senior-level Information System Security Officer (ISSO) Support Specialist
- Discuss this with your agent
- Open in Claude
- Open in ChatGPT
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Role details
Tech stack
+7 more
Job description
We are seeking a senior-level Information System Security Officer (ISSO) Support Specialist with a minimum of 10 years of hands-on cybersecurity and Risk Management Framework (RMF) experience to support Assessment and Authorization (A&A) activities for a federal client. The ideal candidate will develop, maintain, and shepherd Authority to Operate (ATO) packages through the full RMF lifecycle - from Categorize through Monitor - while serving as a trusted security advisor to system owners and stakeholders. This role requires deep familiarity with NIST SP 800-37 Rev. 2 and SP 800-53 Rev. 5, experience across on-premises, cloud, and hybrid environments, and the ability to produce audit-ready, assessment-ready documentation under tight timelines., A&A Package Development and Documentation
- Develop and maintain the full suite of authorization artifacts required for ATO, including System Security Plans (SSP), Business Impact Analyses (BIA), FIPS-199 categorizations, Privacy Threshold/Impact Assessments (PTA/PIA), Configuration Management Plans (CMP), and e-Authentication documentation.
- Author detailed control implementation statements for assigned NIST SP 800-53 Rev. 5 controls within the SSP, clearly describing how each control is implemented, who is responsible, and what evidence supports it.
- Produce foundational documents such as system inventories, Boundary Scope Memorandums (BSM), system architecture diagrams, and Authorization Boundary and Network Diagrams (ABND) across on-premises, cloud (e.g., FedRAMP CSPs), and hybrid environments.
- Support system owners with control scoping, tailoring, and overlay identification, and map control inheritance from Common Control Providers.
- Develop Interconnection Security Agreements (ISA) and Memorandums of Understanding (MOU) between interconnected systems.
- Conduct white-glove reviews of system-level evidence - configuration screenshots, log samples, vulnerability scan reports (e.g., Tenable, Invicti), firewall rule exports, and resource inventories - for NIST SP 800-53 Rev. 5 compliance prior to submission to the Security Control Assessor (SCA).
- Identify AI/ML technologies within system inventories and apply AI RMF 1.0 principles and organization-specific AI overlays alongside the 800-53 Rev. 5 baseline to strengthen model transparency, accountability, and security for AI-enabled systems.
- Leverage approved generative AI tools (e.g., Amazon Bedrock, Anthropic Claude, OpenAI enterprise offerings) to accelerate artifact drafting, evidence review, and control-narrative consistency, while ensuring every AI-assisted product receives full analyst validation before submission.
System Testing and Continuous Monitoring Support
- Develop and maintain system-level Contingency Plans (CP) and Incident Response Plans (IRP) in coordination with system owners and technical staff.
- Coordinate, support, and document annual CP/IRP tabletop and functional testing scaled to each system’s risk categorization; author after-action reports with lessons learned.
- Develop and maintain Continuous Monitoring (ConMon) Plans ensuring NIST SP 800-137 compliance and sustained visibility into security posture beyond ATO grant.
Guidance, Training, and Process Improvement
- Provide expert RMF and Governance, Risk, and Compliance (GRC) guidance to system owners and stakeholders, translating technical requirements into actionable, risk-informed decisions.
- Develop and deliver RMF training, templates, and Standard Operating Procedures (SOPs); maintain template libraries, cloud assessment playbooks, and knowledge-management sites.
- Support process-improvement initiatives such as Authority to Use (ATU) approaches, boundary consolidation, and centralized ATO structures to reduce inventory and cost to compliance.
Strategic Advising and Lifecycle Support
- Serve as a primary security advisor to system owners and stakeholders across the full RMF and ATO lifecycle.
- Review FedRAMP Cloud Service Provider (CSP) authorization packages to scope customer responsibilities and identify agency risk acceptance; build crosswalks mapping SOC 2 Type II / StateRAMP to 800-53 Rev. 5.
- Support secure cloud deployments by reviewing infrastructure-as-code against 800-53 Rev. 5 and FedRAMP requirements.
- Drive data calls and mandated remediation activities (e.g., risk category validation, inventory refreshes) and support system decommissioning, including decommission letters and retirement submissions.
Requirements
- Minimum of 10 years of progressive experience in cybersecurity, information assurance, or IT risk management, with substantial direct experience supporting RMF/A&A and ATO package development.
- Demonstrated expertise with NIST SP 800-37 Rev. 2 (Risk Management Framework) and NIST SP 800-53 Rev. 5 (Security and Privacy Controls).
- Hands-on experience authoring and maintaining SSPs, BIAs, PTA/PIAs, CMPs, ISAs/MOUs, and related authorization artifacts.
- Demonstrated ability to write clear, audit-ready control implementation statements mapped to NIST SP 800-53 Rev. 5 control requirements.
- Working knowledge of FISMA, FedRAMP, and federal cybersecurity governance and compliance requirements.
- Experience reviewing technical evidence, including vulnerability scan results, log samples, and configuration data, to validate control implementation.
- Strong written and verbal communication skills, with the ability to translate complex technical and compliance topics for non-technical stakeholders.
- Experience developing or supporting Contingency Plans (CP), Incident Response Plans (IRP), and Continuous Monitoring (ConMon) programs per NIST SP 800-137.
- Ability to obtain and maintain the level of federal suitability/clearance required by the contract., * Experience applying AI RMF 1.0 or comparable AI-governance frameworks to the authorization of AI/ML-enabled systems.
- Familiarity with GRC and RMF tracking tools such as CSAM/JCAM, Xacta, or eMASS.
- Experience with cloud environments (AWS, Azure, or similar) and reviewing infrastructure-as-code for security compliance.
- Experience developing training curricula, SOPs, or playbooks for RMF stakeholders.
- Prior experience supporting a federal health, defense, or civilian agency authorization program.
Education and Certifications
- Bachelor’s degree in Cybersecurity, Information Technology, Computer Science, or a related field (equivalent experience may be considered in lieu of degree).
- Relevant certification is strongly preferred: CISSP, CAP, Security+, CISM, or equivalent DoD 8570/8140-aligned credential.
Benefits & conditions
$85,000 - $115,000 a year - Full-time, Pulled from the full job description
- Referral program
- Tuition reimbursement
- Health insurance
- 401(k) matching
- Paid time off
- Vision insurance
- Dental insurance, * 401(k) matching
- Dental insurance
- Employee assistance program
- Health insurance
- Life insurance
- Paid time off
- Referral program
- Tuition reimbursement
- Vision insurance
Apply for this position
This job is hosted externally. Click below to view the full posting and apply.
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Good distractions
Talks and stories from around this role — technically off-topic, practically not.
Moments
Explore playlistsVideos
See allRelated articles
See all
Dev Digest 134 - Where pixels sing?
Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.
Understanding and Mitigating Common Web Vulnerabilities
The Overflow: Security and Privacy