Senior Information Systems Security Officer

Bamboo Solutions

Washington (District of Columbia)

Hybrid

USD 130,000 - 180,000

Full time

6 days ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Profit sharing
15 days PTO and 10 holidays
401(k) with employer matching
Health and dental benefits
Opportunity to work with technical pro

Job summary

SharePointXperts in Washington, DC seeks a Senior ISSO to support a U.S. government agency in the National Capital Region. The role validates security implementations, coordinates with engineers, and ensures evidence-based authorization across on-premises and cloud environments.

This senior position requires strong RMF/NIST knowledge, federal authorization experience, and the ability to obtain a public trust. Hybrid work arrangement and close interaction with SP MO staff are expected.

Qualifications

  • Bachelor’s degree and 6+ years of cybersecurity experience, or a master’s degree and 5+ years.
  • Ability to obtain and maintain a public trust requiring U.S. Citizenship or Green Card.
  • Hands-on experience in a technical role with evaluating implementations, validating controls, and challenging assumptions.
  • Experience supporting federal authorization activities (SSPs, POA&Ms, SIAs, continuous monitoring, and SCAs).
  • Knowledge of NIST RMF, NIST SP 800-53, FISMA, and federal cybersecurity requirements.
  • Familiarity with AWS, Azure, Microsoft 365, Entra ID, Active Directory, VMware, Cisco, Oracle, or similar.
  • Identity and access management, encryption, system hardening, logging and monitoring.
  • Experience with GRC or security authorization tools (Archer, eMASS, JCAM/CSAM, Xacta).
  • Strong written and spoken English; ability to produce polished documentation and communicate with stakeholders.
  • Proficiency with Microsoft Word, Excel, PowerPoint, and SharePoint.

Responsibilities

  • Support the security authorization lifecycle and monitoring activities for assigned systems.
  • Develop, review, and maintain security documentation and authorization artifacts (SSPs, SARs, POA&Ms, SIAs) per NIST RMF and agency policies.
  • Coordinate and prepare systems for Security Control Assessments (SCAs) with complete, accurate evidence.
  • Conduct Security Impact Analyses (SIAs) for changes to hardware, software, cloud infrastructure, connectivity, or architecture.
  • Review architecture and supporting evidence to validate controls and resolve discrepancies with engineers and system owners.
  • Support change management, continuous monitoring, POA&Ms, risk acceptance, audit responses, and remediation.
  • Coordinate with system owners and governance stakeholders for standards reviews, exceptions, policy implementation, and risk management.
  • Develop dashboards and executive risk briefings; assist Lead ISSO in operations and coordination.

Skills

RMF
ISSO experience
Cybersecurity
Information security
Technical writing
Security controls evaluation
Communication
Word/Excel/PowerPoint/SharePoint

Education

Bachelor's degree
Master's degree

Tools

Archer
eMASS
JCAM/CSAM
Xacta

Job description

We are looking for a Senior Information System Security Officer (ISSO) to support a critical U.S. government agency in the National Capital Region. This role reports to the Security Program Management Office (SPMO) Manager and works directly with team members and Federal ISSOs to support authorization, compliance, continuous monitoring, and risk management activities across assigned systems.

This is an excellent opportunity for an experienced cybersecurity professional with a strong technical background to support the secure authorization and ongoing compliance of systems across on-premises and cloud environments. This is not a hands-on engineering position. Instead, the Senior ISSO leverages prior experience as a Systems Administrator, Cloud Engineer, Infrastructure Engineer, Network Engineer, Security Engineer, or similar technical role to independently validate security implementations, assess technical risk, and ensure authorization decisions are supported by accurate technical evidence. The successful candidate must be comfortable engaging engineers, architects, and system owners to validate security controls, identify inconsistencies, and challenge unsupported technical assumptions.
Hybrid: 3 Days On-site in Washington, DC / 2 Days Remote
Must be able to obtain a government security clearance requiring U.S. Citizenship or Permanent Resident Status

Responsibilities:
  • Support the security authorization lifecycle and ongoing continuous monitoring activities for assigned systems.
  • Develop, review, and maintain security documentation and authorization artifacts, including SSPs, SARs, POA&Ms, SIAs, and related documentation, in accordance with NIST SP 800-53, RMF, FISMA, and agency policies.
  • Coordinate and prepare systems for Security Control Assessments (SCAs), ensuring documentation and evidence are complete, accurate, and technically defensible.
  • Conduct Security Impact Analyses (SIAs) for changes to hardware, software, cloud infrastructure, connectivity, or system architecture.
  • Review system architecture, technical documentation, and supporting evidence to validate security controls, independently assess technical implementations, identify inconsistencies, and collaborate with engineers, architects, administrators, and system owners to resolve discrepancies.
  • Support change management, continuous monitoring, POA&M management, risk acceptance, audit responses, and remediation activities to maintain ongoing authorization and compliance.
  • Coordinate with system owners, engineers, architects, and governance stakeholders to support standards reviews, exception requests, policy implementation, compliance reporting, and risk management activities.
  • Develop dashboards, executive risk briefings, status reports, and other stakeholder communications while supporting the Lead ISSO in operational execution and coordination activities.
Required Qualifications:
  • Bachelor’s degree and 6+ years of relevant experience, or a master’s degree and 5+ years of experience, in cybersecurity, RMF, ISSO, systems security engineering, systems administration, cloud engineering, network engineering, or a related field.
  • Ability to obtain and maintain a public trust requiring U.S. Citizenship or Green Card.
  • Prior hands-on experience in a technical role such as Systems Administrator, Cloud Engineer, Infrastructure Engineer, Network Engineer, or Security Engineer, with the ability to evaluate technical implementations, validate controls, assess evidence, and challenge unsupported assumptions.
  • Experience supporting federal authorization activities, including SSPs, POA&Ms, SIAs, continuous monitoring, and Security Control Assessments.
  • Working knowledge of NIST RMF, NIST SP 800-53, FISMA, and federal cybersecurity requirements.
  • Familiarity with enterprise and cloud technologies such as AWS, Azure, Microsoft 365, Entra ID, Active Directory, VMware, Cisco, Oracle, or similar platforms.
  • Working knowledge of identity and access management, encryption, system hardening, network and cloud security, secure baselines, logging, and monitoring.
  • Experience with GRC or security authorization tools such as Archer, eMASS, JCAM/CSAM, Xacta, or similar platforms.
  • Strong analytical, technical writing, organizational, and communication skills, including demonstrated professional proficiency in written and spoken English. Ability to independently produce polished, technically accurate documentation; communicate clearly and effectively with technical and non-technical stakeholders; work independently; and manage competing priorities in a fast-paced environment.
  • Proficiency with Microsoft Word, Excel, PowerPoint, and SharePoint.
Preferred Qualifications:
  • Security+, CGRC (formerly CAP), CISSP, CISM, CCSP, or similar cybersecurity certification.
  • Experience supporting federal systems, ATO processes, FedRAMP, federal privacy requirements, or other government compliance programs.
  • Knowledge of modern cybersecurity practices including OWASP Top 10, Zero Trust, application security concepts, and MITRE ATT&CK.
  • Experience participating in incident response, security architecture reviews, technical design reviews, or security remediation efforts.
  • Experience operating in fast-paced, high-visibility environments with competing priorities.
We offer:
  • Competitive salary based on experience
  • Profit sharing distributed twice a year
  • 15 days ofpaid time off and 10 paid holidays per year
  • 401(k)with employer matching
  • Healthand dental benefits
  • Opportunity to work with other talentedtechnical professionals

SharePointXperts is an Equal Opportunity/Affirmative Action employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, disability, or protected Veteran status.

SharePointXperts participates in E-Verify.Click the following links for important information about our participation in this program and your rights.

https://www.e-verify.gov/sites/default/files/everify/posters/IER_RightToWorkPoster%20Eng_Es.pdf

https://www.e-verify.gov/sites/default/files/everify/posters/EVerifyParticipationPoster.pdf

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Information Systems Security Officer (ISSO)
Information Systems Security Officer (ISSO)

Skysoft Inc. • Maryland

Hybrid
USD 120,000 - 170,000
Senior Information Systems Security Officer
Senior Information Systems Security Officer

Saic • Washington

Hybrid
USD 120,000 - 160,000
Cleared On Site Information Systems Security Officers (ISSO) (5359)
Cleared On Site Information Systems Security Officers (ISSO) (5359)

SMX • United States

On-site
USD 105,200 - 176,900
Health insurance
Paid leave
Retirement
Information System Security Officer (ISSO)
Information System Security Officer (ISSO)

Digital Global Connectors • McLean (VA)

Hybrid
USD 120,000 - 150,000
Lead Information System Security Officer (ISSO) / Technical Program Lead
Lead Information System Security Officer (ISSO) / Technical Program Lead

Xtreme Solutions Corporate • Washington

On-site
USD 150,000 - 190,000
Cybersecurity - Lead ISSO
Cybersecurity - Lead ISSO

Securepro Inc • Arlington (VA)

On-site
USD 120,000 - 190,000
401(k)
401(k) matching
Dental insurance
+1
Senior Information Systems Security Officer
Senior Information Systems Security Officer

Steampunk, Inc. • McLean (VA)

On-site
USD 90,000 - 140,000
Cleared On Site Mid-Level Information Systems Security Officers (ISSO) (5358)
Cleared On Site Mid-Level Information Systems Security Officers (ISSO) (5358)

SMX • United States

On-site
USD 105,000 - 177,000
Health insurance
Paid leave
Retirement
Lead Information System Security Officer (ISSO) / Technical Program Lead
Lead Information System Security Officer (ISSO) / Technical Program Lead

Xtreme Solutions Inc • Washington

On-site
USD 150,000 - 190,000
Sr. Information Systems Security Officer (ISSO)
Sr. Information Systems Security Officer (ISSO)

Power3 • Laurel (MD)

On-site
USD 120,000 - 180,000
Competitive health, dental, and vision
401k retirement contributions
Time off: holidays + PTO
+2