ISSO Senior Analyst
Senior
Fisma
Fisma Compliance
Information Security
InfoSec
ISSO
Nist Cybersecurity Framework
Nist Sp 800 53
NIST SP 800-53
Risk Management
Rmf
Security Compliance
Security Controls Assessment
Security Standards
Security Standards And Compliance
Security Standards And Frameworks
Security Standards Compliance
Job Description
Context: The ISSO Senior Analyst role supports federal systems across the NIST RMF lifecycle by owning authorization workstreams and delivering security control assessment documentation.
Responsibilities
- Own RMF delivery workstream for assigned systems by maintaining security posture documentation and supporting system owners and government ISSMs throughout the authorization lifecycle.
- Use NIST SP 800-53A assessment procedures alongside NIST SP 800-53 controls and applicable overlays to select examination, interview, and test methods, judge evidence sufficiency, and document objective results with traceability from implementation statements to architecture and evidence.
- Develop and maintain core authorization artifacts, including System Security Plans, Security Assessment Plans, Security Assessment Reports, control implementation statements, and supporting appendices.
- Perform analysis for information types and impact analysis, including FIPS 199 categorization and NIST SP 800-60 mapping; identify stakeholders and roles; document authorization boundary rationale and risk context.
- Define and document system boundary information and authorization boundaries, component inventories, data flows, interconnections, and inherited or shared controls.
- Determine control baseline selection, tailoring, overlays, scoping, parameter assignment, compensating controls, and common-control inheritance based on system architecture and hosting model.
- Draft findings and create POA&M items linking condition and evidence to control requirements, including threat and vulnerability context, likelihood, impact, recommended action, and acceptance criteria.
- Manage POA&M execution for assigned systems, including remediation tracking, evidence validation, closure packages, and deviation or risk acceptance documentation.
- Execute NIST 800-137 continuous monitoring and event-driven monitoring activities, including control review cycles, vulnerability management reporting, configuration compliance tracking, and monthly reporting deliverables.
- Conduct security impact analyses for proposed changes and document results for system owner review.
- Review scan results and STIG or CIS benchmark results; validate findings, distinguish false positives, and connect technical evidence to NIST controls.
- Maintain accurate system records and authorization artifacts in governance, risk, and compliance tools such as eMASS, JCAM, and Xacta.
- Facilitate evidence-gathering sessions and control interviews with system owners, engineers, and application teams.
- Coordinate assigned workstreams, review Analyst deliverables for quality and consistency, provide task-level guidance, manage dependencies, and escalate risk.
- Track delivery commitments, monitor schedule and quality risks, and escalate issues to engagement leadership.
- Provide day-to-day coaching to Analysts on assessment procedures, evidence expectations, and documentation standards.
- Review Analyst work products for accuracy, completeness, and consistency before submission; provide specific, actionable feedback.
- Use knowledge of cybersecurity industry trends to identify engagement and client service issues and communicate through written correspondence and verbal presentations.
- Stay current on cybersecurity industry trends relevant to delivered services.
Requirements
- Bachelor’s degree in cybersecurity, information technology, information systems, computer science, engineering, business, or related field.
- Minimum 3 years of related work experience in cybersecurity, technology risk, compliance, or information technology, including hands-on federal RMF support.
- Ability to obtain and maintain a secret level clearance.
- Comfortable working in a hybrid setting.
- Experience developing or maintaining RMF documentation, collecting and organizing control evidence, supporting assessment readiness, tracking POA&Ms, or executing continuous monitoring activities.
- Experience in one or more areas such as:
- Federal authorization package development and maintenance.
- NIST SP 800-53 control implementation statements and evidence mapping.
- Security control assessment preparation and response coordination.
- POA&M tracking, remediation support, or continuous monitoring reporting.
- Federal governance, risk, and compliance tools such as eMASS, JCAM, CSAM, or Xacta.
- Technical security artifacts such as network diagrams, inventories, vulnerability scans, STIG or CIS benchmark results, change records, or configuration data.
- Flexibility to travel up to 20%.
Technologies
- NIST CSF
- NIST 800-53r5
- NIST 800-37r2
- NIST SP 800-53A
- NIST SP 800-53
- NIST SP 800-60
- NIST SP 800-30
- NIST SP 800-137
- FIPS 199
- FISMA
- eMASS
- JCAM
- Xacta
- CSAM
- STIG
- CIS
- FISMA and relevant agency-specific policies
Ideally, You’ll Also Have
- CISSP, CISM, CISA, CGRC, CIPT, CIPM, CIPP, CRISC, or other relevant certification.
- Prior experience supporting a federal agency, consulting engagement, service delivery center, or managed service.
Skills and Attributes for Success
- Applied knowledge of federal security frameworks and standards including NIST SP 800-37, 800-53/53A, 800-60, 800-30, 800-137, FIPS 199/200, FISMA, and relevant agency-specific policies.
- Applied knowledge of the NIST Risk Management Framework and security control assessment methodology.
- Ability to analyze technical information and translate it into clear control documentation.
- Ability to manage multiple systems or workstreams concurrently.
- Ability to review work products for quality and consistency.
- Clear communication with technical stakeholders and engagement leadership.
Location: San Antonio, TX (hybrid)