ISSO Information Assurance/Security Specialist (Senior/SME)

Anakim Consulting•Ashburn, VA
•Remote

About The Position

Anakim Consulting is hiring an Information System Security Officer (ISSO) with Senior or SME level expertise to lead Authorization to Operate (ATO) and continuous monitoring activities across multiple major applications (MA) and general support systems (GSS) for a large federal agency. This position requires hands-on experience in IT security, risk management, FedRAMP, and NIST standards. This individual will serve as a technical advisor to System Owners and senior leadership, directing security compliance, threat assessments, and cloud security initiatives.

Requirements

  • U.S. citizenship, no dual citizenship
  • Current DHS CBP Suitability or eligibility to obtain secure access approval for DHS CBP EOD
  • 10+ years of progressive IT security, information assurance, and risk management experience, with a proven track record of leading system accreditations for federal agencies.
  • Bachelor’s degree in Computer Science, Cybersecurity Technology, Information Technology, or a related technical field (Master’s degree preferred).
  • DoD 8570/8140 Requirement: Must possess a current baseline certification satisfying IAT/IAM Level III such as CISSP, CISM, GSLC, CCISO, CASP+, or equivalent.
  • Advanced Certification Requirement: Must possess at least one advanced or specialized credential such as: CISM, CCISO, CISA, CISSP, CDPSE, CCSK.
  • Candidates must hold a minimum of two distinct active certifications to meet both the baseline and advanced credential requirements. Single certifications cannot be used to satisfy both requirements.
  • Expert-level knowledge of NIST SP 800-53 (Rev 4/5), NIST SP 800-37, FIPS 199/200, FISMA, FedRAMP, and NIST Cybersecurity Framework.
  • Hands-on expertise with federal repository and assessment tools such as eMASS, Xacta, CSAM, or RSA Archer.
  • Experience with Splunk, Nessus, Qualys, Retina, IBM BigFix, and ticketing platforms (ServiceNow, Jira, Remedy).
  • Working knowledge of RedHat Enterprise Linux, Windows Server environments, networking concepts (LAN/WAN/VPN, firewalls), and cloud security baselines.
  • Exceptional verbal and written communication skills with demonstrated success briefing senior executive leadership and managing technical teams.

Nice To Haves

  • Master’s degree preferred.

Responsibilities

  • Lead end-to-end Risk Management Framework (RMF) and ATO processes, preparing and maintaining comprehensive security packages (SSP, RA, PTA, PIA, ST&E, and POA&M) in compliance with NIST SP 800-53, SP 800-37, and FISMA standards.
  • Develop, evaluate, and audit Cloud Service package documentation to ensure agency and FedRAMP compliance for cloud integrations.
  • Oversee regular vulnerability scans (Qualys, Nessus, Nexpose, ACAS), analyze Splunk audit logs, evaluate system hardening (STIGs/SCAP), and drive POA&M remediation efforts.
  • Support and optimize CDM initiatives, automated security controls monitoring, and Zero Trust security architectures.
  • Serve on Change Control Boards (CCB) to review proposed system design changes, perform security impact analyses, and ensure baseline compliance.
  • Brief CISOs, System Owners, and senior stakeholders on overall system security posture, residual risk, and threat mitigation strategies.
  • Other duties, as assigned.
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service