Information System Security Officer; ISSO
South Portland, Cumberland County, Maine, 04106, USA
Listed on 2026-10-02
-
IT/Tech
Cybersecurity
Boca Raton, FL (Yamato)
Home based-Iowa
Home based-Idaho
Home based-Illinois
Home based-Kansas
Home based-Kentucky
Home based-Minnesota
Home based-Louisiana
Home based-Montana
Home based-Connecticut
Home based-Georgia
Home based-Indiana
Home based-Rhode Island
Home based-Nebraska
Home based-Tennessee
Home based-New Mexico
Home based-Virginia
Home based-Ohio
Home based-Wisconsin
Home based-North Carolina
Home based-Missouri
Home based-North Dakota
Home based-Maine
Home based-Michigan
Home based-Mississippi
Home based-New Hampshire
Home based-Utah
Home based-New Jersey
Home based-Vermont
Home based-Washington
Home based-West Virginia
Home based-Nevada
Home based-Wyoming
Home based-New York
Home based-Oklahoma
Home based-Massachusetts
Home based-Pennsylvania
Home based-South Carolina
Home based-South Dakota
Home based-Texas
Home based-Maryland
Home based-Oregon
Home based-Arkansas
Home Based-Alabama
Home based-Arizona
Home based-Colorado
Home based-Delaware
Full time
R117439
Are you passionate about driving security compliance in complex cloud environments and helping organizations maintain trusted relationships with government stakeholders?
Do you enjoy collaborating across engineering, security, and operations teams to deliver secure, compliant solutions that make a meaningful impact?
About the BusinessLexis Nexis® Risk Solutions provides customers with solutions and decision tools that combine public and industry specific content with advanced technology and analytics to assist them in evaluating and predicting risk and enhancing operational efficiency. We use the power of data and advanced analytics to help our customers make better, timelier decisions. By bringing clarity to information, we ultimately help make communities safer, insurance rates more accurate, commerce more transparent, business decisions easier and processes more efficient.
You can learn more about Lexis Nexis Risk at
About our teamOur team is composed of highly technical professionals who thrive on solving complex security, cloud, and compliance challenges. We foster a collaborative, engineering-focused culture where team members are empowered to lead difficult initiatives, drive innovation, and deliver outcomes in highly regulated environments.
About the RoleWe are seeking an experienced Information System Security Officer (ISSO) to lead and maintain the security and compliance posture of our recently obtained FedRAMP-authorized cloud environment. The ISSO will serve as the primary security compliance lead responsible for ensuring ongoing adherence to FedRAMP, NIST 800-53, FISMA, and organizational security requirements. This role will partner with Engineering, Cloud Operations, Dev Ops, Product, and Compliance teams to maintain authorization, manage continuous monitoring activities, support audits and assessments, and drive security improvements across the platform.
The ideal candidate combines strong cybersecurity knowledge with hands‑on experience managing FedRAMP-authorized systems in cloud environments such as Azure, AWS, or GCP.
Serve as the designated ISSO for FedRAMP-authorized systems.
Maintain the organization's Authority to Operate (ATO) and support ongoing compliance activities.
Lead FedRAMP continuous monitoring activities, including monthly, quarterly, and annual reporting requirements.
Coordinate annual assessments, independent audits, penetration testing, and security reviews with Third Party Assessment Organizations (3
PAOs).Manage security-related communications with federal agencies, sponsoring organizations, and stakeholders.
Conduct security risk assessments and vulnerability analyses.
Review, assess, and monitor Plan of Action & Milestones (POA&M) items through remediation.
Evaluate security impacts of system changes and support Significant Change Request (SCR) submissions.
Ensure proper implementation and effectiveness of NIST 800-53 security controls.
Facilitate security reviews for architecture changes, new technologies, and cloud deployments.
Maintain FedRAMP security documentation including:
System Security Plan (SSP),
Security Assessment Reports (SAR)
POA&M
Configuration Management Plan
Incident Response Plan
Continuous Monitoring Strategy
Contingency Planning Documentation
Review and approve security documentation updates resulting from system changes.
Ensure evidence collection and compliance artifacts are complete and audit-ready.
Manage POA&M deliverables for the…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).