Information Systems Security Officer (ISSO)
- Discuss this with your agent
- Open in Claude
- Open in ChatGPT
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Role details
Tech stack
+3 more
Job description
NexGen is seeking a detail-oriented Information Security Systems Officer (ISSO) to provide comprehensive RMF, DevSecOps-aligned cybersecurity support, and continuous monitoring activities. The role supports enterprise-wide authorization efforts by maintaining eMASS packages, monitoring RMF and Continuous Monitoring (ConMon) status, coordinating with Program and Product Owners, and ensuring alignment with federal government cybersecurity requirements. The specialist works closely with stakeholders, system owners, and federal partners to maintain accurate RMF documentation, support governance processes, integrate security into DevSecOps workflows, and ensure timely execution of cybersecurity tasks across all accreditation boundaries. Supervisory Responsibilities
- There are no supervisory responsibilities.
Essential Duties and Responsibilities (as assigned)
- Monitor RMF authorization status in eMASS and track required actions to obtain and sustain system/application authorization.
- Support Continuous Monitoring (ConMon) activities, including review of security alerts, vulnerability findings, control evidence, and recurring compliance checks.
- Advise stakeholders on cybersecurity, DevSecOps security integration, and ATO requirements; identify missing or incomplete information in eMASS.
- Create and maintain eMASS entries, ensuring artifacts are properly associated with applicable CCI security controls.
- Develop STIG/control crosswalks to map controls to system functionality and determine control impact.
- Update eMASS controls and POA&Ms using supporting documentation; ensure POA&M entries remain current and submit closure/extension workflows.
- Explain non-compliant controls and recommend remediation strategies; coordinate updates and communication.
- Serve as liaison between Program/Product Owners and stakeholders to coordinate eMASS activities and information flow.
- Provide subject matter expertise on RMF policy, eMASS usage, federal government cybersecurity requirements, DevSecOps security practices, and continuous monitoring expectations.
- Identify efficiencies and apply approved templates or repeatable methods for shared requirements across applications.
- Support Program/Product Owners during assessments, validations, and audits, including eMASS access and clarifications.
- Organize and manage RMF meetings, including scheduling, agendas, meeting notes, and artifact storage.
- Conduct quality assurance reviews of RMF submissions (e.g., ACAS scans, network diagrams, PPSM documentation, HW/SW lists, STIGs, POA&Ms).
- Participate in Cyber Compliance Meetings as required.
- Provide expertise on cATO, PPSM documentation, network traffic diagrams, RMF control remediation, and DevSecOps pipeline security considerations.
- Conduct risk analysis of ATO packages and provide prioritized remediation recommendations; contribute to ISSO Reports with recommended ATO conditions.
- Develop Security Assessment Plans (SAPs) and Security Assessment Reports (SARs) in collaboration with Program/Product Owners and the ISSM.
- Support continuous monitoring dashboards, automated security tooling, and recurring vulnerability review cycles.
- Other duties may be assigned.
Requirements
- 10+ years of experience supporting RMF programs within civilian federal environments.
- Hands-on experience with eMASS (package maintenance, workflows, artifact association).
- Familiarity with POA&M management, ATO Terms and Conditions, and RMF governance processes.
- Understanding of federal government cybersecurity requirements, NIST SP 800-53 controls, STIGs, and DHA/DHRA RMF processes.
- Experience supporting Continuous Monitoring (ConMon) activities, including vulnerability management, recurring control assessments, log review, and automated evidence collection.
- Knowledge of DevSecOps principles, secure SDLC, CI/CD pipeline security, and integration of automated security tooling (SAST, DAST, container/IaC scanning).
- Ability to interpret compliance documentation, assess system boundary requirements, and evaluate risk.
Desired Skills
- Familiarity with DHA ATC workflows and cloud-hosted system RMF requirements.
- Experience developing process documentation, governance artifacts, or compliance KPIs.
- Knowledge of central logging requirements and boundary-level cybersecurity controls.
- Experience integrating security automation into DevSecOps pipelines (e.g., static/dynamic analysis, container scanning, IaC security).
- Experience supporting continuous monitoring programs for federal systems.
Education
- Bachelor’s degree in Cybersecurity, Information Technology, Computer Science, or related field.
Additional Requirements
- Strong analytical, organizational, and documentation skills.
- Ability to work collaboratively with interdisciplinary teams and federal stakeholders.
- Must be able to pass background screening prior to employment.
- US Citizenship, legal permanent residence, or US work authorization with a minimum of 3 years of US presence is required due to federal contract requirements.
About the company
NexGen Technologies, Inc. is a leading IT services firm specializing in delivering innovative, high-quality solutions to our federal government clients. Our core competencies include IT professional support services, software development, cloud services, IT Operations, Agile project management, and GIS services.
Apply for this position
This job is hosted externally. Click below to view the full posting and apply.
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Good distractions
Talks and stories from around this role — technically off-topic, practically not.
Moments
Explore playlistsVideos
See allRelated articles
See all
How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again
Is Software Engineering Over-Saturated?
The Overflow: Security and Privacy
Dev Digest 134 - Where pixels sing?