Intermediate ISSO
Listed on 2026-10-03
-
IT/Tech
Cybersecurity, Information Security & Data Protection
Job#: 3049549
Job Description:
Candidates must be U.S. citizens able to obtain and/or maintain a Department of Defense security clearance as a condition and continuation of employment.
Intermediate ISSOLocation: Washington, DC (Remote)
Clearance: Must be eligible to obtain/maintain a Secret clearance.
Role OverviewWe are seeking an Intermediate Information System Security Officer (ISSO) to support a federal government customer. The primary objective is to restore the security program, which has been neglected, by cleaning up existing compliance issues and stabilizing the environment. This role is central to remediation efforts and will involve enhancing automation to improve efficiency across approximately 90 systems. The position requires working with system owners and cybersecurity teams to manage security controls enterprise-wide, focusing on specific control families rather than individual systems.
Key Responsibilities- Execute Risk Management Framework (RMF) activities to support Authorization to Operate (ATO) decisions.
- Develop, maintain, and update security documentation, including System Security Plans (SSPs), Plan of Action and Milestones (POA&Ms), and Contingency Plans.
- Conduct security control assessments, vulnerability assessments, and Security Impact Analyses for system changes.
- Support continuous monitoring, vulnerability management, and POA&M tracking and remediation.
- Implement security controls to ensure the confidentiality, integrity, and availability of information systems in compliance with federal standards.
- Support change management processes, including participating in Change Advisory Board (CAB) reviews.
- Prepare for and support security audits, testing, and compliance reviews by providing necessary documentation.
- Respond to cybersecurity data calls with timely information for leadership.
- Organize responsibilities by security control areas (e.g., Access Control, Configuration Management) across all systems.
Education and Experience:
- Bachelor's Degree and 10+ years of relevant experience; or an Associate's Degree and 12+ years of experience; or 16+ years of experience with no degree.
- A minimum of 7 years of experience in Information Security or as an ISSO supporting federal systems.
- U.S. Citizenship is required.
- Candidates must reside within a local radius of Washington, D.C., and be available for occasional onsite work if requested.
- Hands-on experience with the RMF lifecycle and ATO activities.
- Strong knowledge of FISMA, NIST 800-37, NIST 800-53, and DHS 4300 Series.
- Experience developing and maintaining SSPs, POA&Ms, Contingency Plans, and other security artifacts.
- Background in conducting security control assessments and Security Impact Analyses.
- Proficiency in continuous monitoring, vulnerability management, and POA&M remediation.
- Strong technical writing skills for producing compliance and assessment documentation.
- Must hold a CISSP, CISM, or CASP+ certification.
- Experience supporting the Department of Homeland Security (DHS) or its components.
- Understanding of cloud security concepts, with experience in AWS or Azure.
- Experience with Governance, Risk, and Compliance (GRC) tools such as CSAM, eMASS, or Reg Scale.
This position is currently 100% remote. The immediate focus is on remediation and stabilization, with automation initiatives to follow. You will be part of a team-oriented environment focused on enterprise-wide security control management rather than system-specific assignments.
Everforth Apex is a world-class IT services company that serves thousands of clients across the globe. When you join Everforth Apex, you become part of a team that…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).