user avatar

Information System Security Officer (ISSO)

Kentro

Posted today

Job Requirements

Remote
Public Trust Polygraph Unspecified
Career Level not specified
Salary not specified
Join Premium to unlock estimated salaries

Job Description

Overview

Thank you for considering IT Concepts dba Kentro, where innovation drives opportunity and collaboration leads to success. Our dynamic community of experts is fully committed to advancing our customers' missions, fostering professional growth, and making a positive impact on our communities.

By joining our supportive community, you will find that Kentro is dedicated to your personal and professional development. Together, we can drive meaningful change, spark innovation, and achieve extraordinary milestones.

Kentro is hiring for an Information System Security Officer (ISSO) in support of a comprehensive cybersecurity modernization and Artificial Intelligence (AI) enabled automation project for a U.S. Government program that includes cybersecurity engineering, defense operations, continuous monitoring, Risk Management, security assessments and compliance, and cybersecurity automation platforms. This modernization effort encompasses the security tools, processes, and workflows that support the client's full cybersecurity mission - transitioning from legacy manual approaches to an integrated, automated, AI-enabled operating model that streamlines cybersecurity processes and workflows while reducing the operational burden and improving the overall cybersecurity posture of the client's enterprise systems.

The Information Systems Security Officer (ISSO) is responsible for day-to-day Risk Management Framework (RMF) execution, continuous monitoring, and authorization support across assigned FISMA systems under the modernization effort. The ISSO serves as the primary point of authority for system security documentation, reviews and approves AI generated risk scoring outputs before they inform authorization decisions and maintains the compliance posture of assigned systems in coordination with the CISO, Authorizing Official, and program management. In addition, the ISSO is responsible for ensuring AI-enabled systems are developed, deployed, and operated in accordance with the NIST Risk Management Framework (RMF), applicable federal cybersecurity requirements, and organizational AI governance policies. In this role, the ISSO works closely with program management, system administrators, engineers, AI developers, cloud architects, DevSecOps teams, Information System Security Engineers (ISSEs), Authorizing Officials (AOs), and government stakeholders to maintain system authorization, implement security controls, monitor cybersecurity risks, and support continuous monitoring activities.

Location: This position can be performed remotely from anywhere within the United States and will support Eastern Time business hours. Occasional onsite work at the customer site in Washington, DC may be required. Candidates located in the DC, Maryland, and Virginia (DMV) area are preferred.

Compensation Range: The salary for this position is between $Min-Max/annually. Factors affecting pay within this range may include geography/market, skills, education, experience, and other qualifications of the successful candidate.

Responsibilities

  • Serve as the cybersecurity lead for information systems and AI-enabled systems throughout the system development lifecycle (SDLC), delivery and operations.
  • Author and approve the System Security Plan (SSP) as primary approver under NIST SP 800-18.
  • Provide Privacy Impact Assessment (PIA) oversight and sign off authority, coordinating with the Privacy Officer.
  • Review, execute and maintain Interconnection Security Agreement (ISA) for platform automation interconnections.
  • Support 3PAO and FedRAMP Moderate assessment activities tied to SSP completion, ISA execution, and remediation of assessment findings.
  • Author and lead Security Privacy Impact Analysis (SPIA) efforts as required.
  • Implement and maintain the NIST Risk Management Framework (RMF) for AI-enabled systems in accordance with NIST SP 800-37, NIST SP 800-53, and applicable agency guidance.
  • Ensure implementation and continuous compliance with NIST SP 800-53 security controls.
  • Develop, maintain, and update RMF artifacts as required.
  • Review and sign off on AI generated SSP control narratives before submission. No AI generated content may be submitted without ISSO review.
  • Review AI Generated risk scores generated from RMF documentation before any authorization decision is made.
  • Validate the implementation of technical, operational, and management controls.
  • Support internal and external security audits, inspections, and assessments.
  • Coordinate vulnerability scanning activities and ensure timely remediation of identified vulnerabilities.
  • Review and analyze Security Technical Implementation Guides (STIGs), Security Requirements Guides (SRGs), and vulnerability assessment results.
  • Track, document, and report POA&Ms, cybersecurity findings and POA&Ms remediation efforts and closures.
  • Support security authorization activities, including Authorization to Operate (ATO), Interim Authorization to Test (IATT), and system reaccreditation efforts.
  • Monitor system security posture through continuous monitoring (ConMon) activities.
  • Assess the security impact of proposed system changes.
  • Review system architecture, software releases, and infrastructure changes for cybersecurity implications.
  • Coordinate incident reporting and assist with cybersecurity incident response activities.
  • Maintain accurate cybersecurity documentation and security records.
  • Support AI governance activities by helping ensure AI systems meet organizational requirements for security, privacy, transparency, accountability, and risk management.
  • Define and maintain the authorization boundary for AI components, including models, training and inference pipelines, retrieval sources, and vector stores, and determine what sits inside the existing boundary versus what requires separate authorization.
  • Determine which NIST SP 800-53 controls require AI-specific tailoring or supplemental implementation guidance, and document the tailoring rationale in the SSP.
  • Support privacy threshold and impact assessments for AI components processing PII, including whether AI-derived outputs constitute a new use requiring notice.
  • Represent the system security position to the agency AI governance process, and align system-level AI decisions with agency AI policy and the agency AI use case inventory obligations.
  • Provide cybersecurity guidance to system administrators, developers, engineers, and program leadership.
  • Ensure compliance with applicable federal laws, regulations, executive orders, and agency cybersecurity policies.

Qualifications

  • Bachelor's degree in Cybersecurity, Information Technology, Computer Science, Information Systems, or related discipline. Equivalent experience may be substituted.
  • 5-8 years of experience supporting cybersecurity or information assurance supporting civilian federal agencies or Department of Defense.
  • Experience implementing the NIST Risk Management Framework (RMF).
  • Working knowledge of NIST SP 800-37, NIST SP 800-53, NIST AI Risk Management Framework (AI RMF), FISMA, FedRAMP, Security Technical Implementation Guides (STIGs) and Continuous Monitoring (ConMon)
  • Experience with security documentation, system authorization packages, and audit support.
  • Strong analytical, organizational, and technical writing skills.
  • Ability to communicate (verbal and written) effectively with technical teams, program leadership, and government customers.

Preferred Qualifications:
  • Experience with electronic governance, risk and compliance (GRC) tools such as eMASS, ServiceNow, etc.
  • Knowledge of Zero Trust Architecture principles, identity management, cloud-native security services, SIEM platforms, and endpoint protection technologies.
  • Familiarity with security tools such as RegScale, Splunk, Qualys, Tenable Nessus, CyberArk or similar solutions.
  • Familiarity with enterprise Windows, Linux, virtualization, cloud, DevSecOps and network environments.
  • Familiarity with AI/ML concepts, including model development lifecycles, data pipelines, and AI-enabled applications.
  • Experience supporting AI workloads in Microsoft Azure Government, AWS GovCloud or hybrid cloud environments.

Clearance Requirement:
  • Willing and able to obtain and maintain Public Trust Clearance
  • Must meet updated ID requirements: https://www.gsa.gov/technology/it-contract-vehicles-and-purchasing-programs/federal-credentialing-services/get-appointment-help/bring-required-documents
    • If you do not currently meet the ID requirements outlined, you must be willing and able to update your current forms of ID in a timely manner to complete the suitability process successfully.

Benefits

The Company

We believe in generating success collaboratively, enabling long-term mission success, and building trust for the next challenge. With you as our partner, let's solve challenges, think innovatively, and maximize impact. As a valued member of our team, you have the unique opportunity to work in a diverse range of technology and business career paths, all while supporting our nation and delivering innovative technology solutions. We are a close community of experts that pride ourselves on creating an environment defined by teamwork, dedication, and excellence.

We hold three ISO certifications (27001:2013, 20000-1:2011, 9001:2015), two CMMI ML 3 ratings (DEV and SVC) and CMMC Level 2 Certification.

Industry Recognition

Growth | Inc 5000's Fastest Growing Private Companies, DC Metro List Fastest Growing; Washington Business Journal: Fastest Growing Companies, Top Performing Small Technology Companies in Greater D.C.

Culture | Northern Virginia Technology Council Tech 100 Honoree; Virginia Best Place to Work; Washington Business Journal: Best Places to Work, Corporate Diversity Index Winner - Mid-Size Companies, Companies Owned by People of Color; Department of Labor's HireVets for our work helping veterans transition; SECAF Award of Excellence finalist; Victory Military Friendly Brand; Virginia Values Veterans (V3); Cystic Fibrosis Foundation Corporate Breath Award

Benefits

We offer competitive benefits package including paid time off, healthcare benefits, supplemental benefits, 401k including an employer match, discount perks, rewards, and more. We invest in our employees - Every employee is eligible for education reimbursement for certifications, degrees, or professional development. Reimbursement amounts may fluctuate due to IRS limitations. We want you to grow as an expert and a leader and offer flexibility for you to take a course, complete a certification, or other professional growth and networking. We are committed to supporting your curiosity and sustaining a culture that prioritizes commitment to continuous professional development.

We work hard; we play hard. Kentro is committed to incorporating fun into every day. We dedicate funds for activities - virtual and in-person - e.g., we host happy hours, holiday events, fitness & wellness events, and annual celebrations. In alignment with our commitment to our communities, we also host and attend charity galas/events. We believe in appreciating your commitment and building a positive workspace for you to be creative, innovative, and happy.

Commitment Equal Opportunity Employment & VEVRAA

Kentro is an equal opportunity employer. All qualified applicants will receive consideration for employment without regard to disability, status as a protected veteran or any other status protected by applicable federal, state or local law.

Kentro is strongly committed to compliance with VEVRAA and other applicable federal, state, and local laws governing equal employment opportunity. We have developed comprehensive policies and procedures to ensure our hiring practices align with these requirements.

As part of our VEVRAA compliance efforts, Kentro has established an equal opportunity plan outlining our commitment to recruiting, hiring, and advancing protected veterans. This plan is regularly reviewed and updated to ensure its effectiveness.

We encourage protected veterans to self-identify during the application process. This information is strictly confidential and will only be used for reporting and compliance purposes as required by law. Providing this information is voluntary and will not impact your employment eligibility.

Our commitment to equal employment opportunity extends beyond legal compliance. We are dedicated to fostering an inclusive workplace where all employees, including protected veterans, are treated with dignity, respect, and fairness.

How to Apply

To apply to Kentro Positions- Please click on the job link and then click the blue "Apply" button at the top right of Job Description. Please upload your resume and complete all the application steps. You must fully submit the application for Kentro to consider you for a position. If you need alternative application methods, please email careers@kentro.us and request assistance.

Accommodations

To perform this job successfully, an individual must be able to perform each essential duty satisfactorily. Reasonable Accommodations may be made to enable qualified individuals with disabilities to perform the essential functions. If you need to discuss reasonable accommodations, please email careers@kentro.us .
group id: 10484831

Similar Jobs


Job Category
IT - Security
Clearance Level
Public Trust
Employer
Kentro