> Markdown version of [/jobs/ext/2505777-junior-information-system-security-officer-fedramp-20x-automation-focused](https://www.wearedevelopers.com/jobs/ext/2505777-junior-information-system-security-officer-fedramp-20x-automation-focused). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Junior Information System Security Officer (FedRAMP 20x / Automation Focused) - **Company:** Aderas, Inc - **Location:** Washington, DC, United States - **Experience:** Starter - **Contract:** Permanent contract - **Skills:** Amazon Web Services, Microsoft Azure, CompTIA Security+, Cyber Security, Document Management Systems, Information Security Management, JSON, Smartsuite, SAP (Applications), Microsoft SharePoint, YAML, Information Technology, Plan of Action and Milestones - **Published:** August 9, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=418c834e939904a3 ## About the Role * JCAM & GRC Tools: Entry-level experience to Governance, Risk, and Compliance platforms like JCAM, CSAM, or eMASS to update control data and pull security reports. * SharePoint Document Control: Experience using Microsoft SharePoint for organizing the Body of Evidence (BoE), managing access control for sensitive compliance artifacts, and tracking document workflows. * FedRAMP 20x Automation: Basic understanding of machine-readable compliance architecture (OSCAL JSON/YAML formats) and utilizing automated continuous tracking methods. * Vulnerability & Log Management: Experience gathering outputs from cloud security posture management (CSPM) utilities and continuous validation scanning infrastructure. Certifications, Preferred (one or more): * CompTIA Security+ (strongly preferred) * (ISC)² SSCP or ISC2 Certified in Cybersecurity (CC) * AWS/Azure/GCP foundational cert (e.g., AWS Cloud Practitioner / Azure Fundamentals) * CAP (ISC2), CRISC, or vendor security specialty certs * NIST RMF training/certifications Required Degrees & Experience * Bachelor's Degree in Cybersecurity, Computer Science, Information Technology, or equivalent technical training. * 1-3 years of experience in IT compliance, federal auditing, or cybersecurity operations. Security Requirement * Active DoD Secret clearance ## Description Aderas is looking for a Junior Information Systems Security Officer to assist in managing system security packages, tracking vulnerabilities, maintaining continuous monitoring data, and utilizing government GRC tools to support FedRAMP 20x automated validation., * Maintain and update FedRAMP security package components (SSP, SAP/SAR support, POA&M, control evidence). * Support implementation and documentation of NIST SP 800-53 controls and NIST RMF (800-37) activities. * Assist with continuous monitoring (ConMon): monthly/quarterly evidence collection, vulnerability status reporting, patch compliance, configuration baselines. * Participate in change management and security impact analysis for system changes. * Track and remediate findings; support POA&M creation, updates, milestones, and risk narratives. * Support incident response documentation and coordination (per policy). * Prepare for and support 3PAO testing and customer/government reviews. * Help improve evidence workflows (e.g., templates, checklists, and basic automation). ## Related Videos - [CI/CD with Github Actions](https://www.wearedevelopers.com/videos/856-ci-cd-with-github-actions) - [Tips and Tricks for Working with JSON](https://www.wearedevelopers.com/videos/1229-tips-and-tricks-for-working-with-json) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Docker Compose: Rediscovered](https://www.wearedevelopers.com/videos/1978-docker-compose-rediscovered) - [Introducing JSON Structure](https://www.wearedevelopers.com/videos/100219-introducing-json-structure) - [Reporting Active Exploits in 24 Hours: Are You Ready for the CRA?](https://www.wearedevelopers.com/videos/100248-reporting-active-exploits-in-24-hours-are-you-ready-for-the-cra) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [The Overflow: Security and Privacy](https://www.wearedevelopers.com/magazine/715-the-overflow-security-and-privacy) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities)