Information System Security Officer (ISSO)

911INFORM LLC
Wall Township, NJ, United States
3 months ago
Apply on indeed.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience required
1 year minimum
Working hours
Regular working hours
Job source

Tech stack

Microsoft Access Microsoft Windows Amazon Web Services JIRA Software as a Service Cyber Security Information Security Management MongoDB Systems Development Life Cycle Microsoft SharePoint Information Security Management System Tenable Nessus
+2 more
Data Management Vulnerability Analysis

Job description

911inform is seeking an Information System Security Officer (ISSO) to serve as the day-to-day security steward of our FedRAMP Moderate authorized SaaS platform. The ISSO is the hands-on owner of the System Security Plan (SSP), continuous monitoring (ConMon), POA&M management, and audit evidence collection across our AWS GovCloud and Commercial environments. This role is ideal for a detail-oriented security practitioner who thrives in compliance-driven operations and enjoys turning controls into working processes., System Security Plan (SSP) Ownership - Maintain and update the FedRAMP Moderate SSP, including all narrative sections, appendices (cryptographic modules, ports/protocols, interconnections), and supporting attachments.

Continuous Monitoring (ConMon) - Execute monthly ConMon deliverables: vulnerability scan reports (Tenable), POA&M updates, inventory reconciliation, and significant change requests.

POA&M Management - Track, prioritize, and drive remediation of findings to closure; coordinate with engineering and IT to meet FedRAMP timelines (30/90/180 days by severity).

Audit Evidence Collection - Package and submit evidence for FedRAMP, SOC 2 Type II, and ISO 27001 audits; maintain Vanta and SharePoint-based evidence libraries.

Access Reviews - Conduct quarterly access reviews across AWS (Commercial + GovCloud), M365 GCC, MongoDB Atlas for Government, CrowdStrike, Tenable, Action1, Jira, and other in-boundary systems.

Vulnerability & Endpoint Oversight - Monitor Tenable Nessus, CrowdStrike Falcon, and Action1 coverage; investigate agent reporting gaps and orphaned endpoints.

Incident Response Support - Maintain the IR Plan, support tabletop exercises, complete Appendix B incident collection forms, and assist in real-world investigations (e.g., supply chain events).

Policy & Procedure Maintenance - Keep Access Control, Privileged Access, Data Management, Incident Response, Secure SDLC, and Third-Party Management policies current and audit-ready.

Third-Party / Vendor Risk - Onboard new vendors, review DPAs/SLAs/SOC 2 reports, maintain the vendor risk register, and route critical-risk acceptances to the CFO per policy.

Control Implementation Support - Partner with engineering on NIST 800-53 Rev. 5 control implementation, particularly AC, AU, CM, CP, IR, RA, SC, and SI families.

Requirements

Do you have experience in SOC 2?, 3-5+ years in information security, compliance, or GRC roles.

Working knowledge of NIST 800-53 Rev. 5, FedRAMP Moderate, SOC 2, and ISO 27001.

Hands-on experience with AWS (GovCloud a plus), Microsoft 365 (GCC a plus), and at least one EDR/VM platform (CrowdStrike, Tenable, Defender).

Experience writing and maintaining SSPs, POA&Ms, and audit evidence.

Strong written communication - able to produce audit-ready narratives and executive summaries.

Preferred Qualifications

CISSP, CISA, CAP, CCSP, Security+, or equivalent.

Prior experience supporting a FedRAMP authorization or 3PAO assessment.

Familiarity with Vanta, Drata, or similar GRC automation tools.

Background in public safety, 9-1-1, telecom, or critical infrastructure SaaS.

Benefits & conditions

Pulled from the full job description

  • Health insurance
  • Paid time off

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on indeed.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

5:03 min

Navigating new cybersecurity compliance frameworks and laws

Kurt Eder · LIVE

3:05 min

Integrating an assistant application with Jira software

Felix Augenstein · LIVE

2:01 min

Migrating existing applications from MongoDB to Postgres

Nikita Shamgunov Nikita Shamgunov · World Congress 2024

4:11 min

Introduction to cloud-native application developer security

Micah Silverman · World Congress 2022

1:45 min

Transitioning from software development to security roles

Stefania Chaplin · World Congress 2022

5:47 min

Integrating user stories and test automation via Jira tools

Christoph Ruggenthaler · LIVE

Videos

See all

Related articles

See all