Information Systems Security Officer
Job Locations
US-Remote
| ID |
2026-10713
|
# of Openings |
1
|
Category |
Information Technology
|
Clearance |
Tier 4 - High Risk (Public Trust)
|
Position Overview
The Senior Information System Security Officer (ISSO) will provide expert cybersecurity oversight, governance, and continuous monitoring support for missioncritical systems within the Department of Veterans Affairs (VA). This role requires deep familiarity with VA security policies, ATO processes, enterprise tools, and the unique operational environment of federal healthcare IT. The ISSO will partner closely with system owners, engineering teams, auditors, and VA cybersecurity leadership to ensure systems remain compliant, secure, and aligned with federal and VAspecific requirements.
Responsibilities
Security Governance & Compliance
Lead security compliance activities in alignment with VA, NIST, FISMA, and federal cybersecurity frameworks
- Manage and maintain system security documentation including SSPs, SARs, POA&Ms, and risk assessments
- Support and guide systems through the full ATO lifecycle, including initial authorization, continuous monitoring, and renewals
- Ensure adherence to VA Handbook 6500, VA security directives, and TIC/Zero Trust initiatives
Continuous Monitoring & Risk Management
- Oversee vulnerability management, patch compliance, and security control assessments
- Conduct regular reviews of audit logs, scan results, and security events
- Identify, document, and track risks; develop mitigation strategies and compensating controls
- Coordinate with VA CSOC, privacy teams, and engineering groups to resolve findings
Technical & Operational Support
- Provide security guidance during system design, integration, and modernization efforts
- Review architecture diagrams, data flows, and configuration changes for security impact
- Support incident response activities and rootcause analysis
- Advise development and operations teams on secure engineering practices
Stakeholder Engagement
- Serve as the security liaison between program leadership, system owners, and VA cybersecurity offices
- Prepare and deliver briefings, dashboards, and status updates for executives and auditors
- Collaborate with crossfunctional teams to ensure security requirements are understood and implemented
Required Experience/Qualifications
- 7+ years of experience as an ISSO or similar cybersecurity role supporting federal agencies
- Direct experience working within the VA environment (e.g., ATO processes, eMASS, Archer, CSAM, VA Handbook 6500)
- Strong understanding of NIST SP 80053, RMF, FISMA, and federal cybersecurity governance
- Experience managing POA&Ms, vulnerability remediation, and continuous monitoring activities
- Ability to interpret technical system details and translate them into security requirements
- Excellent communication skills, including executivelevel reporting
Preferred Experience/Qualifications
- Experience supporting VA OIT, EHRM, VBA, VHA, or enterprise ICAM programs
- Familiarity with cloud security (AWS, Azure, VAEC)
- CISSP, CAP, Security+, or equivalent certifications
- Experience with Zero Trust, identity modernization, or large scale federal IT transformations
Special Requirements/Security Clearance
- Ability to obtain and maintain a Public Trust
|