ISSO Information Assurance/Security Specialist (Senior/SME)

Anakim Consulting Inc
Ashburn, VA, United States
1 day ago
Apply on jobs.localjobnetwork.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Working hours
Regular working hours

Tech stack

Xacta JIRA Cloud Computing Security Cyber Security Computer Networks Federal Information Processing Standards (FIPS) Identity and Access Management Information Security Management Virtual Private Networks (VPN) Windows Servers Red Hat Enterprise Linux Cloud Services
+15 more
Zero Trust Network Access RSA (Cryptosystem) Security Content Automation Protocol Security Software Wide Area Networks Diagnostic Tools Firewalls (Computer Science) Information Technology Nessus Nexpose Splunk Qualys Servicenow Plan of Action and Milestones Vulnerability Analysis

Job description

Anakim Consulting is hiring an Information System Security Officer (ISSO) with Senior or SME level expertise to lead Authorization to Operate (ATO) and continuous monitoring activities across multiple major applications (MA) and general support systems (GSS) for a large federal agency. This position requires hands-on experience in IT security, risk management, FedRAMP, and NIST standards. This individual will serve as a technical advisor to System Owners and senior leadership, directing security compliance, threat assessments, and cloud security initiatives., * Authorization & Accreditation (A&A): Lead end-to-end Risk Management Framework (RMF) and ATO processes, preparing and maintaining comprehensive security packages (SSP, RA, PTA, PIA, ST&E, and POA&M) in compliance with NIST SP 800-53, SP 800-37, and FISMA standards.

  • FedRAMP and Cloud Security: Develop, evaluate, and audit Cloud Service package documentation to ensure agency and FedRAMP compliance for cloud integrations.
  • Vulnerability & Compliance Management: Oversee regular vulnerability scans (Qualys, Nessus, Nexpose, ACAS), analyze Splunk audit logs, evaluate system hardening (STIGs/SCAP), and drive POA&M remediation efforts.
  • Continuous Diagnostics and Mitigation (CDM): Support and optimize CDM initiatives, automated security controls monitoring, and Zero Trust security architectures.
  • Configuration and Impact Analysis: Serve on Change Control Boards (CCB) to review proposed system design changes, perform security impact analyses, and ensure baseline compliance.
  • Leadership and Advisorship: Brief CISOs, System Owners, and senior stakeholders on overall system security posture, residual risk, and threat mitigation strategies.
  • Other duties, as assigned.

Requirements

Requirements and Qualifications:

  • U.S. citizenship, no dual citizenship
  • Current DHS CBP Suitability or eligibility to obtain secure access approval for DHS CBP EOD
  • 10+ years of progressive IT security, information assurance, and risk management experience, with a proven track record of leading system accreditations for federal agencies.
  • Bachelor’s degree in Computer Science, Cybersecurity Technology, Information Technology, or a related technical field (Master’s degree preferred).

Certifications

  • DoD 8570/8140 Requirement: Must possess a current baseline certification satisfying IAT/IAM Level III such as CISSP, CISM, GSLC, CCISO, CASP+, or equivalent.
  • Advanced Certification Requirement: Must possess at least one advanced or specialized credential such as: CISM, CCISO, CISA, CISSP, CDPSE, CCSK., * Frameworks and Standards: Expert-level knowledge of NIST SP 800-53 (Rev 4/5), NIST SP 800-37, FIPS 199/200, FISMA, FedRAMP, and NIST Cybersecurity Framework.
  • Assessment and Authorization Tools: Hands-on expertise with federal repository and assessment tools such as eMASS, Xacta, CSAM, or RSA Archer.
  • Security and Scan Tools: Experience with Splunk, Nessus, Qualys, Retina, IBM BigFix, and ticketing platforms (ServiceNow, Jira, Remedy).
  • Technical Environment: Working knowledge of RedHat Enterprise Linux, Windows Server environments, networking concepts (LAN/WAN/VPN, firewalls), and cloud security baselines.

Communication: Exceptional verbal and written communication skills with demonstrated success briefing senior executive leadership and managing technical teams.

Benefits & conditions

CybersecurityJobs #ISSO #InformationSystemSecurityOfficer #GovConJobs #PublicTrust #DHS #FedRAMP #NIST #RMF #CISM #CISSP #CCISO #CDPSE #CCSK #DMVJobs #SpringfieldVA AshburnVA #VirginiaJobs #Cybersecurity #Hiring #JobOpening #InformationAssurance #ATO

Full-Time/Part-Time Full-Time Salary Range This position offers a full time W2 salary plus eligibility to participate in the company’s benefits program. Req Number INF-26-00036 About the Organization Anakim Consulting is a privately held small company that provides growth opportunities for employees. Come join our team!

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on jobs.localjobnetwork.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

3:05 min

Integrating an assistant application with Jira software

Felix Augenstein · LIVE

2:07 min

Summarizing critical actions for organizational cybersecurity compliance readiness

Matthew Brady Matthew Brady · World Congress 2026 Europe

5:47 min

Integrating user stories and test automation via Jira tools

Christoph Ruggenthaler · LIVE

1:45 min

Transitioning from software development to security roles

Stefania Chaplin · World Congress 2022

3:22 min

Transitioning from software engineering to security roles

Anna Oliveira · Coffee With Developers

1:37 min

Mapping team collaboration networks using jira metadata

Dmitry Yanter Dmitry Yanter · World Congress 2025

Videos

See all

Related articles

See all