Information Systems Security Officer (ISSO)

NexGen Technologies, Inc.
United States
about 2 months ago
Apply on www.indeed.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
10 years minimum
Compensation
$135,200.0 - $156,000.0
Working hours
Regular working hours
Job source

Tech stack

Cyber Security Computer Networks Continuous Integration Dynamic Program Analysis Network Diagrams Systems Development Life Cycle Security Software Software Vulnerability Management Data Logging SARS Software Products Information Technology Devsecops
+3 more
Plan of Action and Milestones Static Application Security Testing Dynamic Application Security Testing

Job description

NexGen is seeking a detail-oriented Information Security Systems Officer (ISSO) to provide comprehensive RMF, DevSecOps-aligned cybersecurity support, and continuous monitoring activities. The role supports enterprise-wide authorization efforts by maintaining eMASS packages, monitoring RMF and Continuous Monitoring (ConMon) status, coordinating with Program and Product Owners, and ensuring alignment with federal government cybersecurity requirements. The specialist works closely with stakeholders, system owners, and federal partners to maintain accurate RMF documentation, support governance processes, integrate security into DevSecOps workflows, and ensure timely execution of cybersecurity tasks across all accreditation boundaries. Supervisory Responsibilities

  • There are no supervisory responsibilities.

Essential Duties and Responsibilities (as assigned)

  • Monitor RMF authorization status in eMASS and track required actions to obtain and sustain system/application authorization.
  • Support Continuous Monitoring (ConMon) activities, including review of security alerts, vulnerability findings, control evidence, and recurring compliance checks.
  • Advise stakeholders on cybersecurity, DevSecOps security integration, and ATO requirements; identify missing or incomplete information in eMASS.
  • Create and maintain eMASS entries, ensuring artifacts are properly associated with applicable CCI security controls.
  • Develop STIG/control crosswalks to map controls to system functionality and determine control impact.
  • Update eMASS controls and POA&Ms using supporting documentation; ensure POA&M entries remain current and submit closure/extension workflows.
  • Explain non-compliant controls and recommend remediation strategies; coordinate updates and communication.
  • Serve as liaison between Program/Product Owners and stakeholders to coordinate eMASS activities and information flow.
  • Provide subject matter expertise on RMF policy, eMASS usage, federal government cybersecurity requirements, DevSecOps security practices, and continuous monitoring expectations.
  • Identify efficiencies and apply approved templates or repeatable methods for shared requirements across applications.
  • Support Program/Product Owners during assessments, validations, and audits, including eMASS access and clarifications.
  • Organize and manage RMF meetings, including scheduling, agendas, meeting notes, and artifact storage.
  • Conduct quality assurance reviews of RMF submissions (e.g., ACAS scans, network diagrams, PPSM documentation, HW/SW lists, STIGs, POA&Ms).
  • Participate in Cyber Compliance Meetings as required.
  • Provide expertise on cATO, PPSM documentation, network traffic diagrams, RMF control remediation, and DevSecOps pipeline security considerations.
  • Conduct risk analysis of ATO packages and provide prioritized remediation recommendations; contribute to ISSO Reports with recommended ATO conditions.
  • Develop Security Assessment Plans (SAPs) and Security Assessment Reports (SARs) in collaboration with Program/Product Owners and the ISSM.
  • Support continuous monitoring dashboards, automated security tooling, and recurring vulnerability review cycles.
  • Other duties may be assigned.

Requirements

  • 10+ years of experience supporting RMF programs within civilian federal environments.
  • Hands-on experience with eMASS (package maintenance, workflows, artifact association).
  • Familiarity with POA&M management, ATO Terms and Conditions, and RMF governance processes.
  • Understanding of federal government cybersecurity requirements, NIST SP 800-53 controls, STIGs, and DHA/DHRA RMF processes.
  • Experience supporting Continuous Monitoring (ConMon) activities, including vulnerability management, recurring control assessments, log review, and automated evidence collection.
  • Knowledge of DevSecOps principles, secure SDLC, CI/CD pipeline security, and integration of automated security tooling (SAST, DAST, container/IaC scanning).
  • Ability to interpret compliance documentation, assess system boundary requirements, and evaluate risk.

Desired Skills

  • Familiarity with DHA ATC workflows and cloud-hosted system RMF requirements.
  • Experience developing process documentation, governance artifacts, or compliance KPIs.
  • Knowledge of central logging requirements and boundary-level cybersecurity controls.
  • Experience integrating security automation into DevSecOps pipelines (e.g., static/dynamic analysis, container scanning, IaC security).
  • Experience supporting continuous monitoring programs for federal systems.

Education

  • Bachelor’s degree in Cybersecurity, Information Technology, Computer Science, or related field.

Additional Requirements

  • Strong analytical, organizational, and documentation skills.
  • Ability to work collaboratively with interdisciplinary teams and federal stakeholders.
  • Must be able to pass background screening prior to employment.
  • US Citizenship, legal permanent residence, or US work authorization with a minimum of 3 years of US presence is required due to federal contract requirements.

About the company

NexGen Technologies, Inc. is a leading IT services firm specializing in delivering innovative, high-quality solutions to our federal government clients. Our core competencies include IT professional support services, software development, cloud services, IT Operations, Agile project management, and GIS services.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.indeed.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

4:01 min

Finding personal fulfillment in the cybersecurity industry

LIVE

1:15 min

Key lessons learned from implementing automated mobile DevSecOps

Moataz Nabil Moataz Nabil · LIVE

1:10 min

Exposing sensitive information through partial search logs

Dennis Schulz Dennis Schulz +1 · World Congress 2026 Europe

4:11 min

Introduction to cloud-native application developer security

Micah Silverman · World Congress 2022

1:45 min

Transitioning from software development to security roles

Stefania Chaplin · World Congress 2022

2:09 min

Shifting security left using the DevSecOps approach

Aarno Aukia · LIVE

Videos

See all

Related articles

See all