Senior Information Systems Security Officer

APTNEXUS

Virginia (MN)

On-site

USD 135,000 - 165,000

Full time

14 days+
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Job summary

AptNexus seeks an experienced Information Systems Security Officer (ISSO) to support a civilian agency. You will manage RMF-driven security activities, author and maintain SA&A artifacts, and ensure continuous monitoring across systems.

Responsibilities include coordinating with AO/SO/CISO, producing SSPs and CAPs, and guiding audit responses. A SECRET clearance is required and on-site work is standard under contract terms.

Qualifications

  • 7–10 years of ISSO/Manager experience in federal or federal contractor environments.
  • Strong knowledge of RMF (SP 800-37 Rev 2) and NIST SP 800-53 Rev 5.
  • Experience developing and maintaining SA&A artifacts (SSPs, POA&Ms, SARs, BIAs, CPs/CPTs).
  • Ability to obtain and maintain required security clearance.

Responsibilities

  • Provide ISSO support for agency systems across their lifecycle.
  • Develop and maintain SA&A artifacts and plan of action and milestones.
  • Conduct daily continuous monitoring and generate related reports.
  • Coordinate security change management and documentation updates.
  • Prepare ATT, SIA, and audit response documentation monthly or as required.
  • Lead gathering of audit artifacts and respond to PBC requests.

Skills

NIST RMF
GRC (Xacta 360)
Security Audits
Audit coordination

Education

Bachelor’s degree in CS/IT

Tools

Xacta 360
Splunk
Elastic

Job description

Salary Range:
  • Up to $150,000 per year based on experience.
Location:
  • Onsite 5 days per week - Required per contract.
Clearance:
  • Active Secret Required
Position Overview:

AptNexus is seeking an experienced Information Systems Security Officer (ISSO) to support our civilian agency customer. In this role, you will provide assigned ISSO support for agency systems throughout their lifecycle, performing daily, weekly, and continuous systems monitoring duties in alignment with the NIST Risk Management Framework (RMF), Departmental/Treasury policy, and Agency-specific cybersecurity requirements.

  • Ensure applicable cybersecurity policies and controls are implemented for the agency’s existing and new systems, maintaining an operational security posture consistent with current policy.
  • Serve as the principal advisor to the Authorizing Official (AO), System Owner (SO), and/or CISO on all matters (technical and otherwise) involving assigned system security.
  • Develop and maintain a full suite of SA&A artifacts, including: FIPS 199 categorizations, System Security Plans (SSPs), Privacy Threshold Analyses (PTAs), Privacy and Civil Liberties Impact Assessments (PCLIAs), Contingency Plans (CP) and Contingency Plan Tests (CPTs), Business Impact Analyses (BIAs), Security Assessment Reports (SARs), IV&V Reports, Risk Acceptances, Waivers, MOUs/ISAs, and Deviations.
  • Develop, update, and maintain Plan of Action & Milestones (POA&M) reports on a monthly basis and as directed, providing trending analysis and remediation recommendations. Monitor open POA&Ms to ensure timely resolution.
  • Conduct daily continuous monitoring of agency systems to ensure compliance with all applicable requirements and generate associated reports.
  • Coordinate with System Owners to ensure system security documentation is maintained and that changes to systems are evaluated for security impact through the agency change management process.
  • Support the development, maintenance, and reporting of Authority to Test (ATT) and Security Impact Analysis (SIA) documentation on a monthly basis or as required.
  • Ensure that system audit trails are regularly examined and anomalies are reported to the bureau CSIRC or other designated security officials.
  • Support the implementation and ongoing authorization of agency systems using NIST SP 800-137 Rev-2 (ISCM) guidance, supporting the Bureau’s transition from time-based ATOs to Ongoing Authorization.
  • Maintain and support 100% of the agency’s system ATOs in an active and compliant status at all times.
  • Ensure documentation detailing IT hardware and software configuration and all security countermeasures are developed and maintained.
  • Utilize the Agency’s Governance, Risk and Compliance (GRC) solution for development and maintenance of all required SA&A documentation.
  • Analyze reports from security and privacy monitoring tools including vulnerability scanners, SIEM (Splunk/Elastic), Endpoint Detection and Response (EDR), CDM tools (CrowdStrike/Qualys), and coordinate corrective actions with IT team members.
  • Support the agency in responding to audits, oversight reviews, and investigations from internal or external oversight organizations.
  • Lead and coordinate the gathering of audit artifacts in response to Provided by Client (PBC) requests from the Office of Inspector General (OIG), GAO, and other internal and external oversight bodies; establish and maintain a PBC tracking matrix with artifact owners, due dates, and submission status to ensure complete and on-time responses.
  • Analyze audit findings, Notices of Findings and Recommendations (NFRs), and corrective action requests; assess root cause, scope, and systemic risk; and develop technically accurate, fully documented Plan of Action and Milestones (POA&M) entries and Corrective Action Plans (CAPs) with realistic milestone schedules and responsible party assignments.
  • Draft formal agency finding responses, management comments, and corrective action narratives in response to OIG and GAO audit reports; coordinate review and approval with the CISO, System Owner, and AptNexus program leadership prior to submission; ensure responses are factually grounded, professionally written, and audit-ready.
  • Support pre-audit readiness reviews by assessing the completeness and accuracy of system security documentation, POA&M status, access control records, training completion records, and configuration baselines prior to scheduled audit engagements; identify and remediate documentation gaps before audit commencement.
  • Support change management activities including risk analysis of existing and new systems and identifying security requirements for new systems (security by design).
Education & Certifications** :**
  • Bachelor’s degree in Computer Science, Information Technology, or a related discipline from an accredited institution.
  • One or more of the following Level III certifications:
    • CISSP – Certified Information Systems Security Professional (required per contract)
    • CASP+ – CompTIA Advanced Security Practitioner
    • GDSA – GIAC Defensible Security Architect
    • Other equivalent certifications covering similar information security domains, depth of knowledge, or experience will be considered
Minimum Experience:
  • 7 to 10 years of experience as an Information Systems Security Officer or Manager in a federal or federal contractor environment.
  • Solid, hands‑on understanding of NIST RMF (SP 800-37 Rev 2), NIST SP 800-53 Rev 5, NIST SP 800-53A, NIST SP 800-137 Rev 2, and FISMA requirements.
  • Experience developing and maintaining complete SA&A packages including SSPs, POA&Ms, SARs, BIAs, CPs, and CPTs.
  • Experience with Governance, Risk, and Compliance (GRC) platforms, preferably Xacta 360.
  • Experience interpreting security and privacy findings from assessments, audits, vulnerability scans, and continuous monitoring tools.
  • Understanding of cloud security architecture across AWS, Azure, and/or Oracle Cloud environments.
  • Ability to obtain and maintain the required security clearance and pass suitability screening.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Information Systems Security Officer
Senior Information Systems Security Officer

APTNEXUS • Arlington (VA)

On-site
USD 135,000 - 165,000
Onsite 5 days per week
Senior Information Systems Security Officer
Senior Information Systems Security Officer

ECS Corporate Services • Washington

On-site
USD 120,000 - 145,000
Information Systems Security Officer Senior
Information Systems Security Officer Senior

Saic • Ashburn (VA)

Hybrid
USD 120,000 - 160,000
Senior Information Systems Security Officer
Senior Information Systems Security Officer

Saic • Washington

Hybrid
USD 120,000 - 160,000
Information System Security Officer (ISSO)
Information System Security Officer (ISSO)

Ara • Albuquerque (NM), Northern (KY)

Hybrid
USD 95,000 - 130,000
Information System Security Officer
Information System Security Officer

Hiring Our Heroes • Arlington (VA)

Hybrid
USD 90,000 - 130,000
Information System Security Officer
Information System Security Officer

Peraton • Maryland

On-site
USD 110,000 - 170,000
Senior Information System Security Officer (ISSO)
Senior Information System Security Officer (ISSO)

Unity Compass • Alexandria (VA)

Hybrid
USD 90,000 - 175,000
Information Systems Security Officer (ISSO) Mid Level (TS w/ SCI Eligibility) -
Information Systems Security Officer (ISSO) Mid Level (TS w/ SCI Eligibility) -

RedTrace Technologies • Washington

On-site
USD 80,000 - 100,000
Competitive salary
401(k) plan
Annual performance bonus
+5
Information System Security Officer
Information System Security Officer

Inadev • Reston (VA)

Hybrid
USD 110,000 - 170,000