Information System Security Officer (ISSO) in New York at Jobgether
Explore Related Opportunities
Job Description
This position is listed on behalf of a partner company, who manages all applications and next steps. Our partner is looking for an Information System Security Officer (ISSO) based in the United States.
This role is responsible for protecting mission-critical government information systems while ensuring rigorous compliance with federal cybersecurity requirements.
You’ll serve as a central security point of contact, partnering with system owners, IT stakeholders, cybersecurity teams, and senior leadership.
The position offers broad ownership across the Risk Management Framework (RMF), Authority to Operate (ATO) processes, security controls, and continuous monitoring.
You’ll develop and maintain essential security documentation, assess risks, coordinate remediation, and support audits and security assessments.
Your expertise will directly contribute to maintaining secure, resilient systems aligned with FISMA, NIST, DHS, and related federal directives.
This is a fully remote opportunity with no required travel and an environment focused on integrity, technical excellence, collaboration, and continuous learning.
The role is well suited to an experienced security professional who enjoys combining hands-on cybersecurity expertise with strategic advisory responsibilities.
- Serve as the primary information security point of contact for assigned systems and Program Management Organizations, supporting cybersecurity engineering and compliance activities.
- Execute end-to-end RMF activities supporting ATO decisions, including system categorization, security control selection and implementation, self-assessments, POA&M development, and continuous monitoring.
- Develop and maintain System Security Plans (SSPs), including control baselines, control inheritance, Business Impact Analyses, implementation statements, technical and system descriptions, and hardware and software inventories.
- Develop and maintain Configuration Management Plans and conduct Security Impact Analyses for system and configuration changes.
- Review and approve Change Requests while documenting the cybersecurity impact of proposed configuration changes.
- Develop, maintain, and test Contingency Plans and Incident Response Plans to support system resilience and business continuity.
- Conduct or support annual risk assessments, security assessments, vulnerability assessments, audits, and other cybersecurity reviews.
- Advise system owners, stakeholders, and senior executives on cybersecurity risks, compliance requirements, remediation strategies, and security best practices.
- Develop remediation work plans to address assessment, audit, and compliance findings and track progress through resolution.
- Maintain accurate hardware and software inventory records and perform FISMA scorecard analysis.
- Ensure appropriate access controls are implemented and maintained for system users and resources.
- Research and evaluate emerging security technologies, processes, practices, tools, and countermeasures designed to protect networks, devices, applications, and data.
- Maintain current knowledge of cybersecurity threats and vulnerabilities, including encryption, network and device security, vulnerability exploitation, and data protection techniques.
- Support compliance with FISMA, NIST standards, DHS 4300 Series requirements, and applicable DHS and component-level directives.
- U.S. citizenship is required.
- Bachelor’s degree plus at least 7 years of applicable information security experience.
- Minimum 7 years of professional experience in information security, cybersecurity, or a closely related field.
- Demonstrated expertise with the Risk Management Framework (RMF), information security processes, audits, security tools, implementation activities, FISMA, NIST, and IT security.
- Proven experience developing and maintaining System Security Plans (SSPs), Plans of Action and Milestones (POA&Ms), and Configuration Management Plans.
- Strong knowledge of NIST SP 800-37, NIST SP 800-53, and DHS 4300 Series requirements.
- DHS EOD suitability is preferred, as is current DHS EOD status.
- Strong analytical, organizational, documentation, and communication skills, with the ability to advise both technical stakeholders and senior leaders.
- Ability to manage multiple security, compliance, and risk activities while maintaining accurate and timely documentation.
- CISSP, CISM, or CompTIA Security+ / CASP+ equivalent qualification is desirable, particularly an Information Assurance Technician Level III certification.
- Previous DHS experience is a plus.
- Experience with GRC platforms such as CSAM, RegScale, eMASS, or comparable tools is preferred.
- Experience supporting emergency operations or disaster response missions is advantageous.
- Knowledge of cloud security and FedRAMP authorization processes is a plus.
- Experience with continuous monitoring and ongoing security assessment activities is desirable.
- Fully remote position available across the United States.
- No required travel.
- Competitive national salary range of $90,300–$189,600 USD, with final compensation based on factors including location, experience, skills, education, certifications, and applicable federal contract requirements.
- Comprehensive healthcare and wellness benefits.
- Retirement and financial benefits designed to support long-term financial well-being.
- Flexible time-off benefits designed to support work-life balance.
- Family support benefits and resources.
- Continuing education, professional development, and learning opportunities.
- Opportunities to contribute to high-impact federal missions focused on national security and public service.
- A collaborative culture emphasizing integrity, innovation, trust, autonomy, and continuous professional growth.