and ConMon plans.
  • Coordinate annual contingency and incident response testing and training.
  • Maintain RMF templates, cloud assessment playbooks, and SharePoint security content.

Skills

Written communication
Stakeholder engagement
Technical documentation
RMF knowledge

Education

Bachelor's degree or equivalent

Tools

eMASS
CSAM
Xacta
JCAM

Job description

Description

K2United is an organization that houses two distinct, national, customer-facing brands tied together by a shared purpose: setting the standard for an extraordinary workplace. Through our brands, K2Share and CareerSafe, we provide advisory services in cyber risk management and online education for workforce readiness.


Our four core values define how we show up every day:



  • Respect Others - We lead with respect, building trust and connection.

  • Internally Driven - We are relentlessly compelled to accomplish our objectives.

  • Collaborative Innovation - We create by listening, sharing, and working together.

  • Client Success - We hold our clients' mission as our own.


We believe in people who are accountable, curious, and motivated to make an impact that matters.


Our programs make a meaningful difference. CareerSafe supports more than two million users each year, while K2Share delivers cybersecurity and IT solutions that strengthen federal agencies. As part of our team, you'll help solve complex challenges in a mission-driven, small-business environment that values professional growth, collaboration, and work-life balance.


Job Type

Contract


About You

You are an experienced cybersecurity professional who enjoys helping organizations successfully navigate the Risk Management Framework while balancing mission objectives and security requirements. You understand that effective RMF implementation requires more than documentation. It requires collaboration, sound technical judgment, and the ability to translate complex security requirements into practical guidance.


You are comfortable working directly with system owners, engineers, privacy professionals, and leadership to develop authorization packages, continuous monitoring strategies, and security documentation that withstands rigorous review. You communicate clearly, stay organized across multiple systems, and take ownership of helping programs achieve and maintain compliance.


You thrive in an environment where you can combine technical expertise with consulting, mentorship, and process improvement to strengthen an organization's overall cybersecurity posture.


Your Impact

As the Information System Security Officer, you will help guide client systems through every phase of the RMF and ATO lifecycle. Your expertise will support secure system design, authorization, continuous monitoring, and operational readiness while serving as a key resource for system owners and stakeholders.


In this role, you will:


  • Develop and maintain RMF authorization artifacts, including the System Security Plan (SSP), Business Impact Analysis (BIA), FIPS 199 categorization, Privacy Threshold and Privacy Impact Assessments (PTA/PIA), Configuration Management Plan (CMP), and e-Authentication documentation.

  • Create foundational system documentation, including Boundary Scope Memorandums (BSM), System Architecture diagrams, and Authorization Boundary and Network Diagrams (ABND).

  • Assist system owners with security control scoping, tailoring, inheritance, and identification of applicable overlays, including the client's AI Overlay where applicable.

  • Apply the NIST AI Risk Management Framework (AI RMF 1.0) and relevant OMB guidance for systems incorporating Artificial Intelligence or Machine Learning capabilities.

  • Support development of Interconnection Security Agreements (ISAs), Memorandums of Understanding (MOUs), and other authorization documentation.

  • Validate technical evidence, including configuration artifacts, scan reports, and system documentation, to ensure compliance with NIST SP 800-53 Rev. 5 prior to authorization package submission.

  • Develop and maintain system-level Contingency Plans (CP), Incident Response Plans (IRP), and Continuous Monitoring (ConMon) Plans.

  • Coordinate and document annual contingency and incident response testing, including corrective actions and follow-up activities.

  • Develop and deliver annual contingency planning and incident response training for system personnel.

  • Maintain RMF templates, SDLC security artifacts, cloud assessment playbooks, process guides, and SharePoint security content, including the Educational Materials and Checklists library with annual updates.

  • Facilitate RMF training sessions, office hours, and user guidance while identifying opportunities to improve authorization processes, such as streamlined Authority to Use (ATU) pathways.

  • Serve as the primary security advisor to system owners, stakeholders, and the client Privacy Coordinator throughout the RMF and ATO lifecycle.

  • Review FedRAMP Cloud Service Provider packages, support secure cloud deployments, assist with system decommissioning, and help resolve discrepancies within enterprise GRC tools.


Requirements


  • Bachelor's degree in a related field, or equivalent experience as allowed by company and contract policy.

  • Four or more years of experience serving as an ISSO or supporting RMF authorization package development within a federal environment.

  • Hands-on experience developing System Security Plans (SSPs), Business Impact Analyses (BIAs), FIPS 199 categorizations, Privacy Threshold and Privacy Impact Assessments (PTA/PIA), and Configuration Management Plans.

  • Working knowledge of NIST SP 800-37 (RMF), NIST SP 800-53 Rev. 5, NIST SP 800-18, and FISMA.

  • Experience developing, maintaining, and testing system-level Contingency Plans and Incident Response Plans.

  • Strong written communication, stakeholder engagement, and technical documentation skills.

  • Ability to meet federal background investigation requirements.


Preferred Qualifications


  • Active certification such as CISSP, CGRC/CAP, CISM, or CompTIA Security+.

  • Experience using GRC and authorization platforms such as eMASS, CSAM, Xacta, or JCAM.

  • Experience supporting FedRAMP authorizations and cloud environments in AWS and/or Azure.

  • Familiarity with the NIST AI Risk Management Framework (AI RMF 1.0).

  • Prior support to federal civilian agency cybersecurity programs.


Benefits


  • 401(k) with employer matching

  • Low-cost medical coverage for employees and their families

  • Paid time off

  • Paid leave for jury duty, military service, voting, and other qualifying events

  • Wellness stipend, including fitness reimbursement

  • Tuition assistance

  • Casual work environment

  • Technical training and certification support

  • Complimentary access to CareerSafe online training courses for employees and their immediate family


Equal Opportunity Employer

K2United is an equal opportunity employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, sexual orientation, gender identity, disability, protected veteran status, or any other characteristic protected by applicable law.


Salary Description

$80,000 - $105,000

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

ISSO/ISCM Lead
ISSO/ISCM Lead

K2United, LLC. • Washington

On-site
USD 120,000 - 180,000
Senior Information Systems Security Officer
Senior Information Systems Security Officer

Saic • Washington

Hybrid
USD 120,000 - 160,000
Information Systems Security Officer (Technical ISSO / RMF Assessor)
Information Systems Security Officer (Technical ISSO / RMF Assessor)

Peraton • Riverdale Park (MD)

On-site
USD 112,000 - 179,000
Heavily subsidized employee benefits
25 days of PTO annually
Eligibility for bonus plan
Information System Security Officer (ISSO)
Information System Security Officer (ISSO)

IPSECURE, INC. • Satellite Beach (FL)

On-site
USD 110,000 - 160,000
Medical insurance
Dental & Vision coverage
401(k) retirement plan
+2
Information Systems Security Officer (ISSO)
Information Systems Security Officer (ISSO)

Cgsfederal • New York (NY)

On-site
USD 95,000 - 150,000
Health, Dental, and Vision
Life Insurance
401k
+2
Information Systems Security Officer (ISSO)
Information Systems Security Officer (ISSO)

Cgsfederal • Chicago (IL)

On-site
USD 110,000 - 165,000
Health, Dental, and Vision
Life Insurance
401k
+3
Information Systems Security Officer (ISSO), Mid (MCSES III)
Information Systems Security Officer (ISSO), Mid (MCSES III)

AMERICAN SYSTEMS • San Diego (CA)

On-site
USD 110,000 - 186,000
Healthcare benefits
Paid leave
Retirement plans
+2
Information Systems Security Officer (ISSO)
Information Systems Security Officer (ISSO)

Cgsfederal • Atlanta (GA)

On-site
USD 110,000 - 140,000
Health, Dental, and Vision
Life Insurance
401k
+2
Information System Security Officer
Information System Security Officer

M2 Technology Group • Fort Meade (MD)

On-site
USD 140,000 - 190,000
20 Days of Personal Time Off
401k with 10% Employer Contribution
$7,500 Training/Tuition Reimbursement
+3
Information Systems Security Officer (ISSO)
Information Systems Security Officer (ISSO)

Cgsfederal • Los Angeles (CA)

On-site
USD 110,000 - 140,000
Health, Dental, and Vision
Life Insurance
401k
+2