Point your AI agent at freehire and let it find you a job.

Get the CLI →

QBA

NewBe an early applicant

Information System Security Officer

Posted
Discussion

Summary

An Information System Security Officer maintains the security posture, RMF/ATO compliance, and continuous monitoring for a large-scale federal system modernization program underpinning U.S. capital markets, built on AWS. Day to day: NIST SP 800-53/FedRAMP evidence management, POA&M tracking, security assessments, and coordination with client security and DevSecOps teams.

Compensation: $200k – $220k • No equity

We are building a team for one of the U.S. Federal Government's largest technology modernization programs, underpinning the U.S. capital markets.

Built on AWS and leveraging an AI-powered software engineering platform, this program offers a unique opportunity to gain hands-on experience with next-generation AI, Agentic AI, cloud technologies, and AI-driven engineering.

If you are looking for technically challenging work, exceptional learning, and a résumé-defining opportunity with national impact, I would love to connect.

Job Title: ISSO

Position Type: Full-Time

Location: Hybrid (2 days onsite)

Days Remote: 3 days remote

Position Summary: The Developer serves as the Information System Security Officer responsible for maintaining the security posture, compliance, and authorization status of a large-scale federal information system. This role manages the Risk Management Framework lifecycle, maintains the system’s Authority to Operate documentation, and coordinates continuous-monitoring activities. The Developer works closely with client security leadership, security teams, and DevSecOps personnel to ensure continued compliance with NIST SP 800-53, FedRAMP, and applicable federal information-security requirements.

Key Responsibilities:

  • Maintain the system’s Risk Management Framework documentation and Authority to Operate package.
  • Manage and maintain security-control implementation evidence aligned with NIST SP 800-53 and FedRAMP requirements.
  • Track security findings and coordinate remediation activities through Plans of Action and Milestones.
  • Manage continuous-monitoring documentation, evidence, and reporting activities.
  • Support security assessments, compliance audits, system authorization reviews, and related security activities.
  • Coordinate with the client Information System Security Manager, security teams, and DevSecOps personnel on security and compliance requirements.
  • Review proposed system changes to assess potential security impacts.
  • Maintain approved system-security configurations and security baselines.
  • Report the system’s security posture, risks, findings, and incidents to program leadership and client stakeholders.

Minimum Experience:

  • 5+ years of information-system security or Information System Security Officer experience.
  • Experience supporting federal Risk Management Framework and Authority to Operate processes.
  • Experience managing continuous-monitoring activities and Plans of Action and Milestones.

Mandatory Skills:

  • Must have CISSP certification in good standing.
  • Information System Security Officer experience.
  • Federal information-system security.
  • Risk Management Framework.
  • Authority to Operate processes and documentation.
  • NIST SP 800-53 security controls.
  • Security-control implementation and evidence management.
  • Plans of Action and Milestones management.
  • Security assessments and audits.
  • Security authorization activities.
  • Security-baseline management.
  • Security-risk and incident reporting.
  • CISSP, CAP, or an equivalent security certification.
  • Non-technical Requirements:
  • U.S. work authorization.
  • Ability to obtain a Public Trust clearance.
  • Continuous monitoring.

Nice-to-Have Skills:

  • FedRAMP experience.
  • AWS cloud-security experience.
  • Financial-regulatory security experience.
  • Security automation experience.
  • Governance, Risk, and Compliance tooling experience.

Pay Rate Range: $200,000–$220,000

Degrees and Certifications:

Required: CISSP, CAP, or an equivalent security certification.

Skills

See also

Security jobs by country — openings, pay and top skills →

Tailor your CV for this role?

We couldn't check your fit for this role — add a CV to your profile to see it next time.

A new version of freehire is available