Information System Security
Job in
Washington, District of Columbia, 20022, USA
Listed on 2026-10-05
Listing for:
Aderas,-Inc
Full Time
position Listed on 2026-10-05
Job specializations:
-
IT/Tech
Cybersecurity, Information Security & Data Protection
Job Description & How to Apply Below
Summary:
Provide hands-on ISSO support across the full system lifecycle (initiation through disposal) for systems within and interconnected to the Client Enterprise General Support System (GSS) boundary, including Client-managed FedRAMP-authorized cloud subscriptions operating under shared responsibility and inherited-controls context, by producing accurate, current, audit-ready RMF and continuous monitoring artifacts and coordinating effectively with technical teams and federal stakeholders.
Primary Responsibilities (outcome-focused)- RMF & authorization support:
- Develop, update, and maintain RMF and authorization-package artifacts in CSAM/JCAM as designated by client, ensuring Government/assessor evidence needs are met for ATO activities, ongoing audits, and operational reviews.
- Support 3
PAO/security assessment activities by organizing evidence, responding to requests for information, and preparing the system team for reviews/testing events
- Documentation quality:
- Produce deliverables that are complete, accurate, timely, professionally prepared, and audit-ready; ensure artifacts are current and free of defects such as outdated/inapplicable citations and broken references.
- Maintain clear traceability between controls, implementations, evidence, findings, and POA&M entries to support defensible security posture reporting.
- Continuous monitoring & posture:
- Execute continuous monitoring activities (e.g., monthly/quarterly evidence collection, patch/configuration compliance reporting, vulnerability status reporting) and help maintain metrics and reporting inputs.
- Support security posture management tasks and recurring operational security reporting needs as directed.
- Vulnerability & POA&M support:
- Coordinate vulnerability management workflows and support POA&M development, updates, milestone tracking, and risk narratives to enable remediation and posture reporting.
- Track findings through closure support activities, ensuring POA&M records remain accurate and usable for governance and risk reporting.
- SIA & change coordination:
- Coordinate Security Impact Analyses (SIA) for planned changes (software releases, infrastructure changes, cloud service modifications).
- Ensure CM/RMF alignment: update SSP/control implementations, update diagrams/inventories, identify control/evidence impacts, and route changes through governance boards as required (e.g., CCB).
- Validate change evidence (approvals, test results, scanning results) is captured and traceable in CSAM/JCAM.
- Assess whether proposed or implemented changes constitute a significant security change and identify any required control reassessment, authorization-artifact updates, or follow‑on security actions.
- Incident coordination (ISSO scope):
- Support incident response within ISSO scope by coordinating with SOC/IR teams to collect artifacts, document timelines, and ensure RMF impacts are recorded (control deviations, compensating controls, required notifications).
- Track incident‑related corrective actions as POA&M(s) (or equivalent) and support closure evidence collection.
- Assist with after‑action reporting inputs and continuous monitoring updates resulting from incidents.
- Provide system‑boundary, authorization/control, and log‑verification context to support SOC/IR activities. This position provides ISSO‑level incident coordination and does not replace SOC monitoring, threat hunting, forensics, malware analysis, or dedicated incident‑response functions.’ This keeps the role boundary clear for candidates.
- Governance integration:
- Coordinate with System Owners/CCPs and the Privacy Office (for PII systems) within the Client governance structure, contributing recommendations, analysis, and documentation. 5
- Operate in a non‑inherently governmental capacity:…
To View & Apply for jobs on this site that accept applications from your location or country, tap the button below to make a Search.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
Search for further Jobs Here:
×