Senior Information Systems Security Officer

Posted 7 Days Ago
Be an Early Applicant
Washington, DC, USA
In-Office
Senior level
Software
The Role
The Senior Information Security Officer supports federal system authorization, continuous monitoring, compliance, and risk management. Responsibilities include maintaining SSPs, SARs, POA&Ms, SIAs, and other authorization artifacts; preparing systems for security assessments; validating technical controls and evidence; assessing change impacts; managing remediation, exceptions, audits, and risk acceptance; and producing dashboards, briefings, and reports. The role collaborates with engineers, architects, administrators, system owners, and governance stakeholders across on-premises and cloud environments.
Summary Generated by Built In

We are looking for a Senior Information System Security Officer (ISSO) to support a critical U.S. government agency in the National Capital Region. This role reports to the Security Program Management Office (SPMO) Manager and works directly with team members and Federal ISSOs to support authorization, compliance, continuous monitoring, and risk management activities across assigned systems.

This is an excellent opportunity for an experienced cybersecurity professional with a strong technical background to support the secure authorization and ongoing compliance of systems across on-premises and cloud environments. This is not a hands-on engineering position. Instead, the Senior ISSO leverages prior experience as a Systems Administrator, Cloud Engineer, Infrastructure Engineer, Network Engineer, Security Engineer, or similar technical role to independently validate security implementations, assess technical risk, and ensure authorization decisions are supported by accurate technical evidence. The successful candidate must be comfortable engaging engineers, architects, and system owners to validate security controls, identify inconsistencies, and challenge unsupported technical assumptions.
Hybrid: 3 Days On-site in Washington, DC / 2 Days Remote
Must be able to obtain a government security clearance requiring U.S. Citizenship or Permanent Resident Status

Responsibilities:

  • Support the security authorization lifecycle and ongoing continuous monitoring activities for assigned systems.
  • Develop, review, and maintain security documentation and authorization artifacts, including SSPs, SARs, POA&Ms, SIAs, and related documentation, in accordance with NIST SP 800-53, RMF, FISMA, and agency policies.
  • Coordinate and prepare systems for Security Control Assessments (SCAs), ensuring documentation and evidence are complete, accurate, and technically defensible.
  • Conduct Security Impact Analyses (SIAs) for changes to hardware, software, cloud infrastructure, connectivity, or system architecture.
  • Review system architecture, technical documentation, and supporting evidence to validate security controls, independently assess technical implementations, identify inconsistencies, and collaborate with engineers, architects, administrators, and system owners to resolve discrepancies.
  • Support change management, continuous monitoring, POA&M management, risk acceptance, audit responses, and remediation activities to maintain ongoing authorization and compliance.
  • Coordinate with system owners, engineers, architects, and governance stakeholders to support standards reviews, exception requests, policy implementation, compliance reporting, and risk management activities.
  • Develop dashboards, executive risk briefings, status reports, and other stakeholder communications while supporting the Lead ISSO in operational execution and coordination activities.
Required Qualifications:
  • Bachelor’s degree and 6+ years of relevant experience, or a master’s degree and 5+ years of experience, in cybersecurity, RMF, ISSO, systems security engineering, systems administration, cloud engineering, network engineering, or a related field.
  • Ability to obtain and maintain a public trust requiring U.S. Citizenship or Green Card. 
  • Prior hands-on experience in a technical role such as Systems Administrator, Cloud Engineer, Infrastructure Engineer, Network Engineer, or Security Engineer, with the ability to evaluate technical implementations, validate controls, assess evidence, and challenge unsupported assumptions.
  • Experience supporting federal authorization activities, including SSPs, POA&Ms, SIAs, continuous monitoring, and Security Control Assessments.
  • Working knowledge of NIST RMF, NIST SP 800-53, FISMA, and federal cybersecurity requirements.
  • Familiarity with enterprise and cloud technologies such as AWS, Azure, Microsoft 365, Entra ID, Active Directory, VMware, Cisco, Oracle, or similar platforms.
  • Working knowledge of identity and access management, encryption, system hardening, network and cloud security, secure baselines, logging, and monitoring.
  • Experience with GRC or security authorization tools such as Archer, eMASS, JCAM/CSAM, Xacta, or similar platforms.
  • Strong analytical, technical writing, organizational, and communication skills, including demonstrated professional proficiency in written and spoken English. Ability to independently produce polished, technically accurate documentation; communicate clearly and effectively with technical and non-technical stakeholders; work independently; and manage competing priorities in a fast-paced environment.
  • Proficiency with Microsoft Word, Excel, PowerPoint, and SharePoint.
Preferred Qualifications:
  • Security+, CGRC (formerly CAP), CISSP, CISM, CCSP, or similar cybersecurity certification.
  • Experience supporting federal systems, ATO processes, FedRAMP, federal privacy requirements, or other government compliance programs.
  • Knowledge of modern cybersecurity practices including OWASP Top 10, Zero Trust, application security concepts, and MITRE ATT&CK.
  • Experience participating in incident response, security architecture reviews, technical design reviews, or security remediation efforts.
  • Experience operating in fast-paced, high-visibility environments with competing priorities.

We offer:

  • Competitive salary based on experience
  • Profit sharing distributed twice a year
  • 15 days of paid time off and 10 paid holidays per year
  • 401(k) with employer matching
  • Health and dental benefits
  • Opportunity to work with other talented technical professionals

SharePointXperts is an Equal Opportunity/Affirmative Action employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, disability, or protected Veteran status. 

SharePointXperts participates in E-Verify. Click the following links for important information about our participation in this program and your rights.

https://www.e-verify.gov/sites/default/files/everify/posters/IER_RightToWorkPoster%20Eng_Es.pdf

https://www.e-verify.gov/sites/default/files/everify/posters/EVerifyParticipationPoster.pdf

Skills Required

  • Bachelor's degree and 6+ years of relevant experience, or a master's degree and 5+ years of relevant experience in cybersecurity, RMF, ISSO, systems security engineering, systems administration, cloud engineering, network engineering, or a related field.
  • Ability to obtain and maintain a public trust requiring U.S. citizenship or Green Card status.
  • Prior hands-on technical experience as a systems administrator, cloud engineer, infrastructure engineer, network engineer, security engineer, or similar, with the ability to evaluate implementations, validate controls, assess evidence, and challenge unsupported assumptions.
  • Experience supporting federal authorization activities, including SSPs, POA&Ms, SIAs, continuous monitoring, and Security Control Assessments.
  • Working knowledge of NIST RMF, NIST SP 800-53, FISMA, and federal cybersecurity requirements.
  • Familiarity with enterprise and cloud technologies such as AWS, Azure, Microsoft 365, Entra ID, Active Directory, VMware, Cisco, Oracle, or similar platforms.
  • Working knowledge of identity and access management, encryption, system hardening, network and cloud security, secure baselines, logging, and monitoring.
  • Experience with GRC or security authorization tools such as Archer, eMASS, JCAM/CSAM, Xacta, or similar platforms.
  • Strong analytical, technical writing, organizational, and communication skills, including professional proficiency in written and spoken English.
  • Ability to independently produce technically accurate documentation, communicate with technical and non-technical stakeholders, work independently, and manage competing priorities.
  • Proficiency with Microsoft Word, Excel, PowerPoint, and SharePoint.
  • Security+, CGRC, CISSP, CISM, CCSP, or similar cybersecurity certification.
  • Experience supporting federal systems, ATO processes, FedRAMP, federal privacy requirements, or other government compliance programs.
  • Knowledge of OWASP Top 10, Zero Trust, application security concepts, and MITRE ATT&CK.
  • Experience participating in incident response, security architecture reviews, technical design reviews, or security remediation efforts.
  • Experience operating in fast-paced, high-visibility environments with competing priorities.
Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
HQ: Reston, VA
80 Employees
Year Founded: 2012

What We Do

Established in 2001, Bamboo® Solutions provides software that helps organizations save significant time and money by deploying and managing applications, data, and users on Microsoft SharePoint. We provide technologies that augment the SharePoint platform, and more than 60 products that provide a broad range of enhanced capabilities and solutions that maximize the value of SharePoint deployments. In late 2016, SharePointXperts purchased Bamboo Solutions. This move positions the company to offer customers a complete suite of products and services designed to help them realize the full value of their SharePoint farms while preparing for the future via the company’s new “Bridge to the Cloud” migration service. SPX's Bamboo Solutions is now a leading provider of enterprise-class software applications and services designed to extend the native capabilities of Microsoft SharePoint and Office 365. So far, over 8,000 organizations worldwide have chosen to enhance their SharePoint deployment with products, solutions, and services from Bamboo.

Similar Jobs

SIERTEK LTD Logo SIERTEK LTD

Senior Information Systems Security Officer*

Information Technology • Professional Services • Defense • Manufacturing
In-Office
20001, Washington, DC, USA
260 Employees

Keeper Security, Inc. Logo Keeper Security, Inc.

Senior Information Systems Security Officer (ISSO)

Mobile • Security • Software • Cybersecurity
Remote or Hybrid
US
350 Employees

One Federal Solution Corporation Logo One Federal Solution Corporation

Senior Information Systems Security Officer

Information Technology • Professional Services • Business Intelligence • Defense
In-Office
Washington, DC, USA
152 Employees

Similar Companies Hiring

Kepler  Thumbnail
Artificial Intelligence • Fintech • Software
New York, New York
9 Employees
Onshore Thumbnail
Artificial Intelligence • Fintech • Software • Financial Services
New York, New York
60 Employees
Revel.io Thumbnail
Aerospace • Hardware • Robotics • Software
US
50 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account