> Markdown version of [/jobs/ext/230843-contingent-senior-information-security-analyst-isso](https://www.wearedevelopers.com/jobs/ext/230843-contingent-senior-information-security-analyst-isso). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # [Contingent] Senior Information Security Analyst (ISSO) - **Company:** phia, LLC - **Location:** Fairfax, VA, United States - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** Configuration Management, Cyber Security, Information Systems, Package Management Systems, Information Technology - **Published:** May 15, 2026 - **Apply:** https://jobs.localjobnetwork.com/job/detail/87174367/Contingent-Senior-Information-Security-Analyst-ISSO ## About the Role * Prior ISSO experience supporting federal agency IT systems * Experience using federal authorization management platforms (e.g., JCAM) for package management and status tracking * Experience coordinating SORN submissions and PIA reviews with agency privacy officials * Experience supporting both on-premises and FedRAMP cloud system authorization packages * Familiarity with NIST SP 800-88 Rev. 1 media sanitization procedures * Experience with configuration management and change control processes in a federal environment REQUIRED EDUCATION + EXPERIENCE Education: Bachelor's degree in Cybersecurity, Information Technology, Computer Science, or related field Experience: 7+ years of cybersecurity expertise; 6+ years developing, maintaining, and assessing SA&A packages resulting in ATO for federal information systems Certifications: Minimum one (1) of the following: CISA (ISACA), CRISC (ISACA), CISSP (ISC2), CGRC (ISC2) Clearance: Public Trust / Suitability clearance required GENERAL PROGRAM REQUIREMENTS Citizenship: Must be a U.S. Citizen. No exception. Work Hours: Full-time; Monday-Friday core hours 0730-1600 EST Work Location: Hybrid - Washington, DC Metro Area; on-site presence required. Classified work must be performed at a government-designated facility on government-provided equipment. Travel: Occasional travel may be required in support of this program. ## Description DISCLAIMER: This position is in support of a current government proposal. Employment is contingent upon contract award to phia, LLC., phia is seeking an experienced Senior Information Security Analyst (ISSO) to provide dedicated ISSO support for a federal client's information systems. This role is responsible for developing, maintaining, and assessing Security Assessment & Authorization (SA&A) packages and supporting the ongoing security and compliance posture of federal IT systems. You will serve as the primary ISSO for assigned federal information systems, managing the full SA&A documentation lifecycle, coordinating with system owners to maintain continuous compliance, and ensuring security artifacts accurately reflect the current state of each system you support. WHAT YOU'LL DO * Serve as the primary ISSO for assigned federal information systems, maintaining comprehensive knowledge of each system's security posture, authorization boundary, and control implementation status. * Develop, maintain, and assess Security Assessment & Authorization (SA&A) packages leading to Authority to Operate (ATO): SSPP, SAR, POA&M, IRP, CP, CMP, IPA, PIA, MOU, ISA, and authorization documentation. * Coordinate with system owners and operations and maintenance (O&M) staff to ensure ongoing compliance with applicable federal security requirements and standards. * Support continuous monitoring activities: track control assessment schedules, review and update authorization packages based on system and environment changes, and report security posture to the Authorizing Official. * Develop and maintain Incident Response Plans and Procedures; coordinate with the client security operations center when security incidents are identified. * Prepare and maintain Contingency Plans (CP) and Configuration Management Plans (CMP) per applicable NIST standards. * Coordinate privacy documentation with records management and privacy officials: IPA, PIA, and SORN for systems processing PII. * Develop and track Plans of Action and Milestones (POA&M) for all identified security and privacy control weaknesses; ensure POA&Ms are accurate and do not improperly defer legally required controls. * Support annual FISMA and FISCAM audit activities: gather evidence, respond to auditor requests, and coordinate corrective actions. * Provide regular security posture status reporting on assigned systems. WHO YOU ARE * ISSO: You have served as an ISSO in practice: you own your systems' security posture, understand their boundaries, and keep their SA&A packages current. * Documentation Expert: You produce SSPP, SAR, POA&M, IRP, CP, and CMP documentation that is accurate, complete, and government-ready without extensive rework. * Privacy-Aware: You recognize when a system triggers PII documentation requirements and know how to coordinate IPA and PIA processes with privacy officials. * Continuous Monitoring Practitioner: You understand federal ISCM strategies and can implement system-level monitoring plans that supplement agency requirements. * Organized: You manage multiple systems simultaneously, tracking authorization status, POA&M items, and upcoming assessment milestones across your portfolio. * Federal-Fluent: You have worked within a federal environment and understand FISMA, the Privacy Act, OMB A-130, and the practical realities of the government authorization process. ## Related Videos - [One Pipeline, Three Regulator - SBOM Compliance for the Developer](https://www.wearedevelopers.com/videos/100169-one-pipeline-three-regulator-sbom-compliance-for-the-developer) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [Microservices? Monoliths? An Annoying Discussion!](https://www.wearedevelopers.com/videos/970-microservices-monoliths-an-annoying-discussion) - [Enabling intelligent logistics automation: home-grown Industrial IoT platform at Austrian Post](https://www.wearedevelopers.com/videos/2018-enabling-intelligent-logistics-automation-home-grown-industrial-iot-platform-at-austrian-post) - [Demystifying Crypto & Web3: A Technical Journey Through 15 Years of Innovation](https://www.wearedevelopers.com/videos/1516-demystifying-crypto-web3-a-technical-journey-through-15-years-of-innovation) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [The Overflow: Security and Privacy](https://www.wearedevelopers.com/magazine/715-the-overflow-security-and-privacy) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Dev Digest 216: CyberSec + Mythos, Stack Overflow for Agents & DOOM in TTF](https://www.wearedevelopers.com/magazine/728-dev-digest-216-cybersec-mythos-stack-overflow-for-agents-doom-in-ttf) - [Is Software Engineering Over-Saturated?](https://www.wearedevelopers.com/magazine/418-is-software-engineering-over-saturated)