×
Register Here to Apply for Jobs or Post Jobs. X

Information System Security

Job in Washington, District of Columbia, 20022, USA
Listing for: Aderas,-Inc
Full Time position
Listed on 2026-10-05
Job specializations:
  • IT/Tech
    Cybersecurity, Information Security & Data Protection
Salary/Wage Range or Industry Benchmark: 120000 - 160000 USD Yearly USD 120000.00 160000.00 YEAR
Job Description & How to Apply Below
Mission / Role

Summary:

Provide hands-on ISSO support across the full system lifecycle (initiation through disposal) for systems within and interconnected to the Client Enterprise General Support System (GSS) boundary, including Client-managed FedRAMP-authorized cloud subscriptions operating under shared responsibility and inherited-controls context, by producing accurate, current, audit-ready RMF and continuous monitoring artifacts and coordinating effectively with technical teams and federal stakeholders.

Primary Responsibilities (outcome-focused)
  • RMF & authorization support:
    • Develop, update, and maintain RMF and authorization-package artifacts in CSAM/JCAM as designated by client, ensuring Government/assessor evidence needs are met for ATO activities, ongoing audits, and operational reviews.
    • Support 3

      PAO/security assessment activities by organizing evidence, responding to requests for information, and preparing the system team for reviews/testing events
  • Documentation quality:
    • Produce deliverables that are complete, accurate, timely, professionally prepared, and audit-ready; ensure artifacts are current and free of defects such as outdated/inapplicable citations and broken references.
    • Maintain clear traceability between controls, implementations, evidence, findings, and POA&M entries to support defensible security posture reporting.
  • Continuous monitoring & posture:
    • Execute continuous monitoring activities (e.g., monthly/quarterly evidence collection, patch/configuration compliance reporting, vulnerability status reporting) and help maintain metrics and reporting inputs.
    • Support security posture management tasks and recurring operational security reporting needs as directed.
  • Vulnerability & POA&M support:
    • Coordinate vulnerability management workflows and support POA&M development, updates, milestone tracking, and risk narratives to enable remediation and posture reporting.
    • Track findings through closure support activities, ensuring POA&M records remain accurate and usable for governance and risk reporting.
  • SIA & change coordination:
    • Coordinate Security Impact Analyses (SIA) for planned changes (software releases, infrastructure changes, cloud service modifications).
    • Ensure CM/RMF alignment: update SSP/control implementations, update diagrams/inventories, identify control/evidence impacts, and route changes through governance boards as required (e.g., CCB).
    • Validate change evidence (approvals, test results, scanning results) is captured and traceable in CSAM/JCAM.
    • Assess whether proposed or implemented changes constitute a significant security change and identify any required control reassessment, authorization-artifact updates, or follow‑on security actions.
  • Incident coordination (ISSO scope):
    • Support incident response within ISSO scope by coordinating with SOC/IR teams to collect artifacts, document timelines, and ensure RMF impacts are recorded (control deviations, compensating controls, required notifications).
    • Track incident‑related corrective actions as POA&M(s) (or equivalent) and support closure evidence collection.
    • Assist with after‑action reporting inputs and continuous monitoring updates resulting from incidents.
    • Provide system‑boundary, authorization/control, and log‑verification context to support SOC/IR activities. This position provides ISSO‑level incident coordination and does not replace SOC monitoring, threat hunting, forensics, malware analysis, or dedicated incident‑response functions.’ This keeps the role boundary clear for candidates.
  • Governance integration:
    • Coordinate with System Owners/CCPs and the Privacy Office (for PII systems) within the Client governance structure, contributing recommendations, analysis, and documentation. 5
    • Operate in a non‑inherently governmental capacity:…
To View & Apply for jobs on this site that accept applications from your location or country, tap the button below to make a Search.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
 
 
 
Search for further Jobs Here:
(Try combinations for better Results! Or enter less keywords for broader Results)
Location
Increase/decrease your Search Radius (miles)
0
200
Filters
Education Level
Experience Level (years)
Posted in last:
Salary