senior-level Information System Security Officer (ISSO) Support Specialist

AZ CYBER SECURITY SOLUTIONS
United States
23 days ago
Apply on www.indeed.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
10 years minimum
Compensation
$85,000.0 - $115,000.0
Working hours
Regular working hours
Job source

Tech stack

Xacta Artificial Intelligence Amazon Web Services Microsoft Azure Configuration Management Cyber Security Federal Information Processing Standards (FIPS) Information Security Management Knowledge Management Machine Learning Network Diagrams Package Development Process
+7 more
Cloud Services Systems Architecture System Testing Privacy Controls Cloud Platform System Information Technology Vulnerability Analysis

Job description

We are seeking a senior-level Information System Security Officer (ISSO) Support Specialist with a minimum of 10 years of hands-on cybersecurity and Risk Management Framework (RMF) experience to support Assessment and Authorization (A&A) activities for a federal client. The ideal candidate will develop, maintain, and shepherd Authority to Operate (ATO) packages through the full RMF lifecycle - from Categorize through Monitor - while serving as a trusted security advisor to system owners and stakeholders. This role requires deep familiarity with NIST SP 800-37 Rev. 2 and SP 800-53 Rev. 5, experience across on-premises, cloud, and hybrid environments, and the ability to produce audit-ready, assessment-ready documentation under tight timelines., A&A Package Development and Documentation

  • Develop and maintain the full suite of authorization artifacts required for ATO, including System Security Plans (SSP), Business Impact Analyses (BIA), FIPS-199 categorizations, Privacy Threshold/Impact Assessments (PTA/PIA), Configuration Management Plans (CMP), and e-Authentication documentation.
  • Author detailed control implementation statements for assigned NIST SP 800-53 Rev. 5 controls within the SSP, clearly describing how each control is implemented, who is responsible, and what evidence supports it.
  • Produce foundational documents such as system inventories, Boundary Scope Memorandums (BSM), system architecture diagrams, and Authorization Boundary and Network Diagrams (ABND) across on-premises, cloud (e.g., FedRAMP CSPs), and hybrid environments.
  • Support system owners with control scoping, tailoring, and overlay identification, and map control inheritance from Common Control Providers.
  • Develop Interconnection Security Agreements (ISA) and Memorandums of Understanding (MOU) between interconnected systems.
  • Conduct white-glove reviews of system-level evidence - configuration screenshots, log samples, vulnerability scan reports (e.g., Tenable, Invicti), firewall rule exports, and resource inventories - for NIST SP 800-53 Rev. 5 compliance prior to submission to the Security Control Assessor (SCA).
  • Identify AI/ML technologies within system inventories and apply AI RMF 1.0 principles and organization-specific AI overlays alongside the 800-53 Rev. 5 baseline to strengthen model transparency, accountability, and security for AI-enabled systems.
  • Leverage approved generative AI tools (e.g., Amazon Bedrock, Anthropic Claude, OpenAI enterprise offerings) to accelerate artifact drafting, evidence review, and control-narrative consistency, while ensuring every AI-assisted product receives full analyst validation before submission.

System Testing and Continuous Monitoring Support

  • Develop and maintain system-level Contingency Plans (CP) and Incident Response Plans (IRP) in coordination with system owners and technical staff.
  • Coordinate, support, and document annual CP/IRP tabletop and functional testing scaled to each system’s risk categorization; author after-action reports with lessons learned.
  • Develop and maintain Continuous Monitoring (ConMon) Plans ensuring NIST SP 800-137 compliance and sustained visibility into security posture beyond ATO grant.

Guidance, Training, and Process Improvement

  • Provide expert RMF and Governance, Risk, and Compliance (GRC) guidance to system owners and stakeholders, translating technical requirements into actionable, risk-informed decisions.
  • Develop and deliver RMF training, templates, and Standard Operating Procedures (SOPs); maintain template libraries, cloud assessment playbooks, and knowledge-management sites.
  • Support process-improvement initiatives such as Authority to Use (ATU) approaches, boundary consolidation, and centralized ATO structures to reduce inventory and cost to compliance.

Strategic Advising and Lifecycle Support

  • Serve as a primary security advisor to system owners and stakeholders across the full RMF and ATO lifecycle.
  • Review FedRAMP Cloud Service Provider (CSP) authorization packages to scope customer responsibilities and identify agency risk acceptance; build crosswalks mapping SOC 2 Type II / StateRAMP to 800-53 Rev. 5.
  • Support secure cloud deployments by reviewing infrastructure-as-code against 800-53 Rev. 5 and FedRAMP requirements.
  • Drive data calls and mandated remediation activities (e.g., risk category validation, inventory refreshes) and support system decommissioning, including decommission letters and retirement submissions.

Requirements

  • Minimum of 10 years of progressive experience in cybersecurity, information assurance, or IT risk management, with substantial direct experience supporting RMF/A&A and ATO package development.
  • Demonstrated expertise with NIST SP 800-37 Rev. 2 (Risk Management Framework) and NIST SP 800-53 Rev. 5 (Security and Privacy Controls).
  • Hands-on experience authoring and maintaining SSPs, BIAs, PTA/PIAs, CMPs, ISAs/MOUs, and related authorization artifacts.
  • Demonstrated ability to write clear, audit-ready control implementation statements mapped to NIST SP 800-53 Rev. 5 control requirements.
  • Working knowledge of FISMA, FedRAMP, and federal cybersecurity governance and compliance requirements.
  • Experience reviewing technical evidence, including vulnerability scan results, log samples, and configuration data, to validate control implementation.
  • Strong written and verbal communication skills, with the ability to translate complex technical and compliance topics for non-technical stakeholders.
  • Experience developing or supporting Contingency Plans (CP), Incident Response Plans (IRP), and Continuous Monitoring (ConMon) programs per NIST SP 800-137.
  • Ability to obtain and maintain the level of federal suitability/clearance required by the contract., * Experience applying AI RMF 1.0 or comparable AI-governance frameworks to the authorization of AI/ML-enabled systems.
  • Familiarity with GRC and RMF tracking tools such as CSAM/JCAM, Xacta, or eMASS.
  • Experience with cloud environments (AWS, Azure, or similar) and reviewing infrastructure-as-code for security compliance.
  • Experience developing training curricula, SOPs, or playbooks for RMF stakeholders.
  • Prior experience supporting a federal health, defense, or civilian agency authorization program.

Education and Certifications

  • Bachelor’s degree in Cybersecurity, Information Technology, Computer Science, or a related field (equivalent experience may be considered in lieu of degree).
  • Relevant certification is strongly preferred: CISSP, CAP, Security+, CISM, or equivalent DoD 8570/8140-aligned credential.

Benefits & conditions

$85,000 - $115,000 a year - Full-time, Pulled from the full job description

  • Referral program
  • Tuition reimbursement
  • Health insurance
  • 401(k) matching
  • Paid time off
  • Vision insurance
  • Dental insurance, * 401(k) matching
  • Dental insurance
  • Employee assistance program
  • Health insurance
  • Life insurance
  • Paid time off
  • Referral program
  • Tuition reimbursement
  • Vision insurance

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.indeed.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

2:41 min

Transitioning artificial intelligence infrastructure into scalable commodity cloud services

juarezjunior juarezjunior · World Congress 2024

7:25 min

Writing system tests to verify operational infrastructure

Ryan Latta · World Congress 2021

5:03 min

Navigating new cybersecurity compliance frameworks and laws

Kurt Eder · LIVE

47 sec

Advantages of edge inference over cloud API services

Sasha Denisov Sasha Denisov · World Congress 2026 Europe

2:51 min

Writing characterization tests to document existing behavior

Gil Zilberfeld · JS Congress

1:45 min

Transitioning from software development to security roles

Stefania Chaplin · World Congress 2022

Videos

See all

Related articles

See all