Senior Information Security Analyst DoS CSS

OneZero Solutions

Washington (District of Columbia)

Remote

USD 110,000 - 170,000

Full time

6 days ago
Be an early applicant
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Benefits offered by this job

Health, dental, vision, life insurance
401(k) with company matching
Paid time off and holidays
Employee referral program
Educational assistance

Job summary

OneZero Solutions is seeking a Senior Information Security Analyst to serve as ISSO for a portfolio of 6–8 moderate-baseline systems and lead RMF activities end to end. You will own authorization packages, guide remediation, and coordinate with IA staff and contractors. The role requires a final SECRET clearance, strong technical writing, and experience with NIST SP 800-37/53 Rev.

5. Remote work within the National Capital Region is required and responsibilities include audit support and

Qualifications

  • 7+ years information security experience, including 4+ years as ISSO for federal systems.
  • CISSP, CISM, CGRC/CAP, or CISA (DoD IAM Level II or higher)
  • Active, final SECRET security clearance; U.S. citizenship.
  • Experience with an enterprise GRC tool and interpreting vulnerability scans.

Responsibilities

  • Serve as ISSO of record for 6–8 moderate-baseline systems.
  • Execute RMF Steps 1–3 for assigned systems with proper documentation.
  • Maintain POA&Ms in the GRC tool with timely updates.
  • Coordinate incident reporting and remediation with SOC and system owners.
  • Support audits and data calls; provide day-to-day direction to IA Analysts.

Skills

ISSO experience
RMF
GRC tooling
Vulnerability analysis
Technical writing
Stakeholder coordination
Security clearance

Education

Bachelor's degree in CS/IT/Cybersecurity
Active SECRET clearance

Tools

ArchAngel GRC
iPost
NIST/Control mapping tools

Job description

We are an employee-centric company that truly values our team members and the contributions they make to our customers and the missions they support. We pride ourselves on being forward-leaning thinkers and on building teams that are, and continue to be, technically proficient across a broad range of cyber mission areas. OneZero full-time employees receive a highly competitive benefits package, including health, dental, vision, and life insurance, a 401(k) with company matching, paid time off and holidays, an employee referral program, and educational assistance. Additional details are available on our website: https://www.onezerollc.com/careers/

Position Title: Senior Information Security Analyst

Location: Remote; must reside within the National Capital Region (NCR).

Clearance: Secret

Work Schedule: Full-time, 40 hours per week. Must be available during Department core hours of 9:00 a.m. – 3:00 p.m. ET, Monday – Friday, and flex working hours as needed to meet CST day-to-day and emergent requirements. No work is performed on Federal holidays or during Government closures.

Employment Type: Full-Time, Exempt (W-2), contingent upon Call Order award

Position Summary

The Senior Information Security Analyst serves as ISSO of record for an assigned portfolio of approximately 6–8 Moderate-baseline consular systems. The Senior Analyst owns each system's authorization package and continuous monitoring cadence end to end, leads the system's triennial RMF cycle, directs technical remediation by system operations teams, and provides day-to-day direction to Information Assurance Analysts supporting the portfolio.

Key Responsibilities
  • Serve as ISSO of record and primary cybersecurity point of contact for an assigned portfolio of approximately 6–8 Moderate-baseline systems.
  • Execute RMF Steps 1–3 for assigned systems: categorization with CIA justification, baseline and overlay selection, tailoring rationale, Inherited Controls Matrix, SSP and Security Control Implementation Statements, Evidence Index, and Implementation Readiness Review.
  • Develop and maintain PIA, DIRA, ISA/MOU, Security Assessment Plan, POA&Ms, SIA, system inventory, IRP, CP/ISCP, CP Test report, and CMP for assigned systems; ensure CMPs are delivered into the GRC tool.
  • Set up and support Security Control Review Meetings and demos, collect and validate artifacts requested by the SCA, attend A&A Findings Meetings, and support remediation validation (RMF Step 4).
  • Maintain authoritative POA&Ms in the GRC tool (monthly updates and within 5 business days of status changes) with realistic milestones, accurate risk levels, and closure evidence attached (RMF Step 6).
  • Review iPost scores weekly; coordinate remediation with system and application teams; track and report findings open more than 30 days.
  • Review vulnerability, KEV, CVE, and STIG results within 5 business days; drive critical and high remediation within Department and BOD timelines; document in POA&Ms.
  • Conduct annual Contingency Plan tests and Annual Control Assessments; document results and lessons learned; update CP, ISCP, IRP, and CMP as needed.
  • Perform Security Impact Analyses for hardware, software, patch, and configuration changes; participate in CCB/ECM; contribute to the Quarterly Configuration and Change Impact Summary.
  • Coordinate incident reporting and documentation with the SOC and system owners; reflect outcomes in risk posture and POA&Ms.
  • Direct system-specific security operations contractors to obtain evidence and implement remediation; validate completion before POA&M closure.
  • Support audits and data calls (OIG, GAO, CISA, HVA, BOD, OMB, CDM) and maintain the Audit and Data Call Response Package for assigned systems.
  • Provide day-to-day direction and quality review for Information Assurance Analysts supporting the portfolio.
Required Qualifications
  • Seven (7)+ years of information security experience, including four (4)+ years as an ISSO or in an equivalent A&A role for federal information systems.
  • Demonstrated experience authoring SSPs, POA&Ms, contingency plans, and supporting authorization packages under NIST SP 800-37 / SP 800-53 Rev. 5.
  • One of: CISSP, CISM, CGRC/CAP, or CISA (DoD 8140/8570 IAM Level II or higher).
  • Active, final SECRET security clearance; U.S. citizenship.
  • Experience with an enterprise GRC tool and with interpreting vulnerability scan results.
  • Strong technical writing and stakeholder coordination skills.
Preferred Qualifications
  • Department of State (DT/CA/CST) experience; ArchAngel and iPost proficiency.
  • Experience with cloud or hybrid authorization boundaries and FedRAMP inheritance.
  • Experience conducting NIST SP 800-34 contingency plan tests and NIST SP 800-63 Digital Identity Risk Assessments.
  • Security+ CE, CySA+, or CCSP in addition to the required certification.
Technical Skills
  • NIST SP 800-37 Rev. 2, 800-53/53A Rev. 5, 800-60, 800-34, 800-61, FIPS 199/200; CISA BODs and KEV.
  • GRC platforms (ArchAngel or equivalent), iPost or equivalent, POA&M lifecycle management.
  • Reading Tenable/Nessus, Wiz, and STIG output; understanding of patch and configuration management.
  • Visio diagramming; advanced Word/Excel; SharePoint/Teams collaboration.
Security Clearance

Active, final SECRET

Education

Bachelor's degree in Computer Science, Information Technology, Cybersecurity, or a related field, or an additional four (4) years of directly relevant experience in lieu of degree.

Remote/Hybrid/On-site and any other relevant work-environment requirement

Remote. Duties are performed remotely; the selected candidate must reside within the National Capital Region (NCR). The Government does not furnish equipment; OneZero provides the laptop and collaboration tools. Position requires an OpenNet account, DoS PIV badge, multifactor authentication, and adherence to DoS SBU/CUI handling requirements. Local travel within the National Capital Region; minimal other travel.

Contract

U.S. Department of State, Bureau of Diplomatic Technology (DT), Enterprise Applications (EA), Consular Systems and Technology (CST) ISSO Support. GSA MAS HACS BPA 19AQMM26Q0274, Call Order 1 (RFQ 19AQMM26R0381). Firm-Fixed-Price; 12-month base period (including 3-month transition-in) plus four 1-year option periods; anticipated start September 30, 2026.

Position Status

New Position, contingent upon Call Order award

OneZero Solutions LLC is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability, or protected veteran status.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Senior Information Security Analyst DoS CSS
Senior Information Security Analyst DoS CSS

OneZero Solutions • Washington

Remote
USD 110,000 - 150,000
SME – Information Security Analyst DoS CSS
SME – Information Security Analyst DoS CSS

OneZero Solutions • Washington

Remote
USD 150,000 - 190,000
Health insurance
Dental insurance
Vision insurance
+6
Program Manager DoS CSS
Program Manager DoS CSS

OneZero Solutions • Washington

Remote
USD 150,000 - 210,000
Health, dental, vision, life insurance
401(k) with company matching
Paid time off and holidays
+2
Deputy Program Manager DoS CSS
Deputy Program Manager DoS CSS

OneZero Solutions • Washington

Remote
USD 120,000 - 160,000
Health insurance
Dental insurance
Vision insurance
+5
Technical Writer DoS CSS
Technical Writer DoS CSS

OneZero Solutions • Washington

Remote
USD 90,000 - 130,000
Health insurance
Dental insurance
Vision insurance
+6
DHS Information Systems Security Officer (ISSO) Senior
DHS Information Systems Security Officer (ISSO) Senior

onezerollc • Washington

On-site
USD 180,000 - 230,000
Parking stipend/parking allowance
DHS Information System Security Officer II
DHS Information System Security Officer II

onezerollc • Washington

On-site
USD 110,000 - 165,000
Parking stipend
Information Assurance Specialist III
Information Assurance Specialist III

onezerollc • Arlington (VA)

Hybrid
USD 120,000 - 150,000
Health insurance
Dental insurance
Vision insurance
+6
DHS Information Systems Security Officer (ISSO) Senior
DHS Information Systems Security Officer (ISSO) Senior

OneZero Solutions • Washington

On-site
USD 120,000 - 150,000
Health insurance
401K with company matching
PTO & paid holidays
+2
Information Assurance Specialist III
Information Assurance Specialist III

OneZero Solutions • Arlington (VA)

On-site
USD 110,000 - 150,000
Health insurance
Dental insurance
Vision insurance
+5