ASRC Federal

Senior Information Security Engineer

ASRC Federal Reston, Virginia, United States

Information Technology & Services · 201-500 employees

15 h ago
Remote security Senior (5-10 yrs) Full-time United States
Create a free account to apply — email only, no card. You can also save this posting or score it against your profile with AI.

About the role

The Senior ISSO serves as the primary cybersecurity and privacy advisor to System Owners, ensuring security requirements are integrated throughout the system lifecycle. They lead RMF activities, maintain authorization packages, and ensure continuous compliance with federal security regulations.

What they look for

Risk Management Framework RMF FISMA NIST SP 800-37 NIST SP 800-53 Cybersecurity Information Assurance Authorization to Operate ATO Continuous Monitoring Vulnerability Management Governance, Risk, and Compliance GRC Security Controls Privacy Compliance Stakeholder Engagement

Requirements

Candidates must have a bachelor's degree in a relevant field and 5-7 years of experience in cybersecurity or information assurance. Required certifications include CISSP and either CGRC or CCSP, along with strong knowledge of NIST frameworks and federal compliance.

Benefits

Health care Dental Vision Life insurance 401(k) Education assistance Paid time off Holidays

Full description

ASRC Federal is a leading government contractor furthering missions in space, public health and defense. As an Alaska Native owned corporation, our work helps secure an enduring future for our shareholders. Join our team and discover why we are a top veteran employer and Certified Great Place to Work™

ASRC Federal Data Networx is seeking a Senior Information System Security Officer (ISSO) to support federal cybersecurity and Risk Management Framework (RMF) activities for enterprise information systems. The ISSO serves as the primary cybersecurity and privacy advisor to System Owners (SOs), ensuring security and privacy requirements are integrated throughout the system lifecycle while maintaining compliance with federal regulations and Authorization to Operate (ATO) requirements.

Work Location: Remote

Key Responsibilities

  • Serve as the primary cybersecurity and privacy advisor to System Owners for assigned systems.
  • Lead RMF activities, including development and maintenance of System Security and Privacy Plans (SSPPs), authorization packages, risk documentation, and supporting artifacts.
  • Ensure systems maintain Authorization to Operate (ATO) through assessment support, continuous monitoring, and compliance with NIST RMF, FISMA, and federal security requirements.
  • Assess security risks, validate security controls, and coordinate remediation of vulnerabilities and Plans of Action and Milestones (POA&Ms).
  • Maintain system inventories, security documentation, contingency plans, configuration management plans, and privacy documentation.
  • Collaborate with ISSMs, System Owners, Security Control Assessors, and technical teams to integrate security throughout the system lifecycle.
  • Monitor system security posture, review vulnerability and compliance scan results, and support continuous authorization initiatives.
  • Provide cybersecurity guidance, develop security policies and procedures, and deliver security awareness training.
  • Support security engineering, certification and accreditation activities, and implementation of security controls across systems.
  • Recommend process improvements and automation opportunities to enhance RMF and cybersecurity operations.

Required Qualifications

  • Bachelor's degree in Cybersecurity, Information Assurance, Computer Science, Information Technology, or a related field.
  • Minimum 5–7 years of experience supporting information assurance, cybersecurity, RMF, or information system security, or an equivalent combination of education and experience.
  • Experience supporting federal cybersecurity programs and the NIST Risk Management Framework (RMF).
  • Experience developing and maintaining RMF documentation, authorization packages, and Governance, Risk, and Compliance (GRC) tools.
  • Strong knowledge of NIST SP 800-37, NIST SP 800-53, FISMA, FIPS 199, and federal privacy requirements.
  • Experience supporting Authorization to Operate (ATO), Continuous ATO (cATO), or Continuous Authorization efforts.
  • Strong analytical, communication, documentation, and stakeholder engagement skills.

Required Certifications

  • Certified Information Systems Security Professional (CISSP)
  • Certified in Governance, Risk and Compliance (CGRC) or Certified Cloud Security Professional (CCSP)

Preferred Qualifications

  • Experience supporting U.S. federal civilian agencies, preferably the USPTO.
  • Experience with continuous monitoring, vulnerability management, and security automation.
  • Familiarity with cloud security, DevSecOps, and continuous authorization initiatives.
  • Knowledge of privacy compliance activities, including Privacy Threshold Assessments (PTAs), Privacy Impact Assessments (PIAs), and System of Records Notices (SORNs).

We invest in the lives of our employees, both in and out of the workplace, by providing competitive pay and benefits packages. Benefits offered may include health care, dental, vision, life insurance; 401(k); education assistance; paid time off including PTO, holidays, and any other paid leave required by law. The salary offered will depend on several factors including, but not limited to, relevant experience, skills, education, geographic location, internal equity, business needs, and other factors permitted by law. Posted pay ranges are a general guideline only and are not a guarantee of compensation or salary.

EEO Statement

ASRC Federal and its Subsidiaries are Equal Opportunity employers. All qualified applicants will receive consideration for employment without regard to race, gender, color, age, sexual orientation, gender identification, national origin, religion, marital status, ancestry, citizenship, disability, protected veteran status, or any other factor prohibited by applicable law.

Similar roles