Information System Security Officer
- Discuss this with your agent
- Open in Claude
- Open in ChatGPT
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Role details
Tech stack
Job description
We are seeking a Senior Information System Security Officer (ISSO) to support a federal cybersecurity program. The successful candidate will play a critical role in remediating and stabilizing the security posture of the information systems, with a future focus on automation. The immediate focus is remediation and stabilization. This position involves managing security across approximately 90 systems, ensuring compliance with federal standards, and advising senior leadership on cybersecurity matters., * Lead the full Risk Management Framework (RMF) lifecycle and Authority to Operate (ATO) process end-to-end.
- Develop and maintain System Security Plans (SSPs), Plans of Action & Milestones (POA&Ms), Configuration Management Plans, Contingency Plans, and Incident Response Plans.
- Serve as the primary cybersecurity lead and advisor for system owners, Program Management Organizations (PMOs), and senior leadership.
- Conduct risk assessments, annual security assessments, vulnerability assessments, and continuous monitoring activities.
- Manage POA&M remediation planning, audit findings, and compliance tracking.
- Perform Security Impact Analyses, review change requests, and oversee configuration management activities.
- Develop and maintain authorization boundary diagrams, security architectures, and security requirement traceability matrices.
- Support security audits, compliance reviews, and accreditation efforts.
Requirements
- Bachelor’s degree and 15+ years of relevant experience; or Associate’s degree and 17+ years of relevant experience; or 21+ years of relevant experience in lieu of a degree.
Technical Skills:
- 10+ years of Information Security experience supporting federal systems.
- Deep expertise in the RMF lifecycle and ATO process.
- Strong knowledge of FISMA, NIST 800-37, NIST 800-53, and DHS 4300 Series requirements.
- Experience with security control implementation, self-assessments, and business impact analyses.
- Strong communication skills with the ability to brief executives and present risk findings to senior leadership.
Preferred Qualifications
- CISSP, CISM, or CASP+ certification.
- Experience with CSAM, RegScale, eMASS, or similar GRC tools.
- Knowledge of cloud security and FedRAMP authorization processes.
- Previous experience supporting federal agencies.
- Experience with continuous monitoring and automated security tools.
About the company
Everforth Apex is a world-class IT services company that serves thousands of clients across the globe. When you join Everforth Apex, you become part of a team that values innovation, collaboration, and continuous learning. We offer quality career resources, training, certifications, development opportunities, and a comprehensive benefits package. Our commitment to excellence is reflected in many awards, including ClearlyRateds Best of Staffing in Talent Satisfaction in the United States and Great Place to Work in the United Kingdom and Mexico.
Everforth Apex uses a virtual recruiter as part of the application process. Click for more details. By applying for this job, you agree to receive calls, AI-generated calls, text messages, or emails from Everforth Apex and its affiliates, and contracted partners. Frequency varies for text messages. Message and data rates may apply. Carriers are not liable for delayed or undelivered messages. You can reply STOP to cancel and HELP for help. You can access our privacy policy at
Apply for this position
This job is hosted externally. Click below to view the full posting and apply.
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Good distractions
Talks and stories from around this role — technically off-topic, practically not.
Moments
Explore playlistsVideos
See allRelated articles
See all
What Are The Top Skills Required For Azure Developers?
How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again
Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.
9 Ways to Make Money Hacking