Information Systems Security Officer (ISSO), Senior

Anavation · Washington, DC

Spotted 1h agoFull Time
Job description

About this role

Employer-provided description, formatted for easier reading.

Be Challenged and Make a Difference

In a world of technology, people make the difference. We believe if we invest in great people, then great things will happen. At AnaVation, we provide unmatched value to our customers and employees through innovative solutions and an engaging culture.

Description of Task to be Performed

AnaVation is seeking a Senior-level ISSO to support a newly-awarded contract. The selected candidate must be able to excel as the sole ISSO to prepare a full accreditation package to quickly obtain ATT/ATO for a new digital evidence platform in support of our Federal Government client. This is a full-time position that can be performed remotely with occasional travel to Washington DC as needed.

What you will be doing Lead all RMF activities for the assigned system, including Categorization, Selection, Implementation, Assessment, Authorization, and Continuous Monitoring. Oversee the design, implementation, and validation of NIST 800-53 Rev 5 security and privacy controls across technical, operational, and management domains.

Develop, maintain, and update key security artifacts including System Security Plans (SSPs), Security Assessment Reports (SARs), POA&Ms, Incident Response Plans, and Continuous Monitoring strategies. Coordinate and support security control assessments (SCAs), penetration tests, vulnerability scans, and compliance audits.

Guide engineering teams on implementing and documenting new or updated security controls, ensuring they align with Rev 5 enhancements and control baselines. Evaluate system changes, architecture updates, and new integrations for security impact and required control modifications. Lead risk assessments, document findings, and track remediation through POA&M management.

Manage continuous monitoring activities, including log review, vulnerability management, patch tracking, and configuration baseline validation. Serve as the primary security liaison for system owners, internal stakeholders, external assessors, and authorizing officials (AOs). Assist in developing security control inheritance strategies from enterprise common controls, and ensure proper documentation and alignment.

Mentor junior ISSOs and analysts in RMF, control interpretation, documentation quality, and security best practices. Stay current on updates to NIST SP 800-53 Rev 5, 800-37, 800-30, and emerging federal cybersecurity guidance.

Interested in this role?Continue on Anavation's careers page.
Apply on Anavation