Intermediate Information System Security Officer
- Discuss this with your agent
- Open in Claude
- Open in ChatGPT
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Role details
Tech stack
Job description
We are seeking an Intermediate Information System Security Officer (ISSO) to support a federal government customer. The primary objective is to restore the security program, which has been neglected, by cleaning up existing compliance issues and stabilizing the environment. This role is central to remediation efforts and will involve enhancing automation to improve efficiency across approximately 90 systems. The position requires working with system owners and cybersecurity teams to manage security controls enterprise-wide, focusing on specific control families rather than individual systems., * Execute Risk Management Framework (RMF) activities to support Authorization to Operate (ATO) decisions.
- Develop, maintain, and update security documentation, including System Security Plans (SSPs), Plan of Action and Milestones (POA&Ms), and Contingency Plans.
- Conduct security control assessments, vulnerability assessments, and Security Impact Analyses for system changes.
- Support continuous monitoring, vulnerability management, and POA&M tracking and remediation.
- Implement security controls to ensure the confidentiality, integrity, and availability of information systems in compliance with federal standards.
- Support change management processes, including participating in Change Advisory Board (CAB) reviews.
- Prepare for and support security audits, testing, and compliance reviews by providing necessary documentation.
- Respond to cybersecurity data calls with timely information for leadership.
- Organize responsibilities by security control areas (e.g., Access Control, Configuration Management) across all systems.
Requirements
- Bachelor’s Degree and 10+ years of relevant experience; or an Associate’s Degree and 12+ years of experience; or 16+ years of experience with no degree.
- A minimum of 7 years of experience in Information Security or as an ISSO supporting federal systems.
Citizenship and Work Location:
- U.S. Citizenship is required.
- Candidates must reside within a local radius of Washington, D.C., and be available for occasional onsite work if requested.
Technical Skills and Knowledge:
- Hands-on experience with the RMF lifecycle and ATO activities.
- Strong knowledge of FISMA, NIST 800-37, NIST 800-53, and DHS 4300 Series.
- Experience developing and maintaining SSPs, POA&Ms, Contingency Plans, and other security artifacts.
- Background in conducting security control assessments and Security Impact Analyses.
- Proficiency in continuous monitoring, vulnerability management, and POA&M remediation.
- Strong technical writing skills for producing compliance and assessment documentation.
Certifications:
- Must hold a CISSP, CISM, or CASP+ certification., * Experience supporting the Department of Homeland Security (DHS) or its components.
- Understanding of cloud security concepts, with experience in AWS or Azure.
- Experience with Governance, Risk, and Compliance (GRC) tools such as CSAM, eMASS, or RegScale.
Benefits & conditions
This position is currently 100% remote. The immediate focus is on remediation and stabilization, with automation initiatives to follow. You will be part of a team-oriented environment focused on enterprise-wide security control management rather than system-specific assignments.
Everforth Apex is a world-class IT services company that serves thousands of clients across the globe. When you join Everforth Apex, you become part of a team that values innovation, collaboration, and continuous learning. We offer quality career resources, training, certifications, development opportunities, and a comprehensive benefits package. Our commitment to excellence is reflected in many awards, including ClearlyRateds Best of Staffing in Talent Satisfaction in the United States and Great Place to Work in the United Kingdom and Mexico.
Everforth Apex uses a virtual recruiter as part of the application process. Click for more details. By applying for this job, you agree to receive calls, AI-generated calls, text messages, or emails from Everforth Apex and its affiliates, and contracted partners. Frequency varies for text messages. Message and data rates may apply. Carriers are not liable for delayed or undelivered messages. You can reply STOP to cancel and HELP for help. You can access our privacy policy at
Everforth Apex Benefits Overview: Everforth Apex offers a range of supplemental benefits, including medical, dental, vision, life, disability, and other insurance plans that offer an optional layer of financial protection. We offer an ESPP (employee stock purchase program) and a 401K program which allows you to contribute typically within 30 days of starting, with a company match after 12 months of tenure. Everforth Apex also offers a HSA (Health Savings Account on the HDHP plan), a SupportLinc Employee Assistance Program (EAP) with up to 8 free counseling sessions, a corporate discount savings program and other discounts. In terms of professional development, Everforth Apex hosts an on-demand training program, provides access to certification prep and a library of technical and leadership courses/books/seminars once you have 6+ months of tenure, and certification discounts and other perks to associations that include CompTIA and IIBA. Everforth Apex has a dedicated customer service team for our Consultants that can address questions around benefits and other resources, as well as a certified Career Coach. You can access a full list of our benefits, programs, support teams and resources within our ‘Welcome Packet’ as well, which an Everforth Apex team member can provide.
Apply for this position
This job is hosted externally. Click below to view the full posting and apply.
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Good distractions
Talks and stories from around this role — technically off-topic, practically not.
Moments
Explore playlistsVideos
See allRelated articles
See all
Best Paying Jobs in Technology
9 Ways to Make Money Hacking
Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.
How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again