> Markdown version of [/jobs/ext/1495216-junior-information-system-security-officer-remote](https://www.wearedevelopers.com/jobs/ext/1495216-junior-information-system-security-officer-remote). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Junior Information System Security Officer (REMOTE) - **Company:** DRAGONFLI GROUP LLC - **Location:** United States (Remote available) - **Experience:** Starter - **Contract:** Permanent contract - **Skills:** Xacta, CompTIA Security+, Cyber Security, Information Systems, Identity and Access Management, Information Security Management, Microsoft Office, Microsoft SharePoint, SARS Software Products, Vulnerability Analysis - **Published:** July 30, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=ce0c601cb4edf10f ## About the Role Dragonfli is looking for a Junior Information System Security Officer (ISSO) to join a federal cybersecurity team supporting a large-scale system authorization and continuous monitoring program under the NIST Risk Management Framework (RMF). This is an entry-level opportunity for candidates who bring a strong foundation in IT, security, or a related military background but may not yet have direct ISSO experience. You'll work alongside senior ISSOs and security engineers to help maintain System Security Plans (SSPs), track Plans of Action and Milestones (POA&Ms), and support the day-to-day activities that keep federal systems authorized to operate. Candidates with 0-2 years of relevant experience, including recent certification holders and veterans transitioning into cybersecurity, are strongly encouraged to apply. Candidates with any previous federal contracting experience are preferred. U.S. Citizenship or Permanent Residency is required. If hired, all work related to this role must be performed within the continental U.S., Must-Have * 0-2 years of experience in IT, cybersecurity, information assurance, or a related military/government role (direct ISSO experience is not required) * Working knowledge of the NIST Risk Management Framework (RMF) and NIST SP 800-53 security controls, gained through training, coursework, or certification study * U.S. Citizenship required; must be able to pass a background investigation for a Public Trust position * Ability to work remotely and collaborate during core business hours (9am-5pm ET) * Strong written communication skills Preferred / Nice-to-Have * Background in IT, communications, electronics, or a security-adjacent role * Exposure to GRC/compliance tools such as eMASS or Xacta * Bachelor's degree in IT, cybersecurity, or a related field (or equivalent experience) * Prior experience in identity and access management (IAM), credentialing, or access control * Familiarity with FISMA and OMB A-130 requirements * Active CompTIA Security+ or (ISC)² Certified in Cybersecurity (CC) certification Skill(s): Technical Skills * RMF fundamentals and the ATO lifecycle * NIST 800-53 control families (foundational awareness) * Identity and access management / access control concepts * Exposure to GRC or vulnerability scanning tools (e.g., ACAS, STIGs) a plus * Documentation and technical writing (SSPs, POA&Ms) * MS Office / SharePoint Soft Skills * Clear, professional written and verbal communication * Attention to detail and follow-through * Ability to learn quickly and take direction from senior team members * Collaboration across distributed, remote teams * Discretion and trustworthiness handling sensitive information * Self-motivation in a remote work environment ## Description * Support RMF lifecycle activities for assigned federal information systems, including categorization, control implementation, assessment, and continuous monitoring, under the guidance of senior team members * Assist in developing and updating system security documentation, including SSPs, Security Assessment Reports (SARs), and POA&Ms * Help track and document security control deviations and vulnerabilities through to closure * Support continuous monitoring activities, including log review and vulnerability scan analysis, alongside senior ISSOs * Assist in maintaining system inventory, hardware/software baselines, and interconnection agreements * Support incident response documentation, escalation tracking, and remediation follow-up * Participate in security reviews, audits, and inspections as part of the broader team * Coordinate with Information System Owners (ISOs) and other stakeholders on routine compliance tasks * Build working knowledge of federal directives including FISMA and OMB A-130 through applied, on-the-job training ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [One Pipeline, Three Regulator - SBOM Compliance for the Developer](https://www.wearedevelopers.com/videos/100169-one-pipeline-three-regulator-sbom-compliance-for-the-developer) - [Cyber Security: Small, and Large!](https://www.wearedevelopers.com/videos/259-cyber-security-small-and-large) - [DevSecOps culture](https://www.wearedevelopers.com/videos/783-devsecops-culture) - [Less Is More: How Lagom and Agile Can Create Harmonious Workflows](https://www.wearedevelopers.com/videos/1993-less-is-more-how-lagom-and-agile-can-create-harmonious-workflows) ## Related Articles - [Fully Remote Software Engineer Jobs](https://www.wearedevelopers.com/magazine/447-fully-remote-software-engineer-jobs) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [The Overflow: Security and Privacy](https://www.wearedevelopers.com/magazine/715-the-overflow-security-and-privacy) - [Is Software Engineering Over-Saturated?](https://www.wearedevelopers.com/magazine/418-is-software-engineering-over-saturated) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking)