> Markdown version of [/jobs/ext/3050996-information-systems-security-officer](https://www.wearedevelopers.com/jobs/ext/3050996-information-systems-security-officer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Information Systems Security Officer - **Company:** AnaVation, LLC - **Location:** United States (Remote available) - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** Amazon Web Services, Software System Penetration Testing, Microsoft Azure, Cloud Computing, Configuration Management, Cyber Security, Identity and Access Management, Software Vulnerability Management, Privacy Controls, Google Cloud, SARS Software Products, Cloud Platform System, Information Technology, Devsecops, Plan of Action and Milestones, Vulnerability Analysis - **Published:** September 24, 2026 - **Apply:** https://startup.jobs/information-systems-security-officer-isso-senior-anavation-10169716 ## About the Role AnaVation is seeking a Senior-level ISSO to support a newly-awarded contract. The selected candidate must be able to excel as the sole ISSO to prepare a full accreditation package to quickly obtain ATT/ATO for a new digital evidence platform in support of our Federal Government client. This is a full-time position that can be performed remotely with occasional travel to Washington DC as needed., * Bachelors Degree in a relevant field such as Cybersecurity or Information Assurance * 10+ years of relevant, hands-on experience in an ISSO or security compliance role * Clearance: * Public Trust; US Citizenship is required * Other Required Skills & Qualifications: * Deep knowledge of NIST SP 800-53 Rev 5 controls, enhancements, baselines, and assessment procedures. * Hands-on experience managing RMF packages and maintaining ongoing authorization. * Strong understanding of enterprise IT systems, networks, operating systems, identity platforms, and cloud environments (Azure, AWS, GCP). * Experience producing and maintaining SSPs, SARs, POA&Ms, Continuous Monitoring Plans, and supporting RMF documentation. * Familiarity with security tools such as SIEMs, vulnerability scanners, endpoint protection, identity governance platforms, and configuration management solutions. * Strong communication skills for interfacing with system owners, engineers, auditors, and executive leadership. * Ability to articulate control requirements and translate them into technical implementations. Preferred Qualifications: * Professional certifications such as CISSP, CISM, CAP, CCSP, or equivalent. * Prior experience supporting federal agencies, regulated industries, or FedRAMP systems. * Knowledge of NIST 800-30 (Risk Assessment), 800-37 (RMF), 800-53A (Control Assessments), and 800-137 (Continuous Monitoring). * Experience working in hybrid or cloud-native environments with security control inheritance patterns. * Background in DevSecOps or automated compliance tooling. Benefits ## Description * Lead all RMF activities for the assigned system, including Categorization, Selection, Implementation, Assessment, Authorization, and Continuous Monitoring. * Oversee the design, implementation, and validation of NIST 800-53 Rev 5 security and privacy controls across technical, operational, and management domains. * Develop, maintain, and update key security artifacts including System Security Plans (SSPs), Security Assessment Reports (SARs), POA&Ms, Incident Response Plans, and Continuous Monitoring strategies. * Coordinate and support security control assessments (SCAs), penetration tests, vulnerability scans, and compliance audits. * Guide engineering teams on implementing and documenting new or updated security controls, ensuring they align with Rev 5 enhancements and control baselines. * Evaluate system changes, architecture updates, and new integrations for security impact and required control modifications. * Lead risk assessments, document findings, and track remediation through POA&M management. * Manage continuous monitoring activities, including log review, vulnerability management, patch tracking, and configuration baseline validation. * Serve as the primary security liaison for system owners, internal stakeholders, external assessors, and authorizing officials (AOs). * Assist in developing security control inheritance strategies from enterprise common controls, and ensure proper documentation and alignment. * Mentor junior ISSOs and analysts in RMF, control interpretation, documentation quality, and security best practices. * Stay current on updates to NIST SP 800-53 Rev 5, 800-37, 800-30, and emerging federal cybersecurity guidance. ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [DevSecOps: Injecting Security into Mobile CI/CD Pipelines](https://www.wearedevelopers.com/videos/273-devsecops-injecting-security-into-mobile-ci-cd-pipelines) - [The Cloud is Calling: Answer with In-Demand Skills](https://www.wearedevelopers.com/videos/945-the-cloud-is-calling-answer-with-in-demand-skills) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [DevSecOps culture](https://www.wearedevelopers.com/videos/783-devsecops-culture) - [Organizational Change Through The Power Of Why - DevSecOps Enablement](https://www.wearedevelopers.com/videos/478-organizational-change-through-the-power-of-why-devsecops-enablement) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [The Overflow: Security and Privacy](https://www.wearedevelopers.com/magazine/715-the-overflow-security-and-privacy) - [How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again](https://www.wearedevelopers.com/magazine/751-how-we-built-a-worry-free-system-that-runs-for-10-years-and-what-we-d-do-again) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking)