Avatar for QBA
QBA
Actively Hiring
IT services, consulting, market research, audit, and compliance solutions

Information System Security Officer

Posted: yesterday• Recruiter recently active
Job Location
Remote Work Policy

Onsite or remote

Hires remotely in
Visa Sponsorship

Not Available

Preferred Timezones
Eastern Time
Collaboration Hours
9:00 AM - 6:00 PM Eastern Time
RelocationAllowed
Skills
CISSP
Information Security
AWS Cloud Services
FEDRAMP
NIST 800-53
Risk Management Framework (RMF)
Authority to Operate (ATO)
Plan of Action and Milestones (POA&M)
Continuous Monitoring (ConMon)

About the job

We are building a team for one of the U.S. Federal Government's largest technology modernization programs, underpinning the U.S. capital markets.

Built on AWS and leveraging an AI-powered software engineering platform, this program offers a unique opportunity to gain hands-on experience with next-generation AI, Agentic AI, cloud technologies, and AI-driven engineering.

If you are looking for technically challenging work, exceptional learning, and a résumé-defining opportunity with national impact, I would love to connect.

Job Title:
ISSO

Position Type:
Full-Time

Location:
Hybrid (2 days onsite)

Days Remote:
3 days remote

Position Summary:
The Developer serves as the Information System Security Officer responsible for maintaining the security posture, compliance, and authorization status of a large-scale federal information system. This role manages the Risk Management Framework lifecycle, maintains the system’s Authority to Operate documentation, and coordinates continuous-monitoring activities. The Developer works closely with client security leadership, security teams, and DevSecOps personnel to ensure continued compliance with NIST SP 800-53, FedRAMP, and applicable federal information-security requirements.

Key Responsibilities:

  • Maintain the system’s Risk Management Framework documentation and Authority to Operate package.
  • Manage and maintain security-control implementation evidence aligned with NIST SP 800-53 and FedRAMP requirements.
  • Track security findings and coordinate remediation activities through Plans of Action and Milestones.
  • Manage continuous-monitoring documentation, evidence, and reporting activities.
  • Support security assessments, compliance audits, system authorization reviews, and related security activities.
  • Coordinate with the client Information System Security Manager, security teams, and DevSecOps personnel on security and compliance requirements.
  • Review proposed system changes to assess potential security impacts.
  • Maintain approved system-security configurations and security baselines.
  • Report the system’s security posture, risks, findings, and incidents to program leadership and client stakeholders.

Minimum Experience:

  • 5+ years of information-system security or Information System Security Officer experience.
  • Experience supporting federal Risk Management Framework and Authority to Operate processes.
  • Experience managing continuous-monitoring activities and Plans of Action and Milestones.

Mandatory Skills:

  • Must have CISSP certification in good standing.
  • Information System Security Officer experience.
  • Federal information-system security.
  • Risk Management Framework.
  • Authority to Operate processes and documentation.
  • NIST SP 800-53 security controls.
  • Security-control implementation and evidence management.
  • Plans of Action and Milestones management.
  • Security assessments and audits.
  • Security authorization activities.
  • Security-baseline management.
  • Security-risk and incident reporting.
  • CISSP, CAP, or an equivalent security certification.
  • Non-technical Requirements:
  • U.S. work authorization.
  • Ability to obtain a Public Trust clearance.
  • Continuous monitoring.

Nice-to-Have Skills:

  • FedRAMP experience.
  • AWS cloud-security experience.
  • Financial-regulatory security experience.
  • Security automation experience.
  • Governance, Risk, and Compliance tooling experience.

Pay Rate Range:
$200,000–$220,000

Degrees and Certifications:

Required:
CISSP, CAP, or an equivalent security certification.

About the company

QBA company logo

QBA

Actively Hiring
IT services, consulting, market research, audit, and compliance solutions201-500 Employees
Company Size
201-500
Learn more about QBA image