TL;DR
Senior Information Systems Security Officer (Cybersecurity): Developing and assessing Security Assessment & Authorization (SA&A) packages for mission-critical federal IT systems with an accent on FISMA, FedRAMP, and NIST compliance. Focus on managing accreditation boundaries, performing risk assessments, and ensuring continuous monitoring within a complex government environment.
Location: Must be based in or able to commute to Washington, DC
Company
hirify.global provides advanced software and systems engineering solutions to the U.S. Federal Intelligence and Law Enforcement communities.
What you will do
- Develop, maintain, and assess SA&A packages to achieve and maintain Authority to Operate (ATO).
- Create and maintain System Security Plans (SSP) and supporting documentation according to agency guidelines.
- Conduct continuous monitoring and risk assessments for government and cloud-based systems.
- Perform security control assessments, including evidence collection and stakeholder interviews.
- Manage system POA&Ms and conduct vulnerability management analysis.
- Coordinate and train personnel on Incident Response and Contingency Plans.
Requirements
- Must possess an active Top Secret clearance
- Minimum 6+ years of professional experience with NIST, FISMA, and SA&A
- CISSP certification is strictly required
- Demonstrated experience with FedRAMP and cloud environments (Azure, AWS, or Oracle)
- Comprehensive knowledge of NIST SP 800-53 publications
- Excellent oral and written communication skills for C-level reporting
Nice to have
- Experience using GRC tools such as CSAM or eMASS
- Ability to perform gap analysis on non-federated vendor audit results (e.g., SOC Type 2)
- Proficiency in data analysis tools like Excel or PowerBI for security reporting
Culture & Benefits
- Comprehensive medical, dental, and vision insurance with generous company cost-sharing
- 401k plan with generous matching and 100% immediate vesting
- 100% company-paid short-term and long-term disability insurance
- Competitive paid leave and holiday package
- Tuition and training reimbursement programs
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →