> Markdown version of [/jobs/ext/1316829-mid-level-information-system-security-officer-isso-system-owner-support](https://www.wearedevelopers.com/jobs/ext/1316829-mid-level-information-system-security-officer-isso-system-owner-support). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Mid-Level Information System Security Officer (ISSO) / System Owner Support - **Company:** K2Share LLC - **Location:** United States - **Experience:** Experienced - **Contract:** Permanent contract - **Skills:** Xacta, Artificial Intelligence, Amazon Web Services, Microsoft Azure, Configuration Management, Software Documentation, CompTIA Security+, Cyber Security, Federal Information Processing Standards (FIPS), Information Security Management, Machine Learning, Network Diagrams, Package Development Process, Systems Development Life Cycle, Cloud Services, Smartsuite, Microsoft SharePoint, Systems Architecture, Information Security Management System, Cloud Platform System - **Published:** July 17, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=15dcce8973305689 ## About the Role You are an experienced cybersecurity professional who enjoys helping organizations successfully navigate the Risk Management Framework while balancing mission objectives and security requirements. You understand that effective RMF implementation requires more than documentation. It requires collaboration, sound technical judgment, and the ability to translate complex security requirements into practical guidance. You are comfortable working directly with system owners, engineers, privacy professionals, and leadership to develop authorization packages, continuous monitoring strategies, and security documentation that withstands rigorous review. You communicate clearly, stay organized across multiple systems, and take ownership of helping programs achieve and maintain compliance. You thrive in an environment where you can combine technical expertise with consulting, mentorship, and process improvement to strengthen an organization's overall cybersecurity posture., * Bachelor's degree in a related field, or equivalent experience as allowed by company and contract policy. * Four or more years of experience serving as an ISSO or supporting RMF authorization package development within a federal environment. * Hands-on experience developing System Security Plans (SSPs), Business Impact Analyses (BIAs), FIPS 199 categorizations, Privacy Threshold and Privacy Impact Assessments (PTA/PIA), and Configuration Management Plans. * Working knowledge of NIST SP 800-37 (RMF), NIST SP 800-53 Rev. 5, NIST SP 800-18, and FISMA. * Experience developing, maintaining, and testing system-level Contingency Plans and Incident Response Plans. * Strong written communication, stakeholder engagement, and technical documentation skills. * Ability to meet federal background investigation requirements., * Active certification such as CISSP, CGRC/CAP, CISM, or CompTIA Security+. * Experience using GRC and authorization platforms such as eMASS, CSAM, Xacta, or JCAM. * Experience supporting FedRAMP authorizations and cloud environments in AWS and/or Azure. * Familiarity with the NIST AI Risk Management Framework (AI RMF 1.0). * Prior support to federal civilian agency cybersecurity programs. ## Description K2Share is seeking an Information System Security Officer (ISSO) to support a federal health-sector client. In this role, you will serve as a trusted security advisor to system owners, business owners, and technical teams, helping guide systems through the Risk Management Framework (RMF) and supporting their Authority to Operate (ATO) throughout the system lifecycle. You will develop and maintain authorization documentation, continuous monitoring strategies, contingency planning, and security guidance while helping ensure client systems remain compliant with federal cybersecurity requirements. This role supports authorization package development while maintaining appropriate independence from formal Security Control Assessment (SCA) and Final Assessment Report (SAR) validation activities for the same systems., * Develop and maintain RMF authorization artifacts, including the System Security Plan (SSP), Business Impact Analysis (BIA), FIPS 199 categorization, Privacy Threshold and Privacy Impact Assessments (PTA/PIA), Configuration Management Plan (CMP), and e-Authentication documentation. * Create foundational system documentation, including Boundary Scope Memorandums (BSM), System Architecture diagrams, and Authorization Boundary and Network Diagrams (ABND). * Assist system owners with security control scoping, tailoring, inheritance, and identification of applicable overlays, including the client's AI Overlay where applicable. * Apply the NIST AI Risk Management Framework (AI RMF 1.0) and relevant OMB guidance for systems incorporating Artificial Intelligence or Machine Learning capabilities. * Support development of Interconnection Security Agreements (ISAs), Memorandums of Understanding (MOUs), and other authorization documentation. * Validate technical evidence, including configuration artifacts, scan reports, and system documentation, to ensure compliance with NIST SP 800-53 Rev. 5 prior to authorization package submission. * Develop and maintain system-level Contingency Plans (CP), Incident Response Plans (IRP), and Continuous Monitoring (ConMon) Plans. * Coordinate and document annual contingency and incident response testing, including corrective actions and follow-up activities. * Develop and deliver annual contingency planning and incident response training for system personnel. * Maintain RMF templates, SDLC security artifacts, cloud assessment playbooks, process guides, and SharePoint security content, including the Educational Materials and Checklists library with annual updates. * Facilitate RMF training sessions, office hours, and user guidance while identifying opportunities to improve authorization processes, such as streamlined Authority to Use (ATU) pathways. * Serve as the primary security advisor to system owners, stakeholders, and the client Privacy Coordinator throughout the RMF and ATO lifecycle. * Review FedRAMP Cloud Service Provider packages, support secure cloud deployments, assist with system decommissioning, and help resolve discrepancies within enterprise GRC tools. ## Related Videos - [Leverage Cloud Computing Benefits with Serverless Multi-Cloud ML ](https://www.wearedevelopers.com/videos/78-leverage-cloud-computing-benefits-with-serverless-multi-cloud-ml) - [One Pipeline, Three Regulator - SBOM Compliance for the Developer](https://www.wearedevelopers.com/videos/100169-one-pipeline-three-regulator-sbom-compliance-for-the-developer) - [ZEISS & Microsoft - Building the Next Generation Medical Ecosystem in the Cloud](https://www.wearedevelopers.com/videos/424-zeiss-microsoft-building-the-next-generation-medical-ecosystem-in-the-cloud) - [Organizational Change Through The Power Of Why - DevSecOps Enablement](https://www.wearedevelopers.com/videos/478-organizational-change-through-the-power-of-why-devsecops-enablement) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Cloud-nativeApplications- What’s the buzz about](https://www.wearedevelopers.com/videos/55-cloud-nativeapplications-what-s-the-buzz-about) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [The Overflow: Security and Privacy](https://www.wearedevelopers.com/magazine/715-the-overflow-security-and-privacy) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities)