Senior Information System Security Officer (Senior ISSO) in Abbeyville, Colorado at Jobgether
Explore Related Opportunities
Job Description
This position is listed on behalf of a partner company, who manages all applications and next steps. Our partner is looking for a Senior Information System Security Officer (Senior ISSO) based in the United States.
This role provides cybersecurity leadership for critical information systems supporting federal mission environments.
You will serve as a trusted security advisor, guiding organizations through Risk Management Framework (RMF) activities and continuous authorization processes.
The position combines cybersecurity governance, technical coordination, documentation management, and risk management expertise.
You will collaborate with system owners, engineering teams, security professionals, and government stakeholders to strengthen security posture.
Your work will directly support compliance, vulnerability remediation, and operational readiness across complex environments.
This is an opportunity to contribute to impactful cybersecurity programs while helping mature enterprise security practices.
The Senior Information System Security Officer will oversee cybersecurity operations for assigned systems throughout their lifecycle, ensuring compliance with federal security standards and maintaining authorization readiness. This role requires strong RMF expertise, excellent coordination abilities, and the capability to align technical teams around effective security practices.
- Serve as the primary cybersecurity advisor for assigned information systems and support security activities throughout the system lifecycle.
- Lead Risk Management Framework (RMF) activities, including system authorization, ongoing authorization, annual assessments, and continuous monitoring.
- Coordinate with system owners, authorizing officials, engineering teams, business stakeholders, and government personnel to maintain security readiness.
- Develop, maintain, and update System Security Plans (SSPs), authorization packages, security documentation, and RMF artifacts.
- Coordinate security control implementation, evidence collection, documentation updates, and assessment preparation.
- Track vulnerabilities, Plans of Action and Milestones (POA&Ms), risk acceptance decisions, and remediation activities.
- Partner with vulnerability management teams to prioritize findings and ensure accurate reporting of security risks.
- Support incident response coordination by incorporating security events, corrective actions, and lessons learned into security documentation.
- Coordinate Security Control Assessments (SCAs), independent assessments, audits, and oversight activities.
- Review assessment findings and collaborate with technical teams to drive remediation and strengthen security controls.
- Support security architecture initiatives, Zero Trust implementation, and continuous monitoring strategies.
- Maintain required privacy, contingency planning, incident response, and interconnection security documentation.
- Prepare cybersecurity status reports, risk summaries, and executive-level updates for stakeholders.
- Mentor junior security professionals and promote consistent application of RMF processes and cybersecurity best practices.
- Participate in governance meetings, risk reviews, change management discussions, and operational planning activities.
- Identify opportunities to improve security processes, documentation quality, and operational efficiency across cybersecurity programs.
The ideal candidate brings extensive experience supporting federal cybersecurity programs, RMF processes, and security authorization activities. This role requires strong knowledge of government security standards, excellent communication skills, and the ability to coordinate complex cybersecurity initiatives across multiple teams.
- Bachelor’s degree in Cybersecurity, Information Systems, Information Technology, Computer Science, or a related discipline.
- Five or more years of experience serving as an Information System Security Officer (ISSO) or supporting federal RMF and Assessment & Authorization (A&A) programs.
- Demonstrated experience supporting all phases of the NIST Risk Management Framework, including system categorization, security control implementation, assessment, authorization, and continuous monitoring.
- Strong understanding of NIST SP 800-37, NIST SP 800-53 Rev. 5, NIST SP 800-53A, FISMA, and federal cybersecurity policies.
- Experience developing and maintaining authorization documentation, including SSPs, Security Assessment Reports (SARs), POA&Ms, contingency plans, and supporting artifacts.
- Experience coordinating cybersecurity activities with system owners, security engineers, vulnerability management teams, auditors, and government stakeholders.
- Strong written and verbal communication skills with the ability to manage complex security initiatives across multiple organizations.
- Ability to analyze cybersecurity risks, recommend mitigation strategies, and support security decision-making.
- Experience supporting continuous monitoring, vulnerability management, and security compliance activities.
Preferred qualifications include:
- Experience supporting federal civilian agencies, healthcare agencies, or large government environments.
- Experience using governance, risk, and compliance platforms such as JCAM, eMASS, ServiceNow GRC, Archer, or similar tools.
- Experience supporting cloud-based systems, High Value Assets (HVAs), or enterprise shared services.
- Familiarity with Zero Trust architecture, cybersecurity engineering practices, and continuous diagnostics.
- Experience supporting FISMA reporting, audit responses, and annual security assessments.
- Experience working in Agile development environments.
- Relevant certifications such as:
- Certified in Governance, Risk and Compliance (CGRC)
- Certified Information Systems Security Professional (CISSP)
- Certified Authorization Professional (CAP)
- Certified Information Security Manager (CISM)
- Security+
- Project Management Professional (PMP)
- Competitive salary paid twice per month.
- Comprehensive medical coverage with 100% of medical premiums covered.
- Company-wide incentive programs tied to business growth.
- Opportunities to contribute through technical publications, webinars, and knowledge-sharing initiatives.
- Three weeks of paid time off (PTO) plus 11 paid holidays annually.
- 401(k) program with 100% company match on the first 4%.
- Monthly reimbursement support for mobile phone and home internet expenses.
- Paid parental leave.
- Investment in professional training, certifications, and career development opportunities.
- Opportunity to work on impactful cybersecurity programs supporting critical missions.