Mid-Level Information System Security Officer (ISSO)
Anavation
Job Summary
This role involves supporting a high-impact cybersecurity program as a Tier II Information System Security Officer (ISSO). Key responsibilities include maintaining security documentation, conducting security control assessments, reviewing audit logs and vulnerability scans, collaborating with technical teams, supporting ongoing authorization activities, and preparing reports for senior leadership. The candidate will ensure alignment with DOJ cybersecurity policies and NIST standards. The position is full-time and on-site.
Must Have
- 4+ years of cybersecurity experience
- Experience with ATO for federal systems
- Strong knowledge of RMF and NIST publications
- Experience drafting and maintaining security documentation
- Familiarity with vulnerability scanning tools
- CISSP, CISM, CGRC, CRISC, ISSMP, CISA, CCSP, CEH, or Security+ certifications
Perks & Benefits
- Generous cost sharing for medical insurance
- 100% company paid dental insurance
- 100% company paid long-term and short term disability insurance
- 100% company paid vision insurance
- 401k plan with generous match and 100% immediate vesting
- Competitive Pay
- Generous paid leave and holiday package
- Tuition and training reimbursement
- Life and AD&D Insurance
Job Description
Be Challenged and Make a Difference
In a world of technology, people make the difference. We believe if we invest in great people, then great things will happen. At AnaVation, we provide unmatched value to our customers and employees through innovative solutions and an engaging culture.
Description of Task to be Performed:
Come join our growing team and make a difference every day! AnaVation is seeking a skilled Tier II Information System Security Officer (ISSO) to support a high-impact cybersecurity program). This mid-level role is perfect for candidates with hands-on RMF experience who are ready to take ownership of system authorizations, continuous monitoring, and federal compliance activities.
Key responsibilities include:
• Support the maintenance of security documentation and support system ATO and ATT efforts.
• Conduct security control assessments and provide recommendations for remediation.
• Perform biweekly audit log and vulnerability scan reviews and track POA&M items.
• Collaborate with system owners and technical teams to manage risk and respond to incident.
• Support Ongoing Authorization (OA) and continuous monitoring activities.
• Prepare and brief senior leadership on system security posture and compliance metric.
• Ensure alignment with DOJ cybersecurity policies and NIST SP 800-53, 800-37, and 800-137.
This position is full-time onsite with our customer in a Metro-accessible location in Washington, DC.
Required Qualifications:
- Education: Bachelor’s degree in Cybersecurity, Information Technology, or a related field. In lieu of a degree, a minimum of four (4) years of hands-on relevant experience is required.
- Experience: 4 years
- Required Skills/Certs:
- Minimum of four (4) years of hands-on experience in cybersecurity, with at least one (1) year maintaining an Authorization to Operate (ATO) for a moderate or high-impact federal information system.
- Strong working knowledge of the Risk Management Framework (RMF) and NIST publications, especially SP 800-53, 800-37, and 800-137.
- Experience drafting, reviewing, and maintaining system security documentation (e.g., SSP, CMP, POA&M, IRP)
- Familiarity with vulnerability scanning tools and interpreting results (e.g., Tenable Nessus, Splunk).
- Must possess at least two of the following certifications:
- Certified Information Systems Security Professional (CISSP)
- Certified Information Security Manager (CISM)
- Certified Governance, Risk and Compliance (CGRC)
- Certified in Risk and Information Systems Control (CRISC)
- Information Systems Security Management Professional (ISSMP)
- Certified Information Systems Auditor (CISA)
- Certified Cloud Security Professional (CCSP)
- Certified Ethical Hacker (CEH)
- CompTIA Security+
- Required Clearance:
- Ability to obtain Public Trust clearance; Secret clearance strongly preferred.
4 Skills Required For This Role
Risk Management
Nessus
Cloud Security
Splunk