Senior Information Systems Security Officer

Jobtailor

Washington (District of Columbia)

On-site

USD 120,000 - 180,000

Full time

10 days ago

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Jobtailor is seeking a seasoned cybersecurity professional in Washington DC to support the security authorization lifecycle and continuous monitoring for federal-related systems. You will develop and maintain SSPs, SARs, POA&Ms, SIAs, and related artifacts in line with NIST RMF, FISMA and agency policies.

Responsibilities include coordinating Security Control Assessments, conducting security impact analyses, reviewing architecture for control validation, and collaborating with engineers and

Qualifications

  • Bachelor’s degree with 5+ years in cybersecurity or master’s with 3+ years.
  • Public trust eligibility requiring U.S. Citizenship or Green Card.
  • Hands-on in roles like Systems Administrator, Cloud/ Infra/ Network/ Security Engineer.
  • Experience supporting federal authorization activities: SSPs, POA&Ms, SIAs.
  • Knowledge of NIST RMF, NIST SP 800-53, FISMA and federal requirements.
  • Familiar with AWS, Azure, Microsoft 365, AD, VMware, Cisco, Oracle; IAM concepts.
  • Certifications such as Security+, CISSP, CISM, CCSP, CGRC preferred.
  • Experience with government compliance programs and OWASP concepts.

Responsibilities

  • Support the security authorization lifecycle and continuous monitoring.
  • Develop, review, and maintain security documentation and artifacts.
  • Coordinate and prepare systems for Security Control Assessments.
  • Conduct Security Impact Analyses for changes to tech and architecture.
  • Review architecture and evidence; validate controls and resolve discrepancies.
  • Support change management, monitoring, POA&Ms, risk, audits, remediation.
  • Coordinate with owners and governance to support policy and risk activities.
  • Develop dashboards and risk briefings; assist Lead ISSO with coordination.

Skills

Security Documentation
Risk Management Framework
Security Impact Analysis
Technical Writing
Systems Security Engineering
Identity and Access Management
Network Security
Cloud Engineering
System Hardening
Compliance Reporting

Education

Bachelor’s degree (or higher) in cybersecurity / related field
Master’s degree in cybersecurity / related field

Tools

AWS
Azure
Microsoft 365
Active Directory
VMware
Cisco
Oracle
Archer
EMASS
Xacta

Job description

  • Support the security authorization lifecycle and ongoing continuous monitoring activities for assigned systems
  • Develop, review, and maintain security documentation and authorization artifacts, including SSPs, SARs, POA&Ms, SIAs, and related documentation, in accordance with NIST SP 800-53, RMF, FISMA, and agency policies
  • Coordinate and prepare systems for Security Control Assessments, ensuring documentation and evidence are complete, accurate, and technically defensible
  • Conduct Security Impact Analyses for changes to hardware, software, cloud infrastructure, connectivity, or system architecture
  • Review system architecture, technical documentation, and supporting evidence to validate security controls, independently assess technical implementations, identify inconsistencies, and collaborate with engineers, architects, administrators, and system owners to resolve discrepancies
  • Support change management, continuous monitoring, POA&Ms management, risk acceptance, audit responses, and remediation activities to maintain ongoing authorization and compliance
  • Coordinate with system owners, engineers, architects, and governance stakeholders to support standards reviews, exception requests, policy implementation, compliance reporting, and risk management activities
  • Develop dashboards, executive risk briefings, status reports, and other stakeholder communications while supporting the Lead ISSO in operational execution and coordination activities
Requirements
  • Bachelor’s degree and 5+ years of relevant experience, or a master’s degree and 3+ years of experience, in cybersecurity, RMF, ISSO, systems security engineering, systems administration, cloud engineering, network engineering, or a related field
  • Ability to obtain and maintain a public trust requiring U.S. Citizenship or Green Card
  • Prior hands-on experience in a technical role such as Systems Administrator, Cloud Engineer, Infrastructure Engineer, Network Engineer, or Security Engineer, with the ability to evaluate technical implementations, validate controls, assess evidence, and challenge unsupported assumptions
  • Experience supporting federal authorization activities, including SSPs, POA&Ms, SIAs, continuous monitoring, and Security Control Assessments
  • Working knowledge of NIST RMF, NIST SP 800-53, FISMA, and federal cybersecurity requirements
  • Familiarity with enterprise and cloud technologies such as AWS, Azure, Microsoft 365, Entra ID, Active Directory, VMware, Cisco, Oracle, or similar platforms
  • Working knowledge of identity and access management, encryption, system hardening, network and cloud security, secure baselines, logging, and monitoring
  • Experience with GRC or security authorization tools such as Archer, eMASS, JCAM/CSAM, Xacta, or similar platforms
  • Strong analytical, technical writing, organizational, and communication skills, including demonstrated professional proficiency in written and spoken English
  • Ability to independently produce polished, technically accurate documentation; communicate clearly and effectively with technical and non-technical stakeholders; work independently; and manage competing priorities in a fast-paced environment
  • Proficiency with Microsoft Word, Excel, PowerPoint, and SharePoint
  • Preferred: Security+, CGRC, CISSP, CISM, CCSP, or similar cybersecurity certification
  • Preferred: Experience supporting federal systems, ATO processes, FedRAMP, federal privacy requirements, or other government compliance programs
  • Preferred: Knowledge of OWASP Top 10, Zero Trust, application security concepts, and MITRE ATT&CK
  • Preferred: Experience participating in incident response, security architecture reviews, technical design reviews, or security remediation efforts
  • Preferred: Experience operating in fast-paced, high-visibility environments with competing priorities
Core Competencies

Demonstrates expertise in security authorization processes, including the development and maintenance of security documentation and compliance with federal cybersecurity standards. Proficient in risk management frameworks and technical assessments, with strong communication skills to engage with diverse stakeholders.

Highest-signal resume keywords
  • Security Authorization Lifecycle
  • NIST RMF
  • Continuous Monitoring
  • Security Control Assessments
  • Cloud Security
ATS Optimization Keywords
Hard Skills
  • Security Documentation
  • Risk Management Framework
  • Security Impact Analysis
  • Technical Writing
  • Systems Security Engineering
  • Identity and Access Management
  • Network Security
  • Cloud Engineering
  • System Hardening
  • Compliance Reporting
Soft Skills
  • Analytical Skills
  • Organizational Skills
  • Communication Skills
  • Independent Work
  • Time Management
Certifications & Qualifications
  • Security+
  • CISSP
  • CISM
  • CCSP
  • CGRC
Industry Keywords
  • FISMA
  • NIST SP 800-53
  • ATO Processes
  • FedRAMP
  • OWASP Top 10
Tools & Technologies
  • AWS
  • Azure
  • Microsoft 365
  • Active Directory
  • VMware
  • Cisco
  • Oracle
  • Archer
  • EMASS
  • Xacta
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Information System Security Manager – ISSM
Information System Security Manager – ISSM

Jobtailor • Ventura (CA)

On-site
USD 110,000 - 150,000
Information Systems Security Engineer
Information Systems Security Engineer

Jobtailor • King of Prussia (PA)

On-site
USD 120,000 - 170,000
Lead Federal Auditor
Lead Federal Auditor

Jobtailor • California (MO)

On-site
USD 120,000 - 180,000
Senior Information Systems Security Engineer – ISSE
Senior Information Systems Security Engineer – ISSE

Jobtailor • Maryland

On-site
USD 140,000 - 180,000
Lead Senior Information System Security Officer
Lead Senior Information System Security Officer

Jobtailor • Washington

On-site
USD 150,000 - 190,000
Senior Information Security Analyst
Senior Information Security Analyst

Jobtailor • Maryland

On-site
USD 110,000 - 170,000
Cybersecurity Risk, Managing Consultant
Cybersecurity Risk, Managing Consultant

Jobtailor • Washington

On-site
USD 120,000 - 180,000
Information System Security Engineer
Information System Security Engineer

CACI International Inc • Leesburg (VA)

On-site
USD 120,000 - 180,000
Senior ISSO Security Analyst (AA SR)
Senior ISSO Security Analyst (AA SR)

STAFFXPERT LLC • United States

On-site
USD 120,000 - 180,000
Advisory Information Security Manager – ISSM
Advisory Information Security Manager – ISSM

Jobtailor • Huntsville (AL)

On-site
USD 110,000 - 170,000