Apply

Ready to go for it?

AI Apply speeds things up—apply directly if you prefer.

FREE ACCESS
5,000–10,000 jobs/day
Scoutfield Logo

See all jobs on Scoutfield

Search thousands of fresh jobs every day.

Discover
  • Fresh listings
  • Fast filters
  • No subscription required
Create a free account and start exploring right away.
Dragonfli Group

Mid-Level Information System Security Officer, ISSO

Dragonfli Group

. Own the security posture for assigned systems .

Posted 9/15/2026full-timeRemote • United StatesMid-LevelSeniorWebsite

Core Competencies

Role fit
Core Competencies

Use this summary to align your resume positioning with the role.

Demonstrates expertise in managing security postures, conducting risk assessments, and maintaining System Security Plans in compliance with NIST standards. Proficient in coordinating audits, defining security metrics, and providing cybersecurity guidance to stakeholders.

Highest-signal resume keywords
ISSO ExperienceNIST SP 800-37 KnowledgePOA&M ManagementContinuous Monitoring PracticesCybersecurity Certifications

ATS Keywords

Tailor your resume
Applicant Tracking System Keywords

Tip: use these terms in your resume and cover letter to boost ATS matches.

Hard Skills
Risk Management FrameworkSystem Security Plan MaintenanceVulnerability RemediationControl ComplianceSecurity Metrics DefinitionAudit CoordinationCybersecurity GuidanceCloud AuthorizationAutomation in RMFContinuous ATO Programs
Soft Skills
Clear CommunicationIndependent WorkCollaborative PostureSound JudgmentAttention to Documentation Quality
Tools & Technologies
XactaEMASSCSAMArcherServiceNow IRM
Certifications & Qualifications
CISSPCGRCCISMCCSP
Industry Keywords
Federal ContractingCybersecurityRisk DecisionsAuthorization BoundariesAssessment Readiness

Tech Stack

Tools & technologies
CloudCyber SecurityServiceNow

About the role

Key responsibilities & impact
  • Own the security posture for assigned systems
  • Advise on architecture, authorization boundaries, and risk decisions
  • Lead control compliance and assessment readiness
  • Maintain the System Security Plan and other key security artifacts
  • Coordinate audits and assessments, including scheduling, evidence readiness, and responses to assessor findings
  • Run continuous monitoring and reporting
  • Define security metrics and escalate material risks and issues
  • Drive vulnerability remediation and POA&M corrective actions, including exceptions, compensating controls, and risk acceptances
  • Execute Risk Management Framework tasks across categorization, control selection, implementation, assessment, and authorization in accordance with NIST SP 800-37
  • Support transition to and management of an Ongoing Authorization program
  • Provide cybersecurity guidance to Business Owners and System Owners
  • Liaise between stakeholders and cybersecurity staff
  • Support System Owner system access reviews and account management compliance
  • Apply automation and AI tooling to streamline RMF documentation, control assessments, and continuous monitoring activities

Requirements

What you’ll need
  • Bachelor's degree in cybersecurity, information technology, or a related field
  • 4 years of ISSO experience, including ownership of security posture for one or more systems
  • Demonstrated experience maintaining SSPs and leading a system through assessment or authorization
  • Hands-on experience managing POA&Ms, including exceptions, compensating controls, and risk acceptances
  • Working knowledge of NIST SP 800-37, NIST SP 800-53, and continuous monitoring practices
  • Experience advising system owners or engineering teams on risk decisions
  • U.S. Citizenship or Permanent Residency
  • All work must be performed within the continental U.S.
  • Ability to pass a federal agency suitability or background investigation
  • Prior federal contracting experience as an ISSO at a civilian agency preferred
  • Experience with Ongoing Authorization or continuous ATO programs preferred
  • Experience with a GRC platform such as Xacta, eMASS, CSAM, Archer, or ServiceNow IRM preferred
  • Cloud authorization experience, including FedRAMP inheritance and interconnection agreements preferred
  • Experience defining security metrics and reporting posture to non-technical stakeholders preferred
  • Certifications such as CISSP, CGRC, CISM, or CCSP preferred
  • Clear written and verbal communication with technical and non-technical audiences
  • Ability to work independently and as a contributing member of a distributed team
  • Comfort operating in a fully remote setting with a camera-on meeting culture
  • Sound judgment about when to decide and when to escalate
  • Collaborative posture with system owners, business owners, developers, and assessors
  • Attention to documentation quality and follow-through on commitments

Benefits

Comp & perks
  • Multiple POS health plan options including an HSA-compatible plan
  • Dental PPO coverage for preventive, basic, and major services
  • Vision coverage including annual exam, frames, lenses, and contact lens allowance
  • 401(k) employer match up to 5% of eligible compensation
  • 100% employer-paid long-term disability coverage at 50% of pre-disability earnings
  • 100% employer-paid life insurance and AD&D coverage valued at $10,000 each
  • 15–25 days of PTO annually based on tenure
  • Paid observance of all 11 federal holidays