Senior Information System Security Officer (Cybersecurity)
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
TL;DR
Senior Information System Security Officer (Cybersecurity): Leading the execution of Risk Management Framework (RMF) activities and serving as the primary security advisor for NIH information systems with an accent on authorization packages, vulnerability remediation, and NIST compliance. Focus on coordinating cybersecurity efforts across system owners and engineering teams to ensure ongoing authorization and continuous monitoring.
Location: 100% Remote (Must be based in the USA due to Federal requirements)
Company
is a fast-growing cybersecurity firm recognized as one of the Best Places to Work and an Inc. 5000 honoree.
What you will do
- Serve as the primary cybersecurity advisor for assigned information systems throughout their lifecycle.
- Lead Risk Management Framework (RMF) activities for initial and ongoing authorization, annual assessments, and continuous monitoring.
- Develop and maintain System Security Plans (SSPs), authorization artifacts, and supporting RMF documentation.
- Track vulnerabilities, POA&Ms, and risk acceptance decisions to ensure cybersecurity risks are managed and documented.
- Coordinate with System Owners, Authorizing Officials, and Government personnel to maintain authorization readiness.
- Mentor junior ISSOs and promote continuous improvement in RMF processes and documentation standards.
Requirements
- Bachelor’s degree in Cybersecurity, IT, Computer Science, or a related discipline.
- 5+ years of experience serving as an ISSO or supporting Federal RMF and Assessment & Authorization (A&A) programs.
- Strong working knowledge of NIST SP 800-37, NIST SP 800-53 Rev. 5, NIST SP 800-53A, FISMA, and Federal cybersecurity policy.
- Experience preparing and maintaining authorization documentation including SSPs, SARs, and POA&Ms.
- Excellent written and verbal communication skills for coordinating complex activities across multiple organizations.
Nice to have
- Experience supporting NIH, HHS, or other Federal civilian agencies.
- Proficiency with eMASS, JCAM, ServiceNow GRC, or Archer.
- Experience with cloud-based systems, High Value Assets (HVAs), or enterprise shared services.
- Familiarity with Zero Trust implementation and Continuous Diagnostics and Mitigation (CDM).
- Certifications such as CISSP, CGRC, CAP, CISM, Security+, or PMP.
Culture & Benefits
- Recognized as a "Best Place to Work" in 2023 and 2025.
- Inc. 5000 honoree for fastest-growing companies in America.
- People-first approach and unwavering dedication to excellence.
- 100% remote work environment.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →