Junior Information System Security Officer (REMOTE)
Dragonfli Group · United States · 1 wk ago
RemoteRemoteInformation TechnologyFull-time
Responsibilities
- Support RMF lifecycle activities for assigned federal information systems, including categorization, control implementation, assessment, and continuous monitoring, under the guidance of senior team members
- Aid in developing and updating system security documentation, including SSPs, Security Assessment Reports (SARs), and POA&Ms
- Help track and document security control deviations and vulnerabilities through to closure
- Support continuous monitoring activities, including log review and vulnerability scan analysis, alongside senior ISSOs
- Maintain system inventory, hardware/software baselines, and interconnection agreements
- Aid in incident response documentation, escalation tracking, and remediation follow-up
- Participate in security reviews, audits, and inspections as part of the broader team
- Cook up with Information System Owners (ISOs) and other stakeholders on routine compliance tasks
- Coordinate with senior ISSOs on routine compliance tasks
Requirements
- Must-Have:
- 0–2 years of experience in IT, cybersecurity, information assurance, or a related military/government role (direct ISSO experience is not required)
- Working knowledge of the NIST Risk Management Framework (RMF) and NIST SP 800-53 security controls, gained through training, coursework, or certification study
- U.S. Citizenship required; must be able to pass a background investigation for a Public Trust position
- Ability to work remotely and collaborate during core business hours (9am–5pm ET)
- Strong written communication skills
- Preferred / Nice-to-Have:
- Background in IT, communications, electronics, or a security-adjacent role
- Exposure to GRC/compliance tools such as eMASS or Xacta
- Bachelor's degree in IT, cybersecurity, or a related field (or equivalent experience)
- Prior experience in identity and access management (IAM), credentialing, or access control
- Familiarity with FISMA and OMB A-130 requirements
- Active CompTIA Security+ or (ISC)² Certified in Cybersecurity (CC) certification
Skills
- Technical Skills:
- RMF fundamentals and the ATO lifecycle
- NIST 800-53 control families (foundational awareness)
- Identity and access management / access control concepts
- Exposure to GRC or vulnerability scanning tools (e.g., ACAS, STIGs) a plus
- Documentation and technical writing (SSPs, POA&Ms)
- MS Office / SharePoint
- Soft Skills:
- Clear, professional written and verbal communication
- Attention to detail and follow-through
- Ability to learn quickly and take direction from senior team members
- Collaboration across distributed, remote teams
- Discretion and trustworthiness handling sensitive information
- Self-motivation in a remote work environment
Benefits
- Medical — Multiple POS health plan options including an HSA-compatible plan
- Dental — PPO coverage for preventive, basic, and major services
- Vision — Annual exam, frames, lenses, and contact lens allowance
- 401(k) — Employer match up to 5% of eligible compensation
- Long-Term Disability — 100% employer-paid coverage at 50% of pre-disability earnings
- Life Insurance & AD&D — 100% employer-paid coverage valued at $10,000 each
- PTO
- 11 Paid Federal Holidays