Mission / Role Summary: Provide hands-on ISSO support across the full system lifecycle (initiation through disposal) for systems within and interconnected to the Client Enterprise General Support System (GSS) boundary, including Client-managed FedRAMP-authorized cloud subscriptions operating under shared responsibility and inherited-controls context, by producing accurate, current, audit-ready RMF and continuous monitoring artifacts and coordinating effectively with technical teams and federal stakeholders.
Primary Responsibilities (outcome-focused)
RMF & authorization support:
Develop, update, and maintain RMF and authorization-package artifacts in CSAM/JCAM as designated by client, ensuring Government/assessor evidence needs are met for ATO activities, ongoing audits, and operational reviews.
Support 3PAO/security assessment activities by organizing evidence, responding to requests for information, and preparing the system team for reviews/testing events
Documentation quality:
Produce deliverables that are complete, accurate, timely, professionally prepared, and audit-ready; ensure artifacts are current and free of defects such as outdated/inapplicable citations and broken references.
Maintain clear traceability between controls, implementations, evidence, findings, and POA&M entries to support defensible security posture reporting.
Continuous monitoring & posture:
Execute continuous monitoring activities (e.g., monthly/quarterly evidence collection, patch/configuration compliance reporting, vulnerability status reporting) and help maintain metrics and reporting inputs.
Support security posture management tasks and recurring operational security reporting needs as directed.
Vulnerability & POA&M support:
Coordinate vulnerability management workflows and support POA&M development, updates, milestone tracking, and risk narratives to enable remediation and posture reporting.
Track findings through closure support activities, ensuring POA&M records remain accurate and usable for governance and risk reporting.
SIA & change coordination:
Coordinate Security Impact Analyses (SIA) for planned changes (software releases, infrastructure changes, cloud service modifications).
Ensure CM/RMF alignment: update SSP/control implementations, update diagrams/inventories, identify control/evidence impacts, and route changes through governance boards as required (e.g., CCB).
Validate change evidence (approvals, test results, scanning results) is captured and traceable in CSAM/JCAM.
Assess whether proposed or implemented changes constitute a significant security change and identify any required control reassessment, authorization-artifact updates, or follow-on security actions.
Incident coordination (ISSO scope):
Support incident response within ISSO scope by coordinating with SOC/IR teams to collect artifacts, document timelines, and ensure RMF impacts are recorded (control deviations, compensating controls, required notifications).
Track incident-related corrective actions as POA&Ms (or equivalent) and support closure evidence collection.
Assist with after-action reporting inputs and continuous monitoring updates resulting from incidents.
Provide system-boundary, authorization/control, and log-verification context to support SOC/IR activities. This position provides ISSO-level incident coordination and does not replace SOC monitoring, threat hunting, forensics, malware analysis, or dedicated incident-response functions.’ This keeps the role boundary clear for candidates.
Governance integration:
Coordinate with System Owners/CCPs and the Privacy Office (for PII systems) within the Client governance structure, contributing recommendations, analysis, and documentation. 5
Operate in a non-inherently governmental capacity: provide recommendations and artifacts, but do not make final Government decisions such as ATO sign-off, final risk acceptance, final POA&M closure approval, or official external representation.
Security Documentation and CSAM Artifact Management
Maintain continuous “audit-ready” posture and evidence traceability by keeping authoritative artifacts and evidence current (including SSP/SAR/POA&M, control evidence, and Splunk-derived log-completeness records where applicable) across assigned CSAM authorization boundaries minimizing surge effort when audits occur.
Audit, FISMA, and Compliance Reporting Support
Support audit preparation/execution and compliance data calls.
Provide audit/assessment support for oversight activities (e.g., FISMA IG audits, GAO audits, OMB FedRAMP customer-responsibility validations) by maintaining an evidence library aligned to NIST SP 800-53 Rev. 5.
Prepare readiness checklists, coordinate interviews/walkthroughs, acknowledge evidence requests within 1 business day, producing evidence within auditor/COR timelines (or escalating constraints), and tracking communications/transmittals.
Non-inherently governmental: Provide recommendations and documentation but do not make final Government decisions (e.g., ATO sign-off, final risk acceptance, final POA&M closure approval, official external representation).
Qualifications / Experience
~5 years cybersecurity/RMF/GRC experience supporting enterprise systems; strong writing and stakeholder communication skills to meet deliverable quality expectations.
Education / Certifications (desired)
Bachelor’s degree in IT/Cyber/related
Security certs aligned to RMF/GRC (e.g., CGRC, CISSP, CISM) consistent with the sample Lead ISSO preference set
Work Location: Hybrid; must report to Washington, DC ≥2 days/week; during core hours 7:00 AM–6:00 PM ET
Citizenship/Suitability: U.S. Citizen; Candidate must possess a current, favorable Tier 4 (High-Risk Public Trust) suitability determination, or meet federal reciprocity requirements
Join the Aderas team!
Aderas is looking to recruit and retain only the best and brightest. If you like working with emerging technologies, using your unique personal skills to solve technical, functional, and organizational issues, and can easily adapt to the ever-changing IT market, then Aderas is the place for you! We are a vibrant company delivering implementation services & support for enterprise solutions and custom application development. We strive to form long-term partnerships with our clients to foster an environment based on trust, a proven history of delivery, and camaraderie.
Why Aderas?
We sincerely try to shape our employees' lives by administering a generous package of employee benefits. Our company culture encourages collaboration, creative thinking, and growth.
Beyond the tangible and intangible rewards, Aderas provides the following:
Pay for Life, AD&D, Short-term disability, and Long-term disability at no cost to the employee.
Employer contribution toward monthly health insurance premiums.
401k plan which employees are eligible for after being with the company for 3 months.
Safe Harbor plan in which Aderas contributes 3% of employees' salaries once a year
A week of paid training and reimbursement for approved professional courses and tests.
All Job Ads are subject to GrabJobs’s Terms of Service. We allow users to flag postings that may be in violation of those terms. Job Ads may also be flagged by GrabJobs moderation team. However, no moderation system is perfect, and flagging a posting does not ensure that it will be removed.
Be the first to receive the latest Others Full-Time Jobs in the US.
Setup your job alert:
By activating job alerts, I agree to GrabJobs Terms & Privacy Policy. I can unsubscribe to job alerts anytime.
Skip
GrabJobs is the no1 job portal in the US, connecting you to thousands of jobs fast!
Find the best jobs in the US, apply in 1 click and get a job today!