Information System Security Officer (ISSO)

Posted Yesterday
Be an Early Applicant
46 Locations
In-Office or Remote
110K-231K Annually
Senior level
Information Technology • Legal Tech • Analytics
The Role
Leads security compliance for a FedRAMP-authorized cloud environment. Maintains the ATO, coordinates continuous monitoring, assessments, audits, penetration testing, risk reviews, POA&M remediation, security documentation, and NIST control implementation. Partners with engineering, DevOps, cloud operations, compliance, and government stakeholders to support incident response, secure system changes, cloud deployments, and audit readiness.
Summary Generated by Built In

Are you passionate about driving security compliance in complex cloud environments and helping organizations maintain trusted relationships with government stakeholders?


Do you enjoy collaborating across engineering, security, and operations teams to deliver secure, compliant solutions that make a meaningful impact?


About the Business

LexisNexis® Risk Solutions provides customers with solutions and decision tools that combine public and industry specific content with advanced technology and analytics to assist them in evaluating and predicting risk and enhancing operational efficiency. We use the power of data and advanced analytics to help our customers make better, timelier decisions. By bringing clarity to information, we ultimately help make communities safer, insurance rates more accurate, commerce more transparent, business decisions easier and processes more efficient.

You can learn more about LexisNexis Risk at

https://risk.lexisnexis.com/


About our team

Our team is composed of highly technical professionals who thrive on solving complex security, cloud, and compliance challenges. We foster a collaborative, engineering-focused culture where team members are empowered to lead difficult initiatives, drive innovation, and deliver outcomes in highly regulated environments.


About the Role

We are seeking an experienced Information System Security Officer (ISSO) to lead and maintain the security and compliance posture of our recently obtained FedRAMP-authorized cloud environment. The ISSO will serve as the primary security compliance lead responsible for ensuring ongoing adherence to FedRAMP, NIST 800-53, FISMA, and organizational security requirements. This role will partner with Engineering, Cloud Operations, DevOps, Product, and Compliance teams to maintain authorization, manage continuous monitoring activities, support audits and assessments, and drive security improvements across the platform. The ideal candidate combines strong cybersecurity knowledge with hands-on experience managing FedRAMP-authorized systems in cloud environments such as Azure, AWS, or GCP.


Key Responsibilities

FedRAMP Program Management

  • Serve as the designated ISSO for FedRAMP-authorized systems.
  • Maintain the organization's Authority to Operate (ATO) and support ongoing compliance activities.
  • Lead FedRAMP continuous monitoring activities, including monthly, quarterly, and annual reporting requirements.
  • Coordinate annual assessments, independent audits, penetration testing, and security reviews with Third Party Assessment Organizations (3PAOs).
  • Manage security-related communications with federal agencies, sponsoring organizations, and stakeholders.

Risk & Security Management

  • Conduct security risk assessments and vulnerability analyses.
  • Review, assess, and monitor Plan of Action & Milestones (POA&M) items through remediation.
  • Evaluate security impacts of system changes and support Significant Change Request (SCR) submissions.
  • Ensure proper implementation and effectiveness of NIST 800-53 security controls.
  • Facilitate security reviews for architecture changes, new technologies, and cloud deployments.

Compliance & Documentation

  • Maintain FedRAMP security documentation including:
    • System Security Plan (SSP),
    • Security Assessment Reports (SAR)
    • POA&M
    • Configuration Management Plan
    • Incident Response Plan
    • Continuous Monitoring Strategy
    • Contingency Planning Documentation
  • Review and approve security documentation updates resulting from system changes.
  • Ensure evidence collection and compliance artifacts are complete and audit-ready.

Continuous Monitoring

  • Manage POA&M deliverables for the sponsor.
  • Monitor security events, incidents, and compliance metrics.
  • Validate remediation efforts for identified security findings.
  • Ensure required security assessments are completed according to established schedules.
  • Track compliance KPIs and report status to leadership.

Security Operations & Incident Response

  • Participate in security incident investigations and response efforts.
  • Coordinate with security operations teams to ensure timely identification and remediation of threats.
  • Support root cause analysis and corrective action planning following incidents.
  • Review security monitoring tools and processes to improve detection and response capabilities.

Cross-Functional Collaboration

  • Partner with Engineering and DevOps teams to integrate compliance into system development and deployment processes.
  • Provide security guidance throughout the SDLC.
  • Support cloud migration, modernization, and technology transformation initiatives.
  • Ensure compliance and security awareness training meet FedRAMP requirements.
  • Matrix manage resources participating in the FedRAMP Program.

Required Qualifications

Education

  • Bachelor's degree in Cybersecurity, Information Systems, Computer Science, Engineering, or related field.
  • Equivalent work experience may be considered in lieu of degree requirements.

Experience

  • 5+ years of information security, cybersecurity, or compliance experience.
  • 3+ years supporting FedRAMP, FISMA, or federal compliance programs.
  • Experience maintaining FedRAMP Moderate or High authorized environments.
  • Experience supporting security assessments, audits, and continuous monitoring activities.
  • Experience with cloud platforms such as AWS, Azure, or Google Cloud.

Technical Knowledge

  • Strong understanding of:
    • FedRAMP requirements
    • NIST SP 800-53
    • NIST 800-37 Risk Management Framework (RMF)
    • FISMA
    • NIST 800-171
    • Zero Trust Architecture principles
    • Vulnerability management processes
    • Security operations and incident response
  • Familiarity with security technologies including:
    • SIEM platforms
    • Vulnerability scanners
    • Endpoint detection and response (EDR)
    • Identity and Access Management (IAM)
    • Cloud-native security services

Preferred Qualifications

  • CISSP, CISM, GSLC, CAP, or equivalent cybersecurity certification.
  • FedRAMP-specific experience acting as:
    • ISSO
    • Security Compliance Manager
    • FedRAMP Program Manager
  • Experience supporting federal agencies or government contractors.
  • Knowledge of automated compliance platforms and Governance, Risk, and Compliance (GRC) tools.
  • Experience leveraging AI and automation to streamline compliance reporting, evidence collection, and POA&M management.
  • Experience with AWS GovCloud or Azure Government environments.
U.S. National Base Pay Range: $115,400 - $192,300. Geographic differentials may apply in some locations to better reflect local market rates. If performed in Colorado, the base pay range is $115,400 - $192,300.If performed in Illinois, the base pay range is $121,200 - $201,900.If performed in Chicago, IL, the base pay range is $126,900 - $211,500.If performed in Maryland, the base pay range is $121,200 - $201,900.If performed in New York, the base pay range is $126,900 - $211,500.If performed in New York City, the base pay range is $138,400 - $230,700.If performed in Rochester, NY, the base pay range is $115,400 - $192,300.If performed in New Jersey, the base pay range is $136,213 - $217,587.If performed in Ohio, the base pay range is $109,500 - $182,700. This job is eligible for an annual incentive bonus. Application deadline is 12/24/2026.

We know your well-being and happiness are key to a long and successful career. We are delighted to offer country specific benefits. Click here to access benefits specific to your location.

We are committed to providing a fair and accessible hiring process. If you have a disability or other need that requires accommodation or adjustment, please let us know by completing our Applicant Request Support Form or please contact 1-855-833-5120.

Criminals may pose as recruiters asking for money or personal information. We never request money or banking details from job applicants. Learn more about spotting and avoiding scams here.

Please read our Candidate Privacy Policy.

We are an equal opportunity employer: qualified applicants are considered for and treated during employment without regard to race, color, creed, religion, sex, national origin, citizenship status, disability status, protected veteran status, age, marital status, sexual orientation, gender identity, genetic information, or any other characteristic protected by law.

USA Job Seekers:

EEO Know Your Rights.

Skills Required

  • Bachelor's degree in Cybersecurity, Information Systems, Computer Science, Engineering, or a related field, or equivalent work experience
  • 5+ years of information security, cybersecurity, or compliance experience
  • 3+ years supporting FedRAMP, FISMA, or federal compliance programs
  • Experience maintaining FedRAMP Moderate or High authorized environments
  • Experience supporting security assessments, audits, and continuous monitoring activities
  • Experience with AWS, Azure, or Google Cloud
  • Understanding of FedRAMP, NIST SP 800-53, NIST 800-37 RMF, FISMA, NIST 800-171, and Zero Trust Architecture
  • Knowledge of vulnerability management, security operations, and incident response
  • Familiarity with SIEM platforms, vulnerability scanners, EDR, IAM, and cloud-native security services
  • CISSP, CISM, GSLC, CAP, or equivalent cybersecurity certification
  • Experience acting as an ISSO, Security Compliance Manager, or FedRAMP Program Manager
  • Experience supporting federal agencies or government contractors
  • Knowledge of automated compliance platforms and GRC tools
  • Experience with AI and automation for compliance reporting, evidence collection, and POA&M management
  • Experience with AWS GovCloud or Azure Government

RELX Compensation & Benefits Highlights

The following summarizes recurring compensation and benefits themes identified from responses generated by popular LLMs to common candidate questions about RELX and has not been reviewed or approved by RELX.

  • Retirement Support — Retirement support is positioned as a meaningful part of total rewards through a 401(k) plan with matching contributions, alongside other financial protections such as life and disability coverage. Tuition reimbursement and share purchase access further broaden the financial value of the package beyond base salary.
  • Leave & Time Off Breadth — Leave and time off breadth appears strong, with generous vacation allowances, mental health days, and options like sabbaticals and tiered PTO by tenure. Parental and caregiving leaves are described in detail, reinforcing time-away benefits as a standout component of the overall package.
  • Wellbeing & Lifestyle Benefits — Wellbeing and lifestyle benefits are supported by offerings such as mental health support (e.g., app access), EAP resources, gym-related perks, and wellness incentives. Flexible working hours and related work-life supports add to the perceived day-to-day value of benefits.

RELX Insights

Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
HQ: London
10,001 Employees
Year Founded: 1880

What We Do

RELX is a global provider of information-based analytics for professional and business customers across industries. We help scientists make new discoveries, doctors and nurses improve the lives of patients and lawyers win cases. We prevent online fraud and money laundering, and help insurance companies evaluate and predict risk. Our events enable customers to learn about markets, source products and complete transactions. In short, we enable our customers to make better decisions, get better results and be more productive. We do this by leveraging a deep understanding of our customers to create innovative solutions which combine content and data with analytics and technology in global platforms. RELX serves customers in more than 180 countries and has offices in about 40 countries. It employs approximately 30,000 people of whom almost half are in North America. We operate in four major market segments: Scientific, Technical & Medical; Risk & Business Analytics; Legal; and Exhibitions.

Similar Jobs

Applied Systems Logo Applied Systems

Sr. Manager, Data Engineering

Artificial Intelligence • Cloud • Payments • Software • Business Intelligence • Generative AI • Automation
Remote or Hybrid
United States
3116 Employees
135K-185K Annually

Digible Logo Digible

Account Manager

AdTech • Agency • Artificial Intelligence • Digital Media • Marketing Tech • Social Media • PropTech
Remote or Hybrid
United States
145 Employees
87K-100K Annually

Xero Logo Xero

Consultant

Cloud • Fintech • Information Technology • Machine Learning • Software
Remote or Hybrid
United States
4500 Employees
79K-89K Annually

Samsara Logo Samsara

Manager, Enterprise Customer Success - Select

Artificial Intelligence • Cloud • Computer Vision • Hardware • Internet of Things • Software
Easy Apply
Remote or Hybrid
United States
4000 Employees
126K-169K Annually

Similar Companies Hiring

NODA AI Thumbnail
Artificial Intelligence • Information Technology • Software • Cybersecurity
Sydney, AU
54 Employees
Legora Thumbnail
Artificial Intelligence • Legal Tech • Software
New York, New York
900 Employees
Golden Pet Brands Thumbnail
Digital Media • eCommerce • Information Technology • Marketing Tech • Pet • Retail • Social Media
El Segundo, California
178 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account