Senior Information System Security Officer (ISSO)

🏢 Dragonfli Group · all Dragonfli Group jobs (6)
📍 United States
📅 Posted 2026-09-06 · via Himalayas
🏷 Governance-Risk-and-Compliance-(GRC),Information-System-Security-Officer,Cybersecurity,Security-Compliance,Federal-Cybersecurity,Information-Systems-Security-Officer-(ISSO),Information-System-Security-Officer-(ISSO),Information-Systems-Security-Officer
Apply on original site ↗

Description

Dragonfli Group is a cybersecurity and IT consulting firm providing services to federal agencies and Fortune 100 enterprises. Headquartered in Washington, DC, Dragonfli supports clients in securing mission-critical systems across on-site, hybrid, and fully remote environments.

Dragonfli Group is seeking a Mid Information System Security Officer (ISSO) to own the security posture of assigned systems on a multi-year cybersecurity program for a large federal agency. You will advise on architecture, authorization boundaries, and risk decisions, and you will lead control compliance and assessment readiness for your systems, maintaining the System Security Plan and other key artifacts and coordinating audits and assessments end to end. You will run continuous monitoring and reporting, define the metrics that make posture legible to stakeholders, and escalate material risks with a recommended course of action. You will also drive vulnerability remediation and POA&M corrective actions, including the harder calls around exceptions, compensating controls, and risk acceptances. This role suits an ISSO with roughly 4 years of experience who is ready to be the accountable security voice for a system rather than a supporting one.

This is a multi-year contract position involving a large US federal agency. Candidates with previous federal contracting experience are preferred. U.S. Citizenship or Permanent Residency is required. If hired, all work related to this role must be performed within the continental U.S.

This position is fully remote. The agency's Rules of Behavior and Telework Policy apply to all contractor personnel and require, among other things, that laptop cameras be turned on and that staff remain visible on camera during all meetings.
Responsibilities

- Own the security posture for assigned systems, advising on architecture, authorization boundaries, and risk decisions

- Lead control compliance and assessment readiness, maintaining key artifacts including the System Security Plan

- Coordinate audits and assessments, including scheduling, evidence readiness, and response to assessor findings

- Run continuous monitoring and reporting, defining metrics and escalating material risks and issues

- Drive vulnerability remediation and POA&M corrective actions, including exceptions, compensating controls, and risk acceptances

- Execute Risk Management Framework tasks across categorization, control selection, implementation, assessment, and authorization in accordance with NIST SP 800-37

- Support the transition to and management of an Ongoing Authorization program

- Provide cybersecurity guidance to Business Owners and System Owners and serve as a liaison between those stakeholders and the cybersecurity staff

- Support System Owner system access reviews and account management compliance

- Apply automation and AI tooling to streamline RMF documentation, control assessments, and continuous monitoring activities

Requirements
Must-Have

- Bachelor's degree in cybersecurity, information technology, or a related field

- 4 years of ISSO experience, including ownership of security posture for one or more systems

- Demonstrated experience maintaining SSPs and leading a system through assessment or authorization

- Hands-on experience managing POA&Ms, including exceptions, compensating controls, and risk acceptances

- Working knowledge of NIST SP 800-37 and NIST SP 800-53, and of continuous monitoring practice

- Experience advising system owners or engineering teams on risk decisions

- U.S. Citizenship or Permanent Residency, with all work performed within the continental U.S.

- Ability to pass a federal agency suitability or background investigation

Preferred / Nice-to-Have

- Prior federal contracting experience as an ISSO at a civilian agency

- Experience with Ongoing Authorization or continuous ATO programs

- Experience with a GRC platform such as Xacta, eMASS, CSAM, Archer, or ServiceNow IRM

- Clou

← All remote jobs

Get remote jobs like this by email

One weekly digest. No spam, unsubscribe anytime.

Similar for you