Job description
Description
Dragonfli Group is a cybersecurity and IT consulting firm providing services to federal agencies and Fortune 100 enterprises. Headquartered in Washington, DC, Dragonfli supports clients in securing mission-critical systems across on-site, hybrid, and fully remote environments.
Dragonfli Group is seeking a Junior Information System Security Officer (ISSO) to support a multi-year cybersecurity program for a large federal agency. You will develop and maintain System Security Plans and the related security documentation that carries systems through authorization, and you will support the activities that help those systems obtain and maintain an Authorization to Operate. Day to day, you will be the security point of contact for software developers, project managers, and other team members inside your ATO boundary, helping them find practical ways to meet security requirements without stalling delivery. This role suits someone with roughly 2 years of ISSO experience who wants ownership of real systems while working under the guidance of a lead or senior ISSO.\
This is a multi-year contract position involving a large US federal agency. Candidates with previous federal contracting experience are preferred. U.S. Citizenship or Permanent Residency is required. If hired, all work related to this role must be performed within the continental U.S.
This position is fully remote. The agency's Rules of Behavior and Telework Policy apply to all contractor personnel and require, among other things, that laptop cameras be turned on and that staff remain visible on camera during all meetings.
Responsibilities
Develop and maintain System Security Plans (SSPs) and related security documentation
Support the activities that help systems obtain and maintain an Authorization to Operate (ATO)
Assist with oversight of the information systems security program for applications and systems within the ATO boundary
Provide day-to-day security support and guidance to software developers, project managers, and other team members
Help identify practical ways to meet security requirements with minimal impact to delivery schedules
Escalate complex or ambiguous security issues to the lead or senior ISSO with the context needed to resolve them
Support execution of Risk Management Framework tasks including categorization, control selection, implementation, assessment, and authorization in accordance with NIST SP 800-37
Support continuous monitoring activities and keep authorization artifacts current
Support System Owner system access reviews and account management compliance
Contribute to the use of automation and AI tooling that streamlines RMF documentation and control assessment work
Requirements
Must-Have
Bachelor's degree in cybersecurity, information technology, or a related field
2 years of ISSO experience, including hands-on work developing or maintaining System Security Plans
Working knowledge of the Risk Management Framework and the federal authorization process (ATO)
Familiarity with NIST SP 800-37 and NIST SP 800-53 control families
Ability to explain security requirements clearly to developers and project managers
U.S. Citizenship or Permanent Residency, with all work performed within the continental U.S.
Ability to pass a federal agency suitability or background investigation
Preferred / Nice-to-Have
Prior federal contracting experience supporting a civilian agency ATO boundary
Experience with a GRC platform such as Xacta, eMASS, CSAM, Archer, or ServiceNow IRM
Exposure to FedRAMP-authorized cloud services and inherited control models
Experience supporting POA&M tracking and remediation
Familiarity with Ongoing Authorization or continuous ATO models
Certifications such as Security+, CGRC (formerly CAP), or CISSP Associate
Skill(s)
Technical Skills
System Security Plan (SSP) authoring and maintenance
Risk Management Framework execution under NIST SP 800-37
NIST SP 800-53 control selection, implementation, and evidence mapping
Authorization package assembly and ATO lifecycle support
POA&M tracking and remediation coordination
Continuous monitoring and security documentation upkeep
GRC tooling (Xacta, eMASS, CSAM, Archer, or ServiceNow IRM)
Cloud service authorization concepts, including FedRAMP inheritance
Soft Skills
Clear written and verbal communication with both technical and non-technical audiences
Ability to work independently and as a contributing member of a distributed team
Comfort operating in a fully remote setting with a camera-on meeting culture
Sound judgment about when to decide and when to escalate
Collaborative posture with system owners, business owners, developers, and assessors
Attention to documentation quality and follow-through on commitments
Benefits
Dragonfli Group offers a comprehensive benefits package that includes:
Medical: Multiple POS health plan options including an HSA-compatible plan
Dental: PPO coverage for preventive, basic, and major services
Vision: Annual exam, frames, lenses, and contact lens allowance
401(k): Employer match up to 5% of eligible compensation
Long-Term Disability: 100% employer-paid coverage at 50% of pre-disability earnings
Life Insurance & AD&D: 100% employer-paid coverage valued at $10,000 each
PTO: 15–25 days annually based on tenure
Paid Federal Holidays: All 11 federal holidays observed
Originally posted on Himalayas
Who can apply
Eligible countries: United States. Accepted UTC offsets: UTC-10, UTC-9, UTC-8, UTC-7, UTC-6, UTC-5, UTC+14. Review the full description for employer-specific work authorization, residency and schedule requirements.