Mid-Level Information System Security Officer (ISSO) / System Owner Support

K2Share LLC
United States
26 days ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Experienced
Experience required
4 years minimum
Working hours
Regular working hours
Job source

Tech stack

Xacta Artificial Intelligence Amazon Web Services Microsoft Azure Configuration Management Software Documentation CompTIA Security+ Cyber Security Federal Information Processing Standards (FIPS) Information Security Management Machine Learning Network Diagrams
+8 more
Package Development Process Systems Development Life Cycle Cloud Services Smartsuite Microsoft SharePoint Systems Architecture Information Security Management System Cloud Platform System

Job description

K2Share is seeking an Information System Security Officer (ISSO) to support a federal health-sector client. In this role, you will serve as a trusted security advisor to system owners, business owners, and technical teams, helping guide systems through the Risk Management Framework (RMF) and supporting their Authority to Operate (ATO) throughout the system lifecycle.

You will develop and maintain authorization documentation, continuous monitoring strategies, contingency planning, and security guidance while helping ensure client systems remain compliant with federal cybersecurity requirements. This role supports authorization package development while maintaining appropriate independence from formal Security Control Assessment (SCA) and Final Assessment Report (SAR) validation activities for the same systems., * Develop and maintain RMF authorization artifacts, including the System Security Plan (SSP), Business Impact Analysis (BIA), FIPS 199 categorization, Privacy Threshold and Privacy Impact Assessments (PTA/PIA), Configuration Management Plan (CMP), and e-Authentication documentation.

  • Create foundational system documentation, including Boundary Scope Memorandums (BSM), System Architecture diagrams, and Authorization Boundary and Network Diagrams (ABND).
  • Assist system owners with security control scoping, tailoring, inheritance, and identification of applicable overlays, including the client’s AI Overlay where applicable.
  • Apply the NIST AI Risk Management Framework (AI RMF 1.0) and relevant OMB guidance for systems incorporating Artificial Intelligence or Machine Learning capabilities.
  • Support development of Interconnection Security Agreements (ISAs), Memorandums of Understanding (MOUs), and other authorization documentation.
  • Validate technical evidence, including configuration artifacts, scan reports, and system documentation, to ensure compliance with NIST SP 800-53 Rev. 5 prior to authorization package submission.
  • Develop and maintain system-level Contingency Plans (CP), Incident Response Plans (IRP), and Continuous Monitoring (ConMon) Plans.
  • Coordinate and document annual contingency and incident response testing, including corrective actions and follow-up activities.
  • Develop and deliver annual contingency planning and incident response training for system personnel.
  • Maintain RMF templates, SDLC security artifacts, cloud assessment playbooks, process guides, and SharePoint security content, including the Educational Materials and Checklists library with annual updates.
  • Facilitate RMF training sessions, office hours, and user guidance while identifying opportunities to improve authorization processes, such as streamlined Authority to Use (ATU) pathways.
  • Serve as the primary security advisor to system owners, stakeholders, and the client Privacy Coordinator throughout the RMF and ATO lifecycle.
  • Review FedRAMP Cloud Service Provider packages, support secure cloud deployments, assist with system decommissioning, and help resolve discrepancies within enterprise GRC tools.

Requirements

You are an experienced cybersecurity professional who enjoys helping organizations successfully navigate the Risk Management Framework while balancing mission objectives and security requirements. You understand that effective RMF implementation requires more than documentation. It requires collaboration, sound technical judgment, and the ability to translate complex security requirements into practical guidance.

You are comfortable working directly with system owners, engineers, privacy professionals, and leadership to develop authorization packages, continuous monitoring strategies, and security documentation that withstands rigorous review. You communicate clearly, stay organized across multiple systems, and take ownership of helping programs achieve and maintain compliance.

You thrive in an environment where you can combine technical expertise with consulting, mentorship, and process improvement to strengthen an organization’s overall cybersecurity posture., * Bachelor’s degree in a related field, or equivalent experience as allowed by company and contract policy.

  • Four or more years of experience serving as an ISSO or supporting RMF authorization package development within a federal environment.
  • Hands-on experience developing System Security Plans (SSPs), Business Impact Analyses (BIAs), FIPS 199 categorizations, Privacy Threshold and Privacy Impact Assessments (PTA/PIA), and Configuration Management Plans.
  • Working knowledge of NIST SP 800-37 (RMF), NIST SP 800-53 Rev. 5, NIST SP 800-18, and FISMA.
  • Experience developing, maintaining, and testing system-level Contingency Plans and Incident Response Plans.
  • Strong written communication, stakeholder engagement, and technical documentation skills.
  • Ability to meet federal background investigation requirements., * Active certification such as CISSP, CGRC/CAP, CISM, or CompTIA Security+.
  • Experience using GRC and authorization platforms such as eMASS, CSAM, Xacta, or JCAM.
  • Experience supporting FedRAMP authorizations and cloud environments in AWS and/or Azure.
  • Familiarity with the NIST AI Risk Management Framework (AI RMF 1.0).
  • Prior support to federal civilian agency cybersecurity programs.

Benefits & conditions

Pulled from the full job description

  • Tuition reimbursement
  • Health insurance
  • 401(k) matching
  • Paid time off
  • Paid jury duty
  • Gym membership, We’re invested in the people who make our success possible. As a K2United employee, you’ll enjoy a comprehensive benefits package designed to support your professional and personal well-being, including:
  • 401(k) with employer matching
  • Low-cost medical coverage for employees and their families
  • Paid time off
  • Paid leave for jury duty, military service, voting, and other qualifying events
  • Wellness stipend, including fitness reimbursement
  • Tuition assistance
  • Casual work environment
  • Technical training and certification support
  • Complimentary access to CareerSafe online training courses for employees and their immediate family

About the company

K2United is an organization that houses two distinct, national, customer-facing brands tied together by a shared purpose: setting the standard for an extraordinary workplace. Through our brands, K2Share and CareerSafe, we provide advisory services in cyber risk management and online education for workforce readiness.

Our four core values define how we show up every day:

  • Respect Others - We lead with respect, building trust and connection.
  • Internally Driven - We are relentlessly compelled to accomplish our objectives.
  • Collaborative Innovation - We create by listening, sharing, and working together.
  • Client Success - We hold our clients’ mission as our own.

We believe in people who are accountable, curious, and motivated to make an impact that matters.

Our programs make a meaningful difference. CareerSafe supports more than two million users each year, while K2Share delivers cybersecurity and IT solutions that strengthen federal agencies. As part of our team, you’ll help solve complex challenges in a mission-driven, small-business environment that values professional growth, collaboration, and work-life balance.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.indeed.com

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

2:41 min

Transitioning artificial intelligence infrastructure into scalable commodity cloud services

juarezjunior juarezjunior · WWC 2024

5:03 min

Navigating new cybersecurity compliance frameworks and laws

Kurt Eder · LIVE

47 sec

Advantages of edge inference over cloud API services

Sasha Denisov Sasha Denisov · WWC Europe 2026

1:45 min

Transitioning from software development to security roles

Stefania Chaplin · WWC 2022

4:01 min

Finding personal fulfillment in the cybersecurity industry

LIVE

3:25 min

The evolution axis from genesis to commodity

Markus Harrer Markus Harrer · WWC 2023

Videos

See all

Related articles

See all