Why This Role Stands Out
Elevate your career in cybersecurity by supporting a critical U.S. government agency, leveraging your expertise to ensure system authorization and compliance in a hybrid environment. This role offers significant growth potential for security professionals who excel at technical risk assessment and collaborative validation, contributing to a company recognized for its commitment to innovation and employee success.
Quick Overview
Job Description
ABOUT PRISM PRISM is devoted to modernization and innovation across technology, security, and IT enterprise solutions. We are recognized for meeting performance requirements and exceeding customer expectations since 1994. Our culture is founded on relationships, opportunity, and success. Offering comprehensive benefit plans including medical, dental, vision, and 401K along with our people - first approach sustains our reputation as a premier employer. PRISM is seeking a Senior Information Systems Security Officerto support a critical U.S. government agency in the National Capital Region.
This role reports to the Security Program Management Office (SPMO) Manager and works directly with team members and Federal ISSOs to support authorization, compliance, continuous monitoring, and risk management activities across assigned systems. This is an excellent opportunity for an experienced cybersecurity professional with a strong technical background to support the secure authorization and ongoing compliance of systems across on-premises and cloud environments. This is not a hands-on engineering position.
Instead, the Senior ISSO leverages prior experience as a Systems Administrator, Cloud Engineer, Infrastructure Engineer, Network Engineer, Security Engineer, or similar technical role to independently validate security implementations, assess technical risk, and ensure authorization decisions are supported by accurate technical evidence. The successful candidate must be comfortable engaging engineers, architects, and system owners to validate security controls, identify inconsistencies, and challenge unsupported technical assumptions.
This is a hybrid position with 3 days on site in Washington, D.C.
RESPONSIBILITIES
- Support the security authorization lifecycle and ongoing continuous monitoring activities for assigned systems.
- Develop, review, and maintain security documentation and authorization artifacts, including SSPs, SARs, POA&Ms, SIAs, and related documentation, in accordance with NIST SP 800-53, RMF, FISMA, and agency policies.
- Coordinate and prepare systems for Security Control Assessments (SCAs), ensuring documentation and evidence are complete, accurate, and technically defensible.
- Conduct Security Impact Analyses (SIAs) for changes to hardware, software, cloud infrastructure, connectivity, or system architecture.
- Review system architecture, technical documentation, and supporting evidence to validate security controls, independently assess technical implementations, identify inconsistencies, and collaborate with engineers, architects, administrators, and system owners to resolve discrepancies.
- Support change management, continuous monitoring, POA&M management, risk acceptance, audit responses, and remediation activities to maintain ongoing authorization and compliance.
- Coordinate with system owners, engineers, architects, and governance stakeholders to support standards reviews, exception requests, policy implementation, compliance reporting, and risk management activities.
- Develop dashboards, executive risk briefings, status reports, and other stakeholder communications while supporting the Lead ISSO in operational execution and coordination activities. REQUIRED QUALIFICATIONS (SKILLS/EDUCATION):
- Bachelor's degree and 5+ years of relevant experience, or a master's degree and 3+ years of experience, in cybersecurity, RMF, ISSO, systems security engineering, systems administration, cloud engineering, network engineering, or a related field.
- Prior hands-on experience in a technical role such as Systems Administrator, Cloud Engineer, Infrastructure Engineer, Network Engineer, or Security Engineer, with the ability to evaluate technical implementations, validate controls, assess evidence, and challenge unsupported assumptions.
- Experience supporting federal authorization activities, including SSPs, POA&Ms, SIAs, continuous monitoring, and Security Control Assessments.
- Working knowledge of NIST RMF, NIST SP 800-53, FISMA, and federal cybersecurity requirements.
- Familiarity with enterprise and cloud technologies such as AWS, Azure, Microsoft 365, Entra ID, Active Directory, VMware, Cisco, Oracle, or similar platforms.
- Working knowledge of identity and access management, encryption, system hardening, network and cloud security, secure baselines, logging, and monitoring.
- Experience with GRC or security authorization tools such as Archer, eMASS, JCAM/CSAM, Xacta, or similar platforms.
- Strong analytical, technical writing, organizational, and communication skills, including demonstrated professional proficiency in written and spoken English. Ability to independently produce polished, technically accurate documentation; communicate clearly and effectively with technical and non-technical stakeholders; work independently; and manage competing priorities in a fast-paced environment.
- Proficiency with Microsoft Word, Excel, PowerPoint, and SharePoint.
PREFERRED QUALIFICATIONS
- Security+, CGRC (formerly CAP), CISSP, CISM, CCSP, or similar cybersecurity certification.
- Experience supporting federal systems, ATO processes, FedRAMP, federal privacy requirements, or other government compliance programs.
- Knowledge of modern cybersecurity practices including OWASP Top 10, Zero Trust, application security concepts, and MITRE ATT&CK.
- Experience participating in incident response, security architecture reviews, technical design reviews, or security remediation efforts.
- Experience operating in fast-paced, high-visibility environments with competing priorities.
REQUIRED SECURITY CLEARANCE: Ability to obtain a Public Trust. PRISM is an Equal Opportunity/Affirmative Action employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability, or veteran status, or any other protected class.
Similar jobs
- MT
Security Operations / Network Security Specialist / Lead at NYC, NY - Onsite
NewMagnum Technologies, Inc.
New York, NY🇺🇸Hybrid18 hours agoAdministrative - KT
Embedded Systems Security Engineer
NewKforce Technology Staffing
Foster City, CA🇺🇸Hybrid18 hours agoEmbedded SystemsEncryptionBash+6Technology - QW
OT Security Engineer
NewQuantum World Technologies Inc.
San Diego, CA🇺🇸On-site18 hours agoIoTTechnology - DD
Information Assurance Specialist with Security Clearance
NewDiné Development Corporation
Fort Huachuca, AZ🇺🇸Hybrid18 hours agoAdministrative - CO
Regional Senior Cybersecurity Coordinator
NewContinental
Rock Hill, SC🇺🇸Hybrid4 hours agoTechnology - IS
Information Systems Security Engineer-(TS/SC w/Poly)-Chantilly, with Security Clearance
NewiSenpai, LLC
Chantilly, VA🇺🇸Hybrid18 hours agoTechnology