> Markdown version of [/jobs/ext/581668-information-system-security-officer-isso](https://www.wearedevelopers.com/jobs/ext/581668-information-system-security-officer-isso). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Information System Security Officer (ISSO) - **Company:** 911INFORM LLC - **Location:** Wall Township, NJ, United States - **Contract:** Permanent contract - **Skills:** Microsoft Access, Microsoft Windows, Amazon Web Services, JIRA, Software as a Service, Cyber Security, Information Security Management, MongoDB, Systems Development Life Cycle, Microsoft SharePoint, Information Security Management System, Tenable Nessus, Data Management, Vulnerability Analysis - **Published:** June 21, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=fb594ae1ad3e66e9 ## About the Role Do you have experience in SOC 2?, 3-5+ years in information security, compliance, or GRC roles. Working knowledge of NIST 800-53 Rev. 5, FedRAMP Moderate, SOC 2, and ISO 27001. Hands-on experience with AWS (GovCloud a plus), Microsoft 365 (GCC a plus), and at least one EDR/VM platform (CrowdStrike, Tenable, Defender). Experience writing and maintaining SSPs, POA&Ms, and audit evidence. Strong written communication - able to produce audit-ready narratives and executive summaries. Preferred Qualifications CISSP, CISA, CAP, CCSP, Security+, or equivalent. Prior experience supporting a FedRAMP authorization or 3PAO assessment. Familiarity with Vanta, Drata, or similar GRC automation tools. Background in public safety, 9-1-1, telecom, or critical infrastructure SaaS. ## Description 911inform is seeking an Information System Security Officer (ISSO) to serve as the day-to-day security steward of our FedRAMP Moderate authorized SaaS platform. The ISSO is the hands-on owner of the System Security Plan (SSP), continuous monitoring (ConMon), POA&M management, and audit evidence collection across our AWS GovCloud and Commercial environments. This role is ideal for a detail-oriented security practitioner who thrives in compliance-driven operations and enjoys turning controls into working processes., System Security Plan (SSP) Ownership - Maintain and update the FedRAMP Moderate SSP, including all narrative sections, appendices (cryptographic modules, ports/protocols, interconnections), and supporting attachments. Continuous Monitoring (ConMon) - Execute monthly ConMon deliverables: vulnerability scan reports (Tenable), POA&M updates, inventory reconciliation, and significant change requests. POA&M Management - Track, prioritize, and drive remediation of findings to closure; coordinate with engineering and IT to meet FedRAMP timelines (30/90/180 days by severity). Audit Evidence Collection - Package and submit evidence for FedRAMP, SOC 2 Type II, and ISO 27001 audits; maintain Vanta and SharePoint-based evidence libraries. Access Reviews - Conduct quarterly access reviews across AWS (Commercial + GovCloud), M365 GCC, MongoDB Atlas for Government, CrowdStrike, Tenable, Action1, Jira, and other in-boundary systems. Vulnerability & Endpoint Oversight - Monitor Tenable Nessus, CrowdStrike Falcon, and Action1 coverage; investigate agent reporting gaps and orphaned endpoints. Incident Response Support - Maintain the IR Plan, support tabletop exercises, complete Appendix B incident collection forms, and assist in real-world investigations (e.g., supply chain events). Policy & Procedure Maintenance - Keep Access Control, Privileged Access, Data Management, Incident Response, Secure SDLC, and Third-Party Management policies current and audit-ready. Third-Party / Vendor Risk - Onboard new vendors, review DPAs/SLAs/SOC 2 reports, maintain the vendor risk register, and route critical-risk acceptances to the CFO per policy. Control Implementation Support - Partner with engineering on NIST 800-53 Rev. 5 control implementation, particularly AC, AU, CM, CP, IR, RA, SC, and SI families. ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Improving quality with Agentic AI with Rovo Dev and Xray](https://www.wearedevelopers.com/videos/2005-improving-quality-with-agentic-ai-with-rovo-dev-and-xray) - [40 Minutes to Build a Serverless COVID-19 REST and GraphQL APIs](https://www.wearedevelopers.com/videos/208-40-minutes-to-build-a-serverless-covid-19-rest-and-graphql-apis) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [One Pipeline, Three Regulator - SBOM Compliance for the Developer](https://www.wearedevelopers.com/videos/100169-one-pipeline-three-regulator-sbom-compliance-for-the-developer) - [Collaboration Quantified: Lessons from Open Source Developer Networks](https://www.wearedevelopers.com/videos/1422-collaboration-quantified-lessons-from-open-source-developer-networks) ## Related Articles - [How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again](https://www.wearedevelopers.com/magazine/751-how-we-built-a-worry-free-system-that-runs-for-10-years-and-what-we-d-do-again) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [The Overflow: Security and Privacy](https://www.wearedevelopers.com/magazine/715-the-overflow-security-and-privacy) - [Dev Digest 121 - AI goes offline](https://www.wearedevelopers.com/magazine/456-dev-digest-121-ai-goes-offline)