> Markdown version of [/jobs/ext/2540174-senior-level-information-system-security-officer-isso-support-specialist](https://www.wearedevelopers.com/jobs/ext/2540174-senior-level-information-system-security-officer-isso-support-specialist). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # senior-level Information System Security Officer (ISSO) Support Specialist - **Company:** AZ CYBER SECURITY SOLUTIONS - **Location:** United States (Remote available) - **Experience:** Expert - **Salary:** $85,000.0 - $115,000.0 - **Contract:** Permanent contract - **Skills:** Xacta, Artificial Intelligence, Amazon Web Services, Microsoft Azure, Configuration Management, Cyber Security, Federal Information Processing Standards (FIPS), Information Security Management, Knowledge Management, Machine Learning, Network Diagrams, Package Development Process, Cloud Services, Systems Architecture, System Testing, Privacy Controls, Cloud Platform System, Information Technology, Vulnerability Analysis - **Published:** August 11, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=b1f4f182f3e539a8 ## About the Role * Minimum of 10 years of progressive experience in cybersecurity, information assurance, or IT risk management, with substantial direct experience supporting RMF/A&A and ATO package development. * Demonstrated expertise with NIST SP 800-37 Rev. 2 (Risk Management Framework) and NIST SP 800-53 Rev. 5 (Security and Privacy Controls). * Hands-on experience authoring and maintaining SSPs, BIAs, PTA/PIAs, CMPs, ISAs/MOUs, and related authorization artifacts. * Demonstrated ability to write clear, audit-ready control implementation statements mapped to NIST SP 800-53 Rev. 5 control requirements. * Working knowledge of FISMA, FedRAMP, and federal cybersecurity governance and compliance requirements. * Experience reviewing technical evidence, including vulnerability scan results, log samples, and configuration data, to validate control implementation. * Strong written and verbal communication skills, with the ability to translate complex technical and compliance topics for non-technical stakeholders. * Experience developing or supporting Contingency Plans (CP), Incident Response Plans (IRP), and Continuous Monitoring (ConMon) programs per NIST SP 800-137. * Ability to obtain and maintain the level of federal suitability/clearance required by the contract., * Experience applying AI RMF 1.0 or comparable AI-governance frameworks to the authorization of AI/ML-enabled systems. * Familiarity with GRC and RMF tracking tools such as CSAM/JCAM, Xacta, or eMASS. * Experience with cloud environments (AWS, Azure, or similar) and reviewing infrastructure-as-code for security compliance. * Experience developing training curricula, SOPs, or playbooks for RMF stakeholders. * Prior experience supporting a federal health, defense, or civilian agency authorization program. Education and Certifications * Bachelor's degree in Cybersecurity, Information Technology, Computer Science, or a related field (equivalent experience may be considered in lieu of degree). * Relevant certification is strongly preferred: CISSP, CAP, Security+, CISM, or equivalent DoD 8570/8140-aligned credential. ## Description We are seeking a senior-level Information System Security Officer (ISSO) Support Specialist with a minimum of 10 years of hands-on cybersecurity and Risk Management Framework (RMF) experience to support Assessment and Authorization (A&A) activities for a federal client. The ideal candidate will develop, maintain, and shepherd Authority to Operate (ATO) packages through the full RMF lifecycle - from Categorize through Monitor - while serving as a trusted security advisor to system owners and stakeholders. This role requires deep familiarity with NIST SP 800-37 Rev. 2 and SP 800-53 Rev. 5, experience across on-premises, cloud, and hybrid environments, and the ability to produce audit-ready, assessment-ready documentation under tight timelines., A&A Package Development and Documentation * Develop and maintain the full suite of authorization artifacts required for ATO, including System Security Plans (SSP), Business Impact Analyses (BIA), FIPS-199 categorizations, Privacy Threshold/Impact Assessments (PTA/PIA), Configuration Management Plans (CMP), and e-Authentication documentation. * Author detailed control implementation statements for assigned NIST SP 800-53 Rev. 5 controls within the SSP, clearly describing how each control is implemented, who is responsible, and what evidence supports it. * Produce foundational documents such as system inventories, Boundary Scope Memorandums (BSM), system architecture diagrams, and Authorization Boundary and Network Diagrams (ABND) across on-premises, cloud (e.g., FedRAMP CSPs), and hybrid environments. * Support system owners with control scoping, tailoring, and overlay identification, and map control inheritance from Common Control Providers. * Develop Interconnection Security Agreements (ISA) and Memorandums of Understanding (MOU) between interconnected systems. * Conduct white-glove reviews of system-level evidence - configuration screenshots, log samples, vulnerability scan reports (e.g., Tenable, Invicti), firewall rule exports, and resource inventories - for NIST SP 800-53 Rev. 5 compliance prior to submission to the Security Control Assessor (SCA). * Identify AI/ML technologies within system inventories and apply AI RMF 1.0 principles and organization-specific AI overlays alongside the 800-53 Rev. 5 baseline to strengthen model transparency, accountability, and security for AI-enabled systems. * Leverage approved generative AI tools (e.g., Amazon Bedrock, Anthropic Claude, OpenAI enterprise offerings) to accelerate artifact drafting, evidence review, and control-narrative consistency, while ensuring every AI-assisted product receives full analyst validation before submission. System Testing and Continuous Monitoring Support * Develop and maintain system-level Contingency Plans (CP) and Incident Response Plans (IRP) in coordination with system owners and technical staff. * Coordinate, support, and document annual CP/IRP tabletop and functional testing scaled to each system's risk categorization; author after-action reports with lessons learned. * Develop and maintain Continuous Monitoring (ConMon) Plans ensuring NIST SP 800-137 compliance and sustained visibility into security posture beyond ATO grant. Guidance, Training, and Process Improvement * Provide expert RMF and Governance, Risk, and Compliance (GRC) guidance to system owners and stakeholders, translating technical requirements into actionable, risk-informed decisions. * Develop and deliver RMF training, templates, and Standard Operating Procedures (SOPs); maintain template libraries, cloud assessment playbooks, and knowledge-management sites. * Support process-improvement initiatives such as Authority to Use (ATU) approaches, boundary consolidation, and centralized ATO structures to reduce inventory and cost to compliance. Strategic Advising and Lifecycle Support * Serve as a primary security advisor to system owners and stakeholders across the full RMF and ATO lifecycle. * Review FedRAMP Cloud Service Provider (CSP) authorization packages to scope customer responsibilities and identify agency risk acceptance; build crosswalks mapping SOC 2 Type II / StateRAMP to 800-53 Rev. 5. * Support secure cloud deployments by reviewing infrastructure-as-code against 800-53 Rev. 5 and FedRAMP requirements. * Drive data calls and mandated remediation activities (e.g., risk category validation, inventory refreshes) and support system decommissioning, including decommission letters and retirement submissions. ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Leverage Cloud Computing Benefits with Serverless Multi-Cloud ML ](https://www.wearedevelopers.com/videos/78-leverage-cloud-computing-benefits-with-serverless-multi-cloud-ml) - [How To Test A Ball of Mud](https://www.wearedevelopers.com/videos/173-how-to-test-a-ball-of-mud) - [Cloud-nativeApplications- What’s the buzz about](https://www.wearedevelopers.com/videos/55-cloud-nativeapplications-what-s-the-buzz-about) - [One Pipeline, Three Regulator - SBOM Compliance for the Developer](https://www.wearedevelopers.com/videos/100169-one-pipeline-three-regulator-sbom-compliance-for-the-developer) - [ZEISS & Microsoft - Building the Next Generation Medical Ecosystem in the Cloud](https://www.wearedevelopers.com/videos/424-zeiss-microsoft-building-the-next-generation-medical-ecosystem-in-the-cloud) ## Related Articles - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [The Overflow: Security and Privacy](https://www.wearedevelopers.com/magazine/715-the-overflow-security-and-privacy) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking)