Dragonfli Group logo
Dragonfli Group
Posted 30 days agoVerified live 1d ago

Junior Information System Security Officer

Brief overview

Remote
UndergradOr in progress
2+ yrsMinimum
Risk Management Framework (RMF)NIST SP 800-37NIST SP 800-53Authorization to Operate (ATO) Lifecycle SupportPOA&M Tracking and RemediationContinuous MonitoringXactaeMASSCSAMRSA ArcherServiceNow IRMFedRAMP

About the company

Dragonfli Group logo
Dragonfli Groupdragonfligroup.com

The Dragonfli Group is a Washington, DC based LLC specializing in management and technology consulting.

Job description

Summary

Dragonfli Group is a cybersecurity and IT consulting firm serving federal agencies and Fortune 100 enterprises. The Junior Information System Security Officer will develop and maintain System Security Plans and security documentation, support Authorization to Operate activities and Risk Management Framework tasks, and provide practical security guidance to developers, project managers, and other stakeholders.

Responsibilities

  • Develop and maintain System Security Plans (SSPs) and related security documentation
  • Support the activities that help systems obtain and maintain an Authorization to Operate (ATO)
  • Assist with oversight of the information systems security program for applications and systems within the ATO boundary
  • Provide day-to-day security support and guidance to software developers, project managers, and other team members
  • Help identify practical ways to meet security requirements with minimal impact to delivery schedules
  • Escalate complex or ambiguous security issues to the lead or senior ISSO with the context needed to resolve them
  • Support execution of Risk Management Framework tasks including categorization, control selection, implementation, assessment, and authorization in accordance with NIST SP 800-37
  • Support continuous monitoring activities and keep authorization artifacts current
  • Support System Owner system access reviews and account management compliance
  • Contribute to the use of automation and AI tooling that streamlines RMF documentation and control assessment work

Skills

  • Bachelor's degree in cybersecurity, information technology, or a related field
  • 2 years of ISSO experience, including hands-on work developing or maintaining System Security Plans
  • Working knowledge of the Risk Management Framework and the federal authorization process (ATO)
  • Familiarity with NIST SP 800-37 and NIST SP 800-53 control families
  • Ability to explain security requirements clearly to developers and project managers
  • U.S. Citizenship or Permanent Residency, with all work performed within the continental U.S
  • Ability to pass a federal agency suitability or background investigation
  • System Security Plan (SSP) authoring and maintenance
  • Risk Management Framework execution under NIST SP 800-37
  • NIST SP 800-53 control selection, implementation, and evidence mapping
  • Authorization package assembly and ATO lifecycle support
  • POA&M tracking and remediation coordination
  • Continuous monitoring and security documentation upkeep
  • GRC tooling (Xacta, eMASS, CSAM, Archer, or ServiceNow IRM)
  • Cloud service authorization concepts, including FedRAMP inheritance
  • Clear written and verbal communication with both technical and non-technical audiences
  • Ability to work independently as a contributing member of a distributed team
  • Comfort operating in a fully remote setting with a camera-on meeting culture
  • Sound judgment about when to decide and when to escalate
  • Collaborative posture with system owners, business owners, developers, and assessors
  • Attention to documentation quality and follow-through on commitments
  • Prior federal contracting experience supporting a civilian agency ATO boundary
  • Experience with a GRC platform such as Xacta, eMASS, CSAM, Archer, or ServiceNow IRM
  • Exposure to FedRAMP-authorized cloud services and inherited control models
  • Experience supporting POA&M tracking and remediation
  • Familiarity with Ongoing Authorization or continuous ATO models
  • Certifications such as Security+, CGRC (formerly CAP), or CISSP Associate

Qualifications

Must Haves

  • Bachelor's degree in cybersecurity, information technology, or a related field
  • 2 years of ISSO experience, including hands-on work developing or maintaining System Security Plans
  • Working knowledge of the Risk Management Framework and the federal authorization process (ATO)
  • Familiarity with NIST SP 800-37 and NIST SP 800-53 control families
  • Ability to explain security requirements clearly to developers and project managers
  • U.S. Citizenship or Permanent Residency, with all work performed within the continental U.S
  • Ability to pass a federal agency suitability or background investigation
  • System Security Plan (SSP) authoring and maintenance
  • Risk Management Framework execution under NIST SP 800-37
  • NIST SP 800-53 control selection, implementation, and evidence mapping
  • Authorization package assembly and ATO lifecycle support
  • POA&M tracking and remediation coordination
  • Continuous monitoring and security documentation upkeep
  • GRC tooling (Xacta, eMASS, CSAM, Archer, or ServiceNow IRM)
  • Cloud service authorization concepts, including FedRAMP inheritance
  • Clear written and verbal communication with both technical and non-technical audiences
  • Ability to work independently as a contributing member of a distributed team
  • Comfort operating in a fully remote setting with a camera-on meeting culture
  • Sound judgment about when to decide and when to escalate
  • Collaborative posture with system owners, business owners, developers, and assessors
  • Attention to documentation quality and follow-through on commitments

Nice to Haves

  • Prior federal contracting experience supporting a civilian agency ATO boundary
  • Experience with a GRC platform such as Xacta, eMASS, CSAM, Archer, or ServiceNow IRM
  • Exposure to FedRAMP-authorized cloud services and inherited control models
  • Experience supporting POA&M tracking and remediation
  • Familiarity with Ongoing Authorization or continuous ATO models
  • Certifications such as Security+, CGRC (formerly CAP), or CISSP Associate

Benefits

  • Medical: Multiple POS health plan options including an HSA-compatible plan
  • Dental: PPO coverage for preventive, basic, and major services
  • Vision: Annual exam, frames, lenses, and contact lens allowance
  • 401(k): Employer match up to 5% of eligible compensation
  • Long-Term Disability: 100% employer-paid coverage at 50% of pre-disability earnings
  • Life Insurance & AD&D: 100% employer-paid coverage valued at $10,000 each
  • PTO: 15–25 days annually based on tenure
  • Paid Federal Holidays: All 11 federal holidays observed

More jobs like this