Information System Security Officer
- Discuss this with your agent
- Open in Claude
- Open in ChatGPT
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Role details
Tech stack
Job description
We are seeking a Junior Information System Security Officer (ISSO) to join our team. In this role, you will support Senior ISSOs with Risk Management Framework (RMF) compliance and system security. You will be responsible for maintaining security documentation, supporting Authority to Operate (ATO) efforts, and conducting risk and vulnerability assessments to ensure federal systems remain compliant and secure., * Execute Risk Management Framework (RMF) activities to support ATO packages and authorization decisions.
- Implement and assess security controls in accordance with NIST, FISMA, and DHS requirements.
- Develop, update, and maintain cybersecurity documentation, including System Security Plans (SSPs), Contingency Plans (CPs), Configuration Management Plans (CMPs), and Plans of Action & Milestones (POA&Ms).
- Support continuous monitoring activities, conduct system assessments, and manage vulnerability remediation efforts.
- Perform Security Impact Analyses (SIAs) for system changes and deployments.
- Assist with cloud security and compliance initiatives.
- Provide documentation for audits and respond to cybersecurity data calls.
- Analyze Risk Assessment Reports and FISMA scorecard metrics.
Requirements
- Must be able to obtain and maintain a DHS/FEMA EOD.
- Bachelor’s degree and 5+ years of relevant experience, or an equivalent combination of education and experience (Associate’s & 7 years, Master’s & 3 years, or 11 years without a degree).
- Experience with Risk Management Framework (RMF), FISMA compliance, NIST SP 800-37, and NIST SP 800-53.
- Experience creating and maintaining SSPs, POA&Ms, and Contingency Plans.
- Knowledge of DHS 4300 Series requirements.
- Experience with continuous monitoring and vulnerability management.
Preferred Qualifications
- Previous experience with DHS or a similar federal agency.
- Experience with GRC tools such as CSAM, RegScale, or eMASS.
- Awareness of cloud security concepts (AWS, Azure) and FedRAMP.
- Relevant security certifications such as CompTIA Security+, CISA, or CISSP.
- Technical writing and communication skills.
About the company
Everforth Apex is a world-class IT services company that serves thousands of clients across the globe. When you join Everforth Apex, you become part of a team that values innovation, collaboration, and continuous learning. We offer quality career resources, training, certifications, development opportunities, and a comprehensive benefits package. Our commitment to excellence is reflected in many awards, including ClearlyRateds Best of Staffing in Talent Satisfaction in the United States and Great Place to Work in the United Kingdom and Mexico.
Everforth Apex uses a virtual recruiter as part of the application process. Click for more details. By applying for this job, you agree to receive calls, AI-generated calls, text messages, or emails from Everforth Apex and its affiliates, and contracted partners. Frequency varies for text messages. Message and data rates may apply. Carriers are not liable for delayed or undelivered messages. You can reply STOP to cancel and HELP for help. You can access our privacy policy at
Apply for this position
This job is hosted externally. Click below to view the full posting and apply.
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Good distractions
Talks and stories from around this role — technically off-topic, practically not.
Moments
Explore playlistsVideos
See allRelated articles
See all
What Are The Top Skills Required For Azure Developers?
Best Paying Jobs in Technology
Dev Digest 134 - Where pixels sing?
How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again