Dragonfly AI Logo

Dragonfly AI

Mid-Level Information System Security Officer (ISSO)

Posted 13 Days Ago
Be an Early Applicant
Remote
Hiring Remotely in GBR
Senior level
Remote
Hiring Remotely in GBR
Senior level
Own the security posture of assigned federal systems, maintaining System Security Plans and authorization artifacts. Lead RMF execution, control assessments, audits, continuous monitoring, vulnerability remediation, POA&M management, and risk acceptance decisions. Advise system and business owners, report security metrics, support ongoing authorization, and coordinate assessment readiness. The role requires strong NIST knowledge, documentation skills, stakeholder communication, and experience with federal cybersecurity compliance.
The summary above was generated by AI
Description

Dragonfli Group is a cybersecurity and IT consulting firm providing services to federal agencies and Fortune 100 enterprises. Headquartered in Washington, DC, Dragonfli supports clients in securing mission-critical systems across on-site, hybrid, and fully remote environments.

Dragonfli Group is seeking a Mid Information System Security Officer (ISSO) to own the security posture of assigned systems on a multi-year cybersecurity program for a large federal agency. You will advise on architecture, authorization boundaries, and risk decisions, and you will lead control compliance and assessment readiness for your systems, maintaining the System Security Plan and other key artifacts and coordinating audits and assessments end to end. You will run continuous monitoring and reporting, define the metrics that make posture legible to stakeholders, and escalate material risks with a recommended course of action. You will also drive vulnerability remediation and POA&M corrective actions, including the harder calls around exceptions, compensating controls, and risk acceptances. This role suits an ISSO with roughly 4 years of experience who is ready to be the accountable security voice for a system rather than a supporting one.

This is a multi-year contract position involving a large US federal agency. Candidates with previous federal contracting experience are preferred. U.S. Citizenship or Permanent Residency is required. If hired, all work related to this role must be performed within the continental U.S.

This position is fully remote. The agency's Rules of Behavior and Telework Policy apply to all contractor personnel and require, among other things, that laptop cameras be turned on and that staff remain visible on camera during all meetings.

Responsibilities

  • Own the security posture for assigned systems, advising on architecture, authorization boundaries, and risk decisions
  • Lead control compliance and assessment readiness, maintaining key artifacts including the System Security Plan
  • Coordinate audits and assessments, including scheduling, evidence readiness, and response to assessor findings
  • Run continuous monitoring and reporting, defining metrics and escalating material risks and issues
  • Drive vulnerability remediation and POA&M corrective actions, including exceptions, compensating controls, and risk acceptances
  • Execute Risk Management Framework tasks across categorization, control selection, implementation, assessment, and authorization in accordance with NIST SP 800-37
  • Support the transition to and management of an Ongoing Authorization program
  • Provide cybersecurity guidance to Business Owners and System Owners and serve as a liaison between those stakeholders and the cybersecurity staff
  • Support System Owner system access reviews and account management compliance
  • Apply automation and AI tooling to streamline RMF documentation, control assessments, and continuous monitoring activities
Requirements

Must-Have

  • Bachelor's degree in cybersecurity, information technology, or a related field
  • 4 years of ISSO experience, including ownership of security posture for one or more systems
  • Demonstrated experience maintaining SSPs and leading a system through assessment or authorization
  • Hands-on experience managing POA&Ms, including exceptions, compensating controls, and risk acceptances
  • Working knowledge of NIST SP 800-37 and NIST SP 800-53, and of continuous monitoring practice
  • Experience advising system owners or engineering teams on risk decisions
  • U.S. Citizenship or Permanent Residency, with all work performed within the continental U.S.
  • Ability to pass a federal agency suitability or background investigation

Preferred / Nice-to-Have

  • Prior federal contracting experience as an ISSO at a civilian agency
  • Experience with Ongoing Authorization or continuous ATO programs
  • Experience with a GRC platform such as Xacta, eMASS, CSAM, Archer, or ServiceNow IRM
  • Cloud authorization experience, including FedRAMP inheritance and interconnection agreements
  • Experience defining security metrics and reporting posture to non-technical stakeholders
  • Certifications such as CISSP, CGRC (formerly CAP), CISM, or CCSP
Skill(s)

Technical Skills

  • System security posture ownership and risk-based decision support
  • SSP and authorization artifact development and maintenance
  • Risk Management Framework execution under NIST SP 800-37
  • Security control assessment readiness under NIST SP 800-53A
  • POA&M management, compensating controls, exceptions, and risk acceptance
  • Continuous monitoring, security metrics definition, and posture reporting
  • Vulnerability management and remediation coordination
  • GRC tooling and cloud authorization models including FedRAMP

Soft Skills

  • Clear written and verbal communication with both technical and non-technical audiences
  • Ability to work independently and as a contributing member of a distributed team
  • Comfort operating in a fully remote setting with a camera-on meeting culture
  • Sound judgment about when to decide and when to escalate
  • Collaborative posture with system owners, business owners, developers, and assessors
  • Attention to documentation quality and follow-through on commitments
Benefits

Dragonfli Group offers a comprehensive benefits package that includes:

  • Medical: Multiple POS health plan options including an HSA-compatible plan
  • Dental: PPO coverage for preventive, basic, and major services
  • Vision: Annual exam, frames, lenses, and contact lens allowance
  • 401(k): Employer match up to 5% of eligible compensation
  • Long-Term Disability: 100% employer-paid coverage at 50% of pre-disability earnings
  • Life Insurance & AD&D: 100% employer-paid coverage valued at $10,000 each
  • PTO: 15–25 days annually based on tenure
  • Paid Federal Holidays: All 11 federal holidays observed

Similar Jobs

An Hour Ago
Remote
United Kingdom
Senior level
Senior level
Artificial Intelligence • Fintech • Information Technology • Logistics • Payments • Business Intelligence • Generative AI
Leads a regional pre-sales Solution Advisory team to drive revenue growth, pipeline development, and customer success. Responsibilities include assigning resources, aligning with sales leadership, coaching and developing talent, supporting recruiting and retention, demonstrating Coupa’s platform architecture and integrations, advising prospects on business needs, and scaling best practices across the organization.
Top Skills: CoupaCoupa AiCoupa Bsm
5 Hours Ago
Remote or Hybrid
Entry level
Entry level
Cloud • Software
Build and operate AI-powered developer tools, agentic workflows, reusable skills, integrations, orchestration capabilities, backend services, and APIs. Integrate AI systems with source control, CI/CD, issue tracking, documentation, and developer environments. Apply testing, evaluation, monitoring, security, and feedback practices to non-deterministic AI systems while collaborating with developers and contributing to platform architecture and engineering processes.
Top Skills: Agentic AiAi Coding ToolsAPIsCi/CdContainersDistributed SystemsDocument DatabasesEmbeddingsGitGoJavaKotlinKubernetesLarge Language ModelsPythonRelational DatabasesRetrieval-Augmented GenerationTypescriptVector Databases
6 Hours Ago
In-Office or Remote
Mid level
Mid level
Cloud • Information Technology • Productivity • Security • Software • App development • Automation
Drive adoption of Atlassian's AI platform Rovo by discovering high-value use cases, co-building custom agents, configuring connectors, and deploying solutions to production. Run discovery workshops, design and validate integrations, enable customers for independent scale, collaborate with account and product teams, and surface product feedback. Travel up to 15% for customer meetings and events.
Top Skills: Ai AgentsAi PlatformsAtlassian (JiraConfluence)Enterprise SearchGitGoogle DrivePrompt EngineeringRovoRovo StudioSharepointSlackThird-Party Connectors

What you need to know about the Belfast Tech Scene

If asked to name the birthplace of the RMS Titanic, you might not say Belfast. Similarly, if asked to name Europe's leading destination for foreign direct investment in new software development, Belfast might not come to mind. Yet, both are true. The city has emerged as a tech powerhouse, recently ranked among the best in the U.K. for tech careers — especially for software developers. It also leads the U.K. with the highest percentage of software development jobs advertised.

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account