Find Jobs
Find Jobs Near You – Available Work in Your Location
Skip to job details
A
Amazon
Information System Security Officer (ISSO), US ADC Security
Career Insights for Cyber Security Analyst
See where this job fits in the broader career landscape. Knowing your career path helps you see what's possible from here.
Scorecard
Based on Virginia data
Review key factors to help you decide if this role fits your goals. How is this calculated?
What they do
A Cyber Security Analyst works on monitoring, controlling, and maintaining systems that protect the security of large databases, including databases with customer information and patient files. Analyzes the examination of client computer systems, identification of weak points in security, development and implementation of new systems, and monitoring and response to security issues.
$131,968 / year median in Virginia
-4% projected decline
Job Description
Job Requirements Herndon, VA Top Secret/SCI Polygraph Career Level not specified Salary not specified Join Premium to unlock estimated salaries Job Description Description Amazon Web Services (AWS) Security is seeking an Information System Security Officer (ISSO) to assess, authorize, and continuously defend information systems supporting a high-priority U.S. Government program. In this role, you will develop, maintain, and continuously improve the System Security Plan (SSP), security control implementation evidence, and the supporting body of evidence. You will drive Assessment & Authorization (A&A) activities, coordinating security control assessments, managing Plans of Action & Milestones (POA&Ms), and sustaining continuous monitoring in accordance with the NIST Risk Management Framework (RMF). Working alongside the Information System Security Manager (ISSM), platform build and engineering teams, and U.S. Government counterparts, you will ensure controls are properly implemented, documented, and defensible throughout the full RMF lifecycle. You will also proactively identify security gaps, recommend remediation strategies, and help maintain the system's authorization posture. This position requires U.S. Citizenship and an active TS/SCI security clearance with polygraph. Key job responsibilities
- Develop, maintain, and continuously improve the System Security Plan (SSP) and all supporting authorization documentation.
- Prepare and maintain security control implementation evidence and the body of evidence required for system authorization.
- Coordinate and support security control assessments.
- Manage Plans of Action & Milestones (POA&Ms) from identification through closure, ensuring timely remediation of findings.
- Execute continuous monitoring activities in accordance with the NIST Risk Management Framework (RMF) and organizational policies.
- Partner with platform build and engineering teams to ensure security controls are properly implemented, configured, and documented.
- Collaborate with the Information System Security Manager (ISSM) and U.S. Government counterparts throughout the full RMF lifecycle.
- Proactively identify security gaps and vulnerabilities, recommend remediation strategies, and track resolution to completion.
- Support audit readiness and respond to ad hoc security inquiries from government stakeholders.
- Contribute to the development and refinement of security processes, templates, and automation to improve A&A efficiency.
- 3+ years of RMF/A&A or ISSO experience.
- Working knowledge of NIST 800-53, RMF, and SSP development.
- Working knowledge of Service Now to apply the RMF
- Experience producing authorization artifacts and evidence.
- Current, active US Government Security Clearance of TS/SCI with Polygraph Preferred Qualifications
- Experience with U.S. Government/IC RMF and ICD 503 authorization.
- Familiarity with the Government-provided RMF workflow tooling.
- Security certification (e.
- 102,000.00
- 178,400.
Benefits
- Paid Time Off (PTO)
- 401(k) Plans
- Mental Health
- Health and Wellness Programs