About this Information Systems Security Officer (ISSO), Senior role at Anavationllc
Description of Task to be Performed:
AnaVation is seeking a Senior-level ISSO to support a newly-awarded contract. The selected candidate must be able to excel as the sole ISSO to prepare a full accreditation package to quickly obtain ATT/ATO for a new digital evidence platform in support of our Federal Government client. This is a full-time position that can be performed remotely with occasional travel to Washington DC as needed.
What you will be doing
- Lead all RMF activities for the assigned system, including Categorization, Selection, Implementation, Assessment, Authorization, and Continuous Monitoring.
- Oversee the design, implementation, and validation of NIST 800-53 Rev 5 security and privacy controls across technical, operational, and management domains.
- Develop, maintain, and update key security artifacts including System Security Plans (SSPs), Security Assessment Reports (SARs), POA&Ms, Incident Response Plans, and Continuous Monitoring strategies.
- Coordinate and support security control assessments (SCAs), penetration tests, vulnerability scans, and compliance audits.
- Guide engineering teams on implementing and documenting new or updated security controls, ensuring they align with Rev 5 enhancements and control baselines.
- Evaluate system changes, architecture updates, and new integrations for security impact and required control modifications.
- Lead risk assessments, document findings, and track remediation through POA&M management.
- Manage continuous monitoring activities, including log review, vulnerability management, patch tracking, and configuration baseline validation.
- Serve as the primary security liaison for system owners, internal stakeholders, external assessors, and authorizing officials (AOs).
- Assist in developing security control inheritance strategies from enterprise common controls, and ensure proper documentation and alignment.
- Mentor junior ISSOs and analysts in RMF, control interpretation, documentation quality, and security best practices.
- Stay current on updates to NIST SP 800-53 Rev 5, 800-37, 800-30, and emerging federal cybersecurity guidance.
Required Qualifications:
Preferred Qualifications:
- Generous cost sharing for medical insurance for the employee and dependents
- 100% company paid dental insurance for employees and dependents
- 100% company paid long-term and short-term disability insurance
- 100% company paid vision insurance for employees and dependents
- 401k plan with generous match and 100% immediate vesting
- Competitive Pay
- Generous paid leave and holiday package
- Tuition and training reimbursement
- Life and AD&D Insurance