Назад
Company hidden
5 дней назад

Information System Security Officer (ISSO)

85 933 - 202 292$
Формат работы
onsite
Тип работы
fulltime
Грейд
senior
Английский
b2
Страна
US
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Information System Security Officer (ISSO) (Cybersecurity/RMF): Managing security assessment and authorization activities for federal information systems in multi-cloud and on-premise environments with an accent on NIST, FISMA, FedRAMP, and continuous monitoring. Focus on developing ATO and SSP documentation, conducting risk and control assessments, tracking POA&Ms, and improving remediation and incident response processes.

Location: On-site in Washington, DC, United States

Salary: $85,933.19–$202,292.42 per year

Company

hirify.global delivers advanced software and systems engineering solutions for complex technical challenges in the U.S. Federal Intelligence Community.

What you will do

  • Support the agency’s risk assessment program through internal audits, streamlined assessment processes, and security posture improvements.
  • Manage Security Assessment & Authorization packages, System Security Plans, supporting documentation, and Authority to Operate requirements.
  • Perform risk and security control assessments for cloud-based and on-premise systems, including evidence collection and stakeholder interviews.
  • Maintain system accreditation, ATO status, continuous monitoring activities, POA&Ms, and vulnerability remediation tracking.
  • Develop, coordinate, test, and train personnel on Incident Response and Contingency Plans.
  • Evaluate infrastructure, data flows, network diagrams, logical security boundaries, and security tooling across complex systems.

Requirements

  • 6+ years of experience with NIST, FISMA, and Security Assessment & Authorization.
  • Experience with FedRAMP and cloud platforms such as Azure, AWS, or Oracle Cloud Infrastructure.
  • In-depth knowledge of the Risk Management Framework and NIST publications, including SP 800-53 Rev. 5, SP 800-53A, and SP 800-18.
  • CISSP certification required.
  • Ability to obtain and maintain a customer Public Trust clearance is required; qualified candidates can be sponsored for this clearance.
  • Strong written and oral communication skills, with experience managing complex security workstreams and compliance artifacts.

Nice to have

  • Experience with governance, risk, and compliance tools such as JCAM, CSAM, or eMASS.
  • Experience analyzing SOC Type 2 and HIPAA results against NIST SP 800-53 Rev. 5 controls.
  • Experience with vulnerability, configuration, endpoint protection, data loss prevention, or intrusion detection tools.
  • Experience with Microsoft Excel or Power BI for combining and analyzing data from multiple sources.
  • Experience presenting security findings and reports to C-level audiences.

Culture & Benefits

  • Medical insurance cost sharing for employees and dependents.
  • Company-paid dental, vision, short-term disability, and long-term disability insurance.
  • 401(k) plan with a company match and immediate vesting.
  • Paid leave and holidays, life and AD&D insurance.
  • Tuition and training reimbursement.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →