Information Systems Security Officer (ISSO), Mid

Posted 2 Days Ago
Be an Early Applicant
Washington, DC, USA
In-Office
105K-125K Annually
Mid level
Artificial Intelligence • Cybersecurity • Quantum Computing • Defense
The Role
Leads federal cybersecurity, privacy, and GRC activities across the NIST RMF lifecycle. Responsibilities include ATO support, authorization package development, risk assessments, vulnerability analysis, continuous monitoring, remediation tracking, privacy compliance, incident response, contingency planning, audit support, and stakeholder advising. The role requires producing audit-ready documentation and coordinating security and privacy initiatives with government and technical teams.
Summary Generated by Built In
Description

Quantum Sky is searching for an Information Systems Security Officer (ISSO), Mid to support a federal customer in Washington, DC. We are looking for a highly organized, proactive, and customer-focused cybersecurity professional who excels at building trusted relationships, communicating with both technical and executive stakeholders, and independently driving complex initiatives to successful completion.

The ideal candidate thrives in a fast-paced environment, embraces ownership and accountability, and consistently delivers high-quality work while balancing customer needs with federal security and privacy requirements. In this role, you will serve as a trusted advisor to government customers while leading information security, privacy, and Governance, Risk, and Compliance (GRC) activities to ensure federal systems remain secure, compliant, and mission-ready.

Responsibilities:

  • Lead and support information system security responsibilities throughout the Risk Management Framework (RMF) lifecycle, including Authorization to Operate (ATO), continuous monitoring, and integration of security, privacy, and legal requirements.
  • Develop, maintain, and present security authorization packages and supporting documentation in accordance with client requirements and NIST SP 800-53, including SSPPs, RARs, SAPs, SARs, POA&Ms, contingency and incident response plans, SOPs, configuration management plans, STIG deviations, and related artifacts.
  • Own security and privacy initiatives from planning through completion by proactively managing tasks, driving remediation efforts, validating corrective actions, and ensuring deliverables are completed accurately and on schedule.
  • Perform security and privacy risk assessments, analyze vulnerability scan results, recommend risk-based solutions, and support continuous monitoring activities across applications, infrastructure, and databases.
  • Serve as a trusted cybersecurity advisor to Contracting Officer Representatives (CORs), system owners, business stakeholders, and technical teams by communicating complex security and privacy requirements clearly, professionally, and with a customer-focused approach.
  • Develop, coordinate, test, and maintain contingency planning, incident response, privacy, and continuity activities, including PTAs, PIAs, HVA support, privacy training, and privacy-by-design integration throughout the System Development Life Cycle (SDLC).
  • Develop and maintain privacy policies, directives, SOPs, and operational guidance while ensuring compliance with applicable federal privacy laws, OMB guidance, NIST publications, CJIS Security Policy, and Legislative Branch requirements.
  • Build strong cross-functional relationships while managing multiple concurrent priorities in a fast-paced environment, identifying process improvements, and maintaining exceptional attention to detail across all security and compliance activities.
  • Coordinate with internal and external stakeholders to support audits, agency data calls, reporting requirements, asset inventories, and other compliance initiatives.
Qualifications

Required:

  • Bachelor's degree and at least four (4) years of relevant experience supporting cybersecurity, information assurance, or Governance, Risk, and Compliance (GRC) activities within the NIST Risk Management Framework (RMF) lifecycle.
    • High school diploma with 8 years of experience in Functional Responsibility area may be substituted for a Bachelor’s Degree
    • PMP, ISO 27001, or CISM certifications equate to 3 years of experience in Functional Responsibility each
    • ITIL, CISSP, or other relevant IT management certifications equate to 2 years of general experience each
  • Knowledge of and proficiency in federal government privacy programs, including the Privacy Act of 1974, the E-Government Act of 2002, and related federal privacy laws and regulations.
  • Demonstrated understanding of information privacy principles, including information access, release of information, and implementation of privacy controls for electronic and non-electronic information.
  • Experience supporting Cybersecurity Awareness Training (CSAT) privacy initiatives, including training development, effectiveness evaluation, and privacy awareness programs.
  • Experience with HR privacy and behavioral privacy considerations related to workforce data and monitoring activities.
  • Thorough knowledge of FISMA, NIST RMF, Security and Privacy Assessment & Authorization (SPA&A), NIST publications, OMB circulars and memoranda, and CNSS guidance.
  • Strong written and verbal communication skills with experience developing technical documentation, presenting complex security and privacy concepts to technical and non-technical audiences, and building trusted relationships with Contracting Officer Representatives (CORs), government leadership, and cross-functional stakeholders.
  • Demonstrated ability to lead end-to-end security and compliance initiatives by proactively managing competing priorities, driving deliverables to completion, and exercising sound judgment in a fast-paced, customer-focused environment.
  • Highly organized, detail-oriented, and self-motivated with strong analytical and critical thinking skills, a commitment to producing audit-ready documentation, and the ability to identify process improvements while balancing customer service with regulatory compliance.

Desired:

  • CRISC, CAP, CISSP, or equivalent
  • Experience with FedRAMP and cloud service providers
  • Experience with CSAM and ServiceNow
  • Experience with vulnerability assessment tools such as Nessus and/or Qualys
  • Policy writing background is highly preferred

Clearance:

  • US Citizen with Public Trust eligibility required

Location:

  • On-site in DC, minimal remote flexibility
About Quantum Sky

Compensation:

  • Compensation is unique to each candidate and relative to the skills and experience they bring to the position. The salary range for this position is typically between $105,000-$125,000. This does not guarantee a specific salary as compensation is based upon multiple factors such as education, experience, certifications, and other requirements, and may fall outside of the above-stated range.

Benefits:

  • Highlights of our benefits include Health/Dental/Vision, 401(k) match, Paid Time Off, STD/LTD/Life Insurance, Referral Bonuses, professional development reimbursement, and parental leave.

The world the mission operates in is going post-quantum, contested, and machine-speed. Quantum Sky engineers the advantage across cyber, networks, software, and quantum because the mission demands dominance, not parity. We don't follow the map. We draw it. 


At Quantum Sky, we believe that success starts with our people. We foster a collaborative, innovative, and mission-driven environment where every team member plays a critical role in shaping the future of technology. Are you ready to join #TeamQuantumSky? 


Quantum Sky Engineering LLC is an Equal Opportunity Employer; all qualified applicants will receive consideration for employment without regard to race, color, religion, sex, [sexual orientation, gender identity,] national origin, disability, status as a protected veteran, or any characteristic protected by applicable law.

Skills Required

  • Bachelor's degree and at least four years of relevant cybersecurity, information assurance, or GRC experience supporting the NIST RMF lifecycle
  • High school diploma with eight years of functional responsibility experience may substitute for a bachelor's degree
  • PMP, ISO 27001, or CISM certification may equate to three years of functional responsibility experience
  • ITIL, CISSP, or other relevant IT management certification may equate to two years of general experience
  • Knowledge of federal privacy programs, including the Privacy Act of 1974 and E-Government Act of 2002
  • Understanding of information privacy principles, information access, information release, and privacy controls
  • Experience supporting cybersecurity awareness training privacy initiatives and privacy awareness programs
  • Experience with HR privacy and behavioral privacy considerations for workforce data and monitoring
  • Knowledge of FISMA, NIST RMF, SPA&A, NIST publications, OMB guidance, and CNSS guidance
  • Strong written and verbal communication skills, technical documentation experience, and ability to present security and privacy concepts
  • Ability to lead security and compliance initiatives, manage competing priorities, and drive deliverables to completion
  • Strong organizational, analytical, critical-thinking, and process-improvement skills
  • CRISC, CAP, CISSP, or equivalent certification
  • Experience with FedRAMP and cloud service providers
  • Experience with CSAM and ServiceNow
  • Experience with Nessus and/or Qualys vulnerability assessment tools
  • Policy writing experience
  • US citizenship with Public Trust eligibility
  • Ability to work on-site in Washington, DC, with minimal remote flexibility
Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
969 Employees
Year Founded: 2018

What We Do

Quantum Sky is a Reston, Virginia-based mission technology company, formerly Tyto Athene, that delivers secure, AI-enabled and quantum-ready capabilities to defense, intelligence, and federal civilian agencies. Its work spans enterprise IT, network engineering, cybersecurity, cloud, software, post-quantum cryptography, and applied quantum technologies, helping customers modernize critical systems, protect mission data, and achieve faster, more resilient decision-making across complex, high-consequence missions.

Similar Jobs

Aceable Logo Aceable

Senior Analytics Engineer

eCommerce • Edtech • Insurance • Mobile • Real Estate • Software
Easy Apply
Remote or Hybrid
USA
140 Employees
140K-154K Annually

Imprivata Logo Imprivata

Regional Sales Manager

Healthtech • Information Technology • Security • Software • Cybersecurity
Remote or Hybrid
United States
1372 Employees
210K-320K Annually

Babylist Logo Babylist

Insurance Billing Specialist

eCommerce • Healthtech • Kids + Family • Retail • Social Media
Easy Apply
Remote or Hybrid
United States
300 Employees
66K-88K Annually

Altana Logo Altana

Account Executive

Artificial Intelligence • Machine Learning • Software
Easy Apply
Hybrid
3 Locations
228 Employees
150K-170K Annually

Similar Companies Hiring

Kepler  Thumbnail
Artificial Intelligence • Fintech • Software
New York, New York
9 Employees
Onshore Thumbnail
Artificial Intelligence • Fintech • Software • Financial Services
New York, New York
60 Employees
Blee Thumbnail
Artificial Intelligence • Marketing Tech • Software
New York, New York
30 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account