Information System Security Officer (ISSO)

Illumination Works
United States
6 days ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
5 years minimum
Working hours
Regular working hours

Tech stack

Application Programming Interfaces (APIs) Amazon Web Services Microsoft Azure Cloud Computing Security Cyber Security Information Security Management Systems Architecture Systems Integration Software Vulnerability Management SC Clearance Information Technology Api Design
+1 more
Plan of Action and Milestones

Job description

We are seeking an experienced Information System Security Officer (ISSO) to support implementing and maintaining the cybersecurity posture of mission-critical finance-related systems. This role is responsible for supporting Risk Management Framework (RMF) compliance, Authority to Operate (ATO) activities, continuous monitoring, cybersecurity audit readiness, and security compliance across enterprise data environments. The successful candidate will work closely with cybersecurity, engineering, system architecture, and Government stakeholders to implement and maintain security controls in a cloud environment while supporting recurring FISCAM, NIST, RMF, and financial management security compliance activities., * Support implementation and enforcement of cybersecurity policies and controls in accordance with DoD RMF, NIST 800-53, and Air Force guidance

  • Support security compliance activities for enterprise financial data and system integrations via implementing and maintaining RMF Financial Management (FM) Overlay security controls
  • Support ATO lifecycle activities, including control implementation, validation, and continuous monitoring
  • Develop, maintain, and update RMF documentation, including System Security Plans (SSPs), POA&Ms, security control implementation evidence, assessment artifacts, and other ATO and FISCAM audit readiness documentation
  • Support recurring Government cybersecurity and financial audits by preparing documentation, responding to auditor requests, and participating in technical walkthroughs
  • Evaluate and validate security controls for systems, applications, and integrations, including cloud and API-based architectures
  • Support incident response activities, including detection, reporting, and coordination with cybersecurity teams
  • Track, document, and support remediation of security findings through Corrective Action Plans (CAPs)
  • Provide support to the Information System Security Manager (ISSM) for maintaining the appropriate operational IA posture for a system/program/enclave

Do you have what it takes? Are you driven to implement creative solutions that unravel complex and ever-changing challenges? We value passion, curiosity, and perseverance with an ability to communicate ideas and results to diverse audiences. We look for people who thrive in collaborative and independent assignments, have the aptitude to learn new data quickly, and who are willing to mentor junior team members.

Requirements

  • Must hold active Secret Clearance
  • Experience with DoD RMF processes, especially for FM systems, including preparing for FISCAM audits, FM control implementation, POA&M management, and ATO support
  • Experience supporting FISCAM, FIAR, or other Federal audit activities
  • Knowledge of NIST 800-53 security controls and continuous monitoring practices
  • Experience performing security assessments and validating system compliance
  • Familiarity with vulnerability management tools (e.g., ACAS, Tenable, or similar)
  • Experience using eMASS to manage RMF packages and security documentation
  • Understanding of cloud security principles (AWS/Azure, GovCloud, or similar environments)
  • Experience proposing, coordinating, implementing, and enforcing information systems security policies, standards, and methodologies, preferably on a large software or IT program
  • Experience securing enterprise data integrations, APIs, or system interfaces
  • Strong documentation skills, particularly for RMF artifacts (e.g., SSP) and compliance reporting
  • Strong analytical, problem-solving, and organizational skills
  • Ability to work collaboratively across engineering, architecture, and cybersecurity teams
  • Must have excellent interpersonal skills
  • Security+ certification required (or higher DoD 8570/8140 equivalent)
  • 5+ years of experience in information system security, cybersecurity, or related roles
  • Bachelor’s degree in Computer Science, Cybersecurity, or comparable academic discipline
  • Ability to pass required background screening and drug testing

Benefits & conditions

Why choose us? We invest in our employees in all aspects of their life and we value family. We offer market-competitive salary, a generous PTO package, and comprehensive medical, dental, vision and life insurance plans. We also offer 401K, short/long-term disability insurance, a fun and engaging culture, and training opportunities to keep you up to speed on the latest technologies.

About the company

At Illumination Works, we know data, and we should, we’ve been doing it since we started in 2006! We specialize in everything data from big data to data science, data engineering, software engineering, and cloud design. We are a trusted technology partner in user-centered digital transformation-delivering impactful business results to clients. We partner with customers to solve their unique technology and data challenges and stay on top of modern technologies and advancements leveraging our Innovation Lab. Check out our website to learn more at www.ilwllc.com .

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.clearancejobs.com

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

4:11 min

Introduction to cloud-native application developer security

Micah Silverman · WWC 2022

3:10 min

Understanding the core concepts of API design

Alen Pokos · LIVE

5:03 min

Navigating new cybersecurity compliance frameworks and laws

Kurt Eder · LIVE

3:44 min

Current industry adoption and future security initiatives

Alexander Allmendinger · LIVE

3:26 min

Prioritizing backward compatibility in API design

Justin Kitagawa · Coffee With Developers

3:22 min

Transitioning from software engineering to security roles

Anna Oliveira · Coffee With Developers

Videos

See all

Related articles

See all