ISSO Analyst
Emass
Fips / Nist
Fisma
Fisma Compliance
Information Security
Information Systems Security
InfoSec
ISSO
NIST
Nist Sp 800 53
NIST SP 800-53
Nist Standards
Risk Management
Security
Security Assessment And Authorization
Security Compliance
Security Standards
Security Standards And Compliance
Security Standards And Frameworks
Job Description
The ISSO Analyst role at EY supports Information System Security Officer (ISSO) and Security Control Assessment (SCA) activities across the NIST Risk Management Framework (RMF) lifecycle for federal information systems. The position centers on maintaining authorization documentation, building evidence packages mapped to NIST controls, supporting assessment readiness, and managing POA&M remediation and continuous monitoring tasks.
Location and Work Setup
- Location: San Antonio, TX
- Work model: Hybrid
Compensation
- Estimated salary: USD 73,100 - 109,200 per year
Key Responsibilities
- Support RMF delivery for assigned federal information systems by maintaining documentation and tracking actions, assisting system owners and government security personnel with authorization activities.
- Support RMF Prepare by maintaining system information, stakeholder lists, asset and component inventories, authorization boundary information, data-flow documentation, interconnections, and risk context.
- Assist with information-type identification, NIST SP 800-60 mapping, and FIPS 199 security categorization, and document rationale and supporting information for review.
- Support control baseline selection and tailoring by documenting overlays, scoping decisions, organization-defined parameters, common controls, and system-specific responsibilities.
- Draft and update authorization artifacts, including System Security Plans, control implementation statements, inventories, diagrams, assessment-readiness materials, and supporting appendices.
- Collect, organize, and map evidence (policies, procedures, configurations, screenshots, tickets, scan outputs, and other materials) to applicable NIST SP 800-53 controls and assessment objectives.
- Review implementation statements and evidence for completeness, consistency, and traceability, and escalate gaps or conflicting information to senior team members.
- Prepare evidence packages, interview materials, document-request trackers, and response logs to support security control assessments.
- Participate in evidence-gathering sessions and control interviews with system owners, engineers, application teams, and assessors, capturing decisions, action items, and follow-up requests.
- Assist with drafting assessment responses, findings, risk statements, and corrective actions while preserving assessment independence.
- Create and maintain POA&M records, including weaknesses, responsible parties, milestones, scheduled completion dates, remediation evidence, and closure documentation.
- Track POA&M progress, follow up on overdue actions, validate evidence submissions, and escalate schedule or risk issues.
- Execute continuous monitoring, including scheduled control reviews, vulnerability and configuration reporting, evidence refreshes, and recurring status deliverables.
- Support security impact analyses for proposed system changes by documenting affected components, controls, evidence, and authorization artifacts.
- Review vulnerability scan results, STIG or CIS benchmark results, and configuration data; connect technical findings to NIST controls and remediation activities.
- Maintain accurate system records, workflows, and authorization artifacts in federal governance, risk, and compliance tools such as eMASS, JCAM, CSAM, or Xacta.
- Perform first-level quality checks using established templates and checklists to identify missing information, inconsistent dates, unsupported conclusions, and formatting issues.
- Track assigned deliverables and commitments, communicate progress clearly, and raise blockers or emerging risks promptly.
- Collaborate with engagement team members and client stakeholders, incorporate feedback, and complete assigned work within expected timeframes.
- Stay current on federal cybersecurity requirements and continue developing technical, writing, and RMF delivery skills.
Required Qualifications
- Education: Bachelor's degree in cybersecurity, information technology, information systems, computer science, engineering, business, or a related field.
- Experience: 1-3+ years of experience in cybersecurity, technology risk, compliance, or information technology, including hands-on experience supporting federal RMF activities.
- Ability to obtain and maintain a secret level clearance.
- Comfort working in a hybrid environment.
- Experience developing or maintaining RMF documentation, collecting and organizing control evidence, supporting assessment readiness, tracking POA&Ms, or executing continuous monitoring activities.
- Experience developing or maintaining at least one of the following:
- Federal authorization package development and maintenance
- NIST SP 800-53 control implementation statements and evidence mapping
- Security control assessment preparation and response coordination
- POA&M tracking, remediation support, or continuous monitoring reporting
- Federal governance, risk and compliance tools such as eMASS, JCAM, CSAM, or Xacta
- Technical security artifacts such as network diagrams, inventories, vulnerability scans, STIG or CIS benchmark results, change records, or configuration data
- Flexibility to travel up to 20%.
Technologies
- NIST CSF
- NIST 800-53r5
- NIST 800-37r2
- NIST SP 800-60
- FIPS 199
- NIST SP 800-53
- NIST SP 800-37
- NIST 800-53A
- FIPS 200
- FISMA
- eMASS
- JCAM
- CSAM
- Xacta
- POA&M
- STIG
- CIS benchmarks
- FIPS 199 security categorization
Benefits
- Comprehensive compensation and benefits package
- Base salary range (varies by location)
- Medical and dental coverage
- Pension and 401(k) plans
- Paid time off options
- Flexible vacation policy
- Time off for designated EY Paid Holidays, Winter/Summer breaks, Personal/Family Care, and other leaves of absence
Preferred Qualifications
- CompTIA Security+, ISC2 CGRC, or another relevant cybersecurity or risk management certification
- Prior experience supporting a federal agency, consulting engagement, service delivery center, or managed service
What the Role Emphasizes
- Taking ownership of assigned work
- Attention to detail in federal RMF delivery
- Clear communication and collaboration
- Constructive responsiveness to feedback and thoughtful questioning