Position Title: Information System Security Officer (ISSO)
Location: Remote (U.S.) with Occasional Travel
Client: Federal / Public Sector Programs
Work Authorization: Candidates must be authorized to work in the United States. U.S. Citizenship may be required based on client assignment.
📩 To apply, please submit your resume to careers@wintrio.com or complete the application form below.
Job Summary
WINTrio LLC is seeking an experienced Information System Security Officer (ISSO) to support Federal information systems through security documentation, security control implementation, continuous monitoring, vulnerability management, and security authorization activities.
The ideal candidate will possess hands-on experience supporting Federal cybersecurity and compliance programs and will work closely with System Owners, Information System Security Managers (ISSMs), Security Control Assessors (SCAs), developers, administrators, cloud teams, and program leadership to maintain system compliance and improve overall cybersecurity posture.
This role is well suited for cybersecurity professionals with experience supporting Risk Management Framework (RMF), Authority to Operate (ATO), security documentation, POA&M management, vulnerability remediation, and ongoing compliance activities within Federal environments.
Job Responsibilities
- Support RMF and ATO activities for Federal applications, infrastructure, databases, cloud-hosted systems, and enterprise platforms.
- Develop, review, and maintain cybersecurity documentation, including System Security Plans (SSPs), Contingency Plans (CPs), Incident Response Plans (IRPs), Configuration Management Plans (CMPs), Risk Assessments, Privacy Threshold Analyses (PTAs), Privacy Impact Assessments (PIAs), and supporting artifacts.
- Track and validate security controls against NIST SP 800-53 requirements, agency security policies, and system-specific baselines.
- Monitor vulnerability scan results, coordinate remediation activities with technical teams, and validate evidence supporting closure of findings.
- Support continuous monitoring activities, annual security assessments, control reviews, security audits, and compliance reporting requirements.
- Coordinate with Security Control Assessors, Authorizing Officials, System Owners, developers, administrators, privacy personnel, and program leadership.
- Review system changes and architecture modifications to identify potential security impacts and support change control processes.
- Maintain security posture dashboards, compliance trackers, risk registers, and status reports.
- Support incident response documentation, evidence collection, reporting, corrective actions, and lessons-learned activities.
- Ensure security documentation remains current following releases, infrastructure modifications, cloud migrations, and technology updates.
- Support audit readiness efforts and assist with preparation for security assessments, authorization reviews, and compliance inspections.
- Contribute to continuous improvement initiatives that strengthen system security and compliance maturity.
Required Qualifications
- Bachelor’s degree in Cybersecurity, Information Technology, Computer Science, Engineering, or a related field.
- Minimum five (5) years of cybersecurity, information assurance, or information security experience supporting Federal systems.
- Experience supporting RMF, ATO, security documentation, POA&M management, and continuous monitoring activities.
- Strong understanding of NIST SP 800-53 security controls, RMF processes, and FISMA compliance requirements.
- Experience reviewing vulnerability scan results and coordinating remediation activities.
- Experience working with security documentation, control implementation, and compliance evidence collection.
- Strong written and verbal communication skills.
- Ability to communicate cybersecurity requirements effectively to both technical and non-technical stakeholders.
- Strong organizational, analytical, and problem-solving abilities.
Technical Areas
Cybersecurity Governance & Compliance
- NIST Risk Management Framework (RMF)
- NIST SP 800-37
- NIST SP 800-53
- FISMA
- FedRAMP
- Security Authorization Support
- Continuous Monitoring
- Security Control Validation
Security Documentation
- System Security Plans (SSP)
- Security Assessment Reports (SAR)
- Risk Assessment Reports (RAR)
- Plans of Action & Milestones (POA&M)
- Privacy Threshold Analysis (PTA)
- Privacy Impact Assessment (PIA)
- Business Impact Analysis (BIA)
- Contingency Plans (CP)
- Incident Response Plans (IRP)
- Configuration Management Plans (CMP)
Vulnerability Management
- Vulnerability Assessments
- Security Findings Analysis
- Risk-Based Remediation
- Compliance Tracking
- Security Control Evidence Validation
Cloud & Enterprise Security
- AWS GovCloud
- Microsoft Azure Government
- Cloud Security Controls
- Hybrid Cloud Security
- Security Architecture Reviews
Tools & Platforms
ATO & GRC Platforms
- eMASS
- Xacta
- CSAM
- RSA Archer
- ServiceNow
- RegScale
Vulnerability & Security Assessment Tools
- ACAS
- Nessus
- Tenable
- Qualys
- Rapid7
Application Security Tools
- WebInspect
- Fortify
- SonarQube
- SAST Tools
- DAST Tools
Monitoring & Security Operations
- Splunk
- Azure Monitor
- AWS CloudWatch
- ELK Stack
Configuration & Compliance Tools
- STIG Viewer
- SCAP
- CIS-CAT
- DISA STIGs
- CIS Benchmarks
Collaboration & Reporting
- JIRA
- Confluence
- SharePoint
- Microsoft Teams
- ServiceNow
Preferred Certifications
- CompTIA Security+
- Certified Information Systems Security Professional (CISSP)
- Certified Authorization Professional (CAP)
- Certified Information Security Manager (CISM)
- CompTIA Advanced Security Practitioner (CASP+)
- Certified Cloud Security Professional (CCSP)
- Certified Ethical Hacker (CEH)
- ITIL Foundation
- AWS Certified Cloud Practitioner
- Microsoft Azure Fundamentals
Preferred Qualifications
- Experience supporting DHS, USDA, IRS, CBP, DoD, or other Federal agencies.
- Experience working with cloud-hosted systems in AWS GovCloud or Microsoft Azure Government environments.
- Experience supporting Agile, DevSecOps, or cloud modernization initiatives.
- Experience preparing systems for security assessments, audits, or authorization renewals.
- Familiarity with ongoing authorization and continuous monitoring environments.
- Experience supporting enterprise cybersecurity and compliance programs.
Work Environment
- Full-time position.
- Remote within the United States.
- Standard business hours Monday through Friday.
- Occasional travel may be required in support of customer meetings, security assessments, and program activities.
WINTrio Benefits
- Healthcare (Medical, Dental, and Vision)
- Flexible Spending Account (FSA) and Health Savings Account (HSA)
- 401(k) and Retirement Savings Plan
- Annual Bonus and Profit Sharing Opportunities
- Paid Time Off (PTO) and Vacation
- Employee Assistance Program (EAP)
- Life, Personal, and Voluntary Disability Insurance
Growth Opportunities
There is ample opportunity to grow in multiple dimensions, including cybersecurity leadership, cloud security, compliance modernization, Zero Trust Architecture, DevSecOps, risk management, program management, and business development. We are a completely employee-driven company, and our continued success is built on the talent, dedication, and innovation of our team members.
Equal Opportunity Employer
WINTrio LLC is an Equal Opportunity/Affirmative Action Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, gender identity, sexual orientation, national origin, age, disability, protected veteran status, or any other characteristic protected by applicable federal, state, or local law.