2 дня назад
Senior Information Systems Security Officer (Cybersecurity)
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
Текст:
TL;DR
Senior Information Systems Security Officer (Cybersecurity) (FedRAMP/GovRAMP): Maintaining security posture, authorization readiness, and compliance documentation for regulated cloud and application systems with an accent on NIST controls, System Security Plans, continuous monitoring, and remediation tracking. Focus on supporting FedRAMP High, GovRAMP High, and DoD Impact Level 5 activities, validating security controls, and coordinating complex assessments across technical and government stakeholders.
Location: Remote in the US; hybrid schedule available for candidates in the Chicago, IL metro area. U.S. citizenship and an enhanced security background check, including a financial vulnerability assessment, are required.
Company
develops cybersecurity software, including an AI-enabled, cloud-native privileged access management platform for regulated public and private-sector environments.
What you will do
- Serve as the Information Systems Security Officer for assigned systems and environments.
- Maintain system architecture knowledge, security boundaries, data flows, dependencies, and control implementations.
- Develop and maintain System Security Plans, control narratives, policies, procedures, audit evidence, and Plans of Action and Milestones.
- Support FedRAMP High, GovRAMP High, DoD Impact Level 5, Authorization to Operate, continuous monitoring, and recurring assessment activities.
- Coordinate security control implementation, remediation, risk analysis, incident response, contingency planning, disaster recovery, and tabletop exercises.
- Work with Engineering, DevOps, IT, Security, Compliance, auditors, assessors, and government stakeholders to maintain assessment readiness.
Requirements
- 5+ years of experience in information security, information assurance, cybersecurity compliance, system security, or a related field.
- Experience as an ISSO, system security analyst, compliance engineer, or similar professional supporting regulated information systems.
- Strong knowledge of NIST SP 800-53, the Risk Management Framework, vulnerability management, configuration management, access control, logging, encryption, incident response, and system change management.
- Experience with FedRAMP, GovRAMP, DoD Impact Level requirements, System Security Plans, Plans of Action and Milestones, Authorization to Operate activities, and assessment evidence.
- Working knowledge of AWS cloud environments, cloud and application architectures, and translating technical implementations into security documentation.
- U.S. citizenship and the ability to pass an enhanced security background check, including a financial vulnerability assessment, are required.
Nice to have
- Experience with FedRAMP High, GovRAMP High, DoD Impact Level 5, cloud-native SaaS products, and AWS-based architectures.
- Familiarity with automated compliance, evidence collection, and continuous monitoring tools.
- Knowledge of NIST SP 800-37, NIST SP 800-53A, FIPS 199, FIPS 200, SOC 2, or ISO 27001.
- Experience with third-party assessments or 3PAOs and certifications such as CISSP, CISM, CAP/CGRC, Security+, or CCSP.
Culture & Benefits
- 100% remote work for eligible US-based candidates, with a hybrid option in the Chicago metropolitan area.
- Medical, dental, and vision coverage, including domestic partnerships.
- Employer-paid life insurance and supplemental life insurance options.
- Voluntary short- and long-term disability insurance and a Roth or traditional 401(k).
- Generous paid time off, including bereavement and jury duty leave, plus above-market annual bonuses.
- Responsible use of AI-enabled tools such as Claude or ChatGPT is supported for research, control analysis, documentation, and workflow efficiency.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →
Похожие вакансии
2 дня назад
Senior Security Engineer (Cybersecurity)
13 часов назад
Information Systems Security Engineer (Cybersecurity)
128 887 - 180 000$
13 часов назад
Information Systems Security Engineer (ISSE)
112 075 - 160 000$
14 часов назад
Senior Cybersecurity Engineer (US Federal)
159 600 - 239 400$
7 дней назад
Staff Vulnerability Management Engineer (Cybersecurity)
2 дня назад
Principal Cybersecurity Engineer (US Federal)
184 800 - 277 200$