IT Security Specialist IV - ISSO

GAMA-1 Technologies
Washington, DC, United States
3 months ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
7 years minimum
Working hours
Regular working hours
Job source

Tech stack

Cyber Security Information Systems Information Technology

Job description

The IT Security Specialist IV - ISSO ensures systems remain secure, compliant, and mission-ready throughout their lifecycle by leading the development, execution, and maintenance of comprehensive Security Assessment and Authorization (SA&A) packages in a remote and on-site work environment. This role directly supports mission success by proactively managing cybersecurity risk, sustaining Authorization to Operate (ATO) status, and ensuring continuous alignment with federal security requirements.

What You Will Do in This Role

  • Lead development, execution, and maintenance of SA&A packages across the system lifecycle
  • Manage system security documentation to ensure accuracy, completeness, and audit readiness
  • Oversee security control implementation, assessment coordination, and validation activities
  • Support continuous monitoring activities in alignment with federal requirements and organizational policy
  • Coordinate with system owners, engineers, auditors, and external assessors throughout SA&A and ATO processes
  • Maintain and manage Plan of Action and Milestones (POA&M), including tracking, prioritization, and remediation oversight
  • Guide stakeholders through SA&A and ATO processes, ensuring compliance, risk visibility, and timely authorization sustainment
  • Ensure systems remain in a continuous state of compliance and maintain an active ATO status

Requirements

Do you have experience in Security risk assessment investigation?, Do you have a Bachelor’s degree?, * Bachelor’s degree in cybersecurity, information systems, computer science, or a related field

  • 7+ years of overall cybersecurity or information assurance experience
  • 7+ years of experience supporting RMF, ATO, SA&A, or related cybersecurity authorization activities within federal or regulated environments
  • Hands-on experience developing, managing, and maintaining SA&A packages in federal environments
  • Deep expertise in cybersecurity operations and strong knowledge of the ATO lifecycle
  • Strong understanding of continuous monitoring and federal cybersecurity compliance requirements
  • Demonstrated ability to manage cybersecurity risk across technical and non-technical stakeholders
  • Certifications such as CISA, CRISC, CISSP, or CGRC are required
  • Strong written and verbal communication skills with the ability to clearly articulate cybersecurity risk and compliance posture

Benefits & conditions

Pulled from the full job description

  • 401(k)
  • Health insurance
  • Paid time off
  • Disability insurance
  • Paid holidays
  • Opportunities for advancement

About the company

GAMA-1 is a rapidly growing technology business that is based in Greenbelt, Maryland. GAMA-1 Technologies provides strategic information assurance, information security, and business enterprise and networking solutions to the Federal Government. Our success is based on using industry and agency standards, establishing and performing with standardized processes, and IT Services expertise. At GAMA-1, we believe employees should grow, achieve, and develop just as the company grows, achieves, and develops. GAMA-1 is committed to providing our employees with opportunities for career advancement throughout their employment. For more information, visit www.gama1tech.com.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on indeed.com

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

59 sec

Proving regulatory compliance to auditors and chief officers

Mike Bursell Mike Bursell · WWC Europe 2026

5:03 min

Navigating new cybersecurity compliance frameworks and laws

Kurt Eder · LIVE

42 sec

Energy forecasts and resource demands of information technology

Marjolein Pordon · LIVE

4:11 min

Introduction to cloud-native application developer security

Micah Silverman · WWC 2022

1:45 min

Transitioning from software development to security roles

Stefania Chaplin · WWC 2022

2:46 min

Missing equipment retrieval processes for departing employees

Jasmin Azemović Jasmin Azemović · WWC Europe 2026

Videos

See all

Related articles

See all