waypointjobs

Dragonfli Group

Mid-Level Information System Security Officer (ISSO)

Remote — United States (see country and timezone requirements)

Check who can apply and the requirements below before continuing.

Job description

Description

Dragonfli Group is a cybersecurity and IT consulting firm providing services to federal agencies and Fortune 100 enterprises. Headquartered in Washington, DC, Dragonfli supports clients in securing mission-critical systems across on-site, hybrid, and fully remote environments.

Dragonfli Group is seeking a Mid Information System Security Officer (ISSO) to own the security posture of assigned systems on a multi-year cybersecurity program for a large federal agency. You will advise on architecture, authorization boundaries, and risk decisions, and you will lead control compliance and assessment readiness for your systems, maintaining the System Security Plan and other key artifacts and coordinating audits and assessments end to end. You will run continuous monitoring and reporting, define the metrics that make posture legible to stakeholders, and escalate material risks with a recommended course of action. You will also drive vulnerability remediation and POA&M corrective actions, including the harder calls around exceptions, compensating controls, and risk acceptances. This role suits an ISSO with roughly 4 years of experience who is ready to be the accountable security voice for a system rather than a supporting one.

This is a multi-year contract position involving a large US federal agency. Candidates with previous federal contracting experience are preferred. U.S. Citizenship or Permanent Residency is required. If hired, all work related to this role must be performed within the continental U.S.

This position is fully remote. The agency's Rules of Behavior and Telework Policy apply to all contractor personnel and require, among other things, that laptop cameras be turned on and that staff remain visible on camera during all meetings.

Responsibilities

Own the security posture for assigned systems, advising on architecture, authorization boundaries, and risk decisions

Lead control compliance and assessment readiness, maintaining key artifacts including the System Security Plan

Coordinate audits and assessments, including scheduling, evidence readiness, and response to assessor findings

Run continuous monitoring and reporting, defining metrics and escalating material risks and issues

Drive vulnerability remediation and POA&M corrective actions, including exceptions, compensating controls, and risk acceptances

Execute Risk Management Framework tasks across categorization, control selection, implementation, assessment, and authorization in accordance with NIST SP 800-37

Support the transition to and management of an Ongoing Authorization program

Provide cybersecurity guidance to Business Owners and System Owners and serve as a liaison between those stakeholders and the cybersecurity staff

Support System Owner system access reviews and account management compliance

Apply automation and AI tooling to streamline RMF documentation, control assessments, and continuous monitoring activities

Requirements

Must-Have

Bachelor's degree in cybersecurity, information technology, or a related field

4 years of ISSO experience, including ownership of security posture for one or more systems

Demonstrated experience maintaining SSPs and leading a system through assessment or authorization

Hands-on experience managing POA&Ms, including exceptions, compensating controls, and risk acceptances

Working knowledge of NIST SP 800-37 and NIST SP 800-53, and of continuous monitoring practice

Experience advising system owners or engineering teams on risk decisions

U.S. Citizenship or Permanent Residency, with all work performed within the continental U.S.

Ability to pass a federal agency suitability or background investigation

Preferred / Nice-to-Have

Prior federal contracting experience as an ISSO at a civilian agency

Experience with Ongoing Authorization or continuous ATO programs

Experience with a GRC platform such as Xacta, eMASS, CSAM, Archer, or ServiceNow IRM

Cloud authorization experience, including FedRAMP inheritance and interconnection agreements

Experience defining security metrics and reporting posture to non-technical stakeholders

Certifications such as CISSP, CGRC (formerly CAP), CISM, or CCSP

Skill(s)

Technical Skills

System security posture ownership and risk-based decision support

SSP and authorization artifact development and maintenance

Risk Management Framework execution under NIST SP 800-37

Security control assessment readiness under NIST SP 800-53A

POA&M management, compensating controls, exceptions, and risk acceptance

Continuous monitoring, security metrics definition, and posture reporting

Vulnerability management and remediation coordination

GRC tooling and cloud authorization models including FedRAMP

Soft Skills

Clear written and verbal communication with both technical and non-technical audiences

Ability to work independently and as a contributing member of a distributed team

Comfort operating in a fully remote setting with a camera-on meeting culture

Sound judgment about when to decide and when to escalate

Collaborative posture with system owners, business owners, developers, and assessors

Attention to documentation quality and follow-through on commitments

Benefits

Dragonfli Group offers a comprehensive benefits package that includes:

Medical: Multiple POS health plan options including an HSA-compatible plan

Dental: PPO coverage for preventive, basic, and major services

Vision: Annual exam, frames, lenses, and contact lens allowance

401(k): Employer match up to 5% of eligible compensation

Long-Term Disability: 100% employer-paid coverage at 50% of pre-disability earnings

Life Insurance & AD&D: 100% employer-paid coverage valued at $10,000 each

PTO: 15–25 days annually based on tenure

Paid Federal Holidays: All 11 federal holidays observed

Originally posted on Himalayas

Who can apply

Eligible countries: United States. Accepted UTC offsets: UTC-10, UTC-9, UTC-8, UTC-7, UTC-6, UTC-5, UTC+14. Review the full description for employer-specific work authorization, residency and schedule requirements.

Ready for your next step?Apply on the official website
Apply on Himalayas ↗

Explore related searches

Current related jobs

Red Wine and Blue

Himalayas

General Interest Application

Remote — United States (see country and timezone requirements)

Salary not specifiedfull timeRemote

WHO THE HECK ARE WE? Red Wine & Blue is a national community of over 600,000 diverse suburban women working together to defeat extremism, one fr…

Listing expires 2026-12-04View job

Carle Health

Himalayas

Finance Systems Analyst

Remote — United States (see country and timezone requirements)

$26.41 – $44.10 per hourfull timeRemote

OverviewThe Finance Systems Analyst assists with supporting assigned finance/accounting applications for the enterprise such as costing, producti…

Listing expires 2026-12-04View job

Kyowa Kirin

Himalayas

Scientific Relations Manager

Remote — Worldwide (see timezone requirements)

Salary not specifiedfull timeRemote

OverviewWE PUSH THE BOUNDARIES OF MEDICINE. LEAPING FORWARD TO MAKE PEOPLE SMILE At Kyowa Kirin International (KKI), our purpose is to make peop…

Listing expires 2026-12-04View job

Belden, Inc

Himalayas

Solution Consultant - Cybersecurity Practice (US)

Remote — United States (see country and timezone requirements)

$125,000.00 – $160,000.00 per yearfull timeRemote

Innovation Starts With YouPropel your career at Belden, where innovation creates possibilities—for our people, our customers, and the communities…

Listing expires 2026-12-04View job