Security Authorization / ISSO Analyst

Essnova Solutions, Inc.Bethesda, MD
Hybrid

About The Position

Essnova Solutions, Inc. is seeking an experienced Security Authorization / Information System Security Officer (ISSO) Analyst to support federal cybersecurity authorization, compliance, security documentation, and audit-readiness activities for a large-scale endpoint-management and endpoint-security modernization program supporting the National Institutes of Health (NIH). This position is contingent upon Essnova receiving contract award. The Security Authorization / ISSO Analyst will support continuous Assessment and Authorization (A&A), Authority to Operate (ATO), Authority to Use (ATU), System Security Plan (SSP), security-control evidence, remediation, and audit-response activities across an enterprise environment of approximately 55,000 endpoints and 15,000+ servers.

Requirements

  • Demonstrated experience supporting federal information-system security, Assessment and Authorization (A&A), and authorization lifecycle activities.
  • Hands-on experience developing, maintaining, or supporting System Security Plans (SSPs) and ATO/authorization documentation.
  • Strong working knowledge of NIST security controls and federal cybersecurity compliance requirements.
  • Experience collecting, validating, organizing, and maintaining security-control implementation evidence.
  • Experience supporting security assessments, findings, remediation activities, POA&Ms, exceptions, and closure evidence.
  • Experience supporting federal security audits, assessments, oversight reviews, and authorization evidence requests.
  • Ability to work directly with technical engineering teams to translate platform configurations and operational controls into defensible security/compliance evidence.
  • Strong technical-writing, documentation, organization, and stakeholder-communication skills.
  • Ability to manage multiple authorization artifacts, findings, dependencies, deadlines, and Government review comments simultaneously.
  • Ability and willingness to satisfy applicable post-award Government security, privacy, training, background-investigation, NDA, and system-access requirements.

Nice To Haves

  • Experience supporting cybersecurity authorization or ISSO functions for HHS, NIH, or another federal civilian agency.
  • Experience with NIST SP 800-53, FISMA, FIPS 200, OMB A-130, and federal security authorization processes.
  • Experience supporting enterprise Microsoft environments involving Intune, MECM, Microsoft Defender for Endpoint, Microsoft Defender Antivirus, Azure/Defender for Cloud, or JAMF/macOS.
  • Experience supporting large, distributed federal IT environments.
  • Experience producing audit-ready evidence packages under short Government response deadlines.
  • Experience with configuration-management, security-baseline, vulnerability/remediation, and exception-management processes.
  • Relevant cybersecurity certification such as CISSP, CGRC, Security+, CISM, or equivalent.

Responsibilities

  • Support continuous A&A, ATO, ATU, and SSP activities for endpoint-management and endpoint-security capabilities.
  • Develop, maintain, update, and coordinate required security authorization documentation and supporting evidence.
  • Support implementation and documentation of applicable NIST security controls and federal/HHS cybersecurity requirements.
  • Develop and maintain System Security Plans (SSPs), including security-control implementation information, supporting evidence, dependencies, and updates.
  • Support security assessments, findings, remediation activities, exceptions, and POA&M tracking through closure.
  • Coordinate with endpoint-platform, Microsoft Defender, program-management, and Government stakeholders to collect and validate technical security evidence.
  • Support Government security reviews, assessments, audits, oversight activities, and cybersecurity compliance requests.
  • Develop accurate and traceable audit and review evidence packages and support required Government response timelines, including the PWS requirement for requested audit artifacts within three business days unless otherwise approved.
  • Maintain security findings, exceptions, remediation items, owners, due dates, aging, closure evidence, and recurrence status.
  • Support authorization and compliance activities associated with enterprise technologies including Microsoft Intune, MECM, Microsoft Defender, Azure Arc, and JAMF/macOS.
  • Support endpoint configuration and security baseline evidence, macOS/JAMF authorization artifacts, and operational-readiness documentation.
  • Assist with risk assessments, security assessment evidence, configuration-management documentation, incident-response documentation, and other authorization artifacts as applicable.
  • Maintain organized, current security documentation and authorization records supporting transition, knowledge transfer, and operational continuity.
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service