Security Authorization / ISSO Analyst
Essnova Solutions, Inc. · Bethesda, MD, United States
About The Role
Employment: Full-Time
Status: Contingent Upon Proposal Award
About Essnova
Essnova Solutions, Inc. is seeking an experienced Security Authorization / Information System Security Officer (ISSO) Analyst to support federal cybersecurity authorization, compliance, security documentation, and audit-readiness activities for a large-scale endpoint-management and endpoint-security modernization program supporting the National Institutes of Health (NIH) .
This position is contingent upon Essnova receiving contract award.
The Security Authorization / ISSO Analyst will support continuous Assessment and Authorization (A&A), Authority to Operate (ATO), Authority to Use (ATU), System Security Plan (SSP), security-control evidence, remediation, and audit-response activities across an enterprise environment of approximately 55,000 endpoints and 15,000+ servers .
What You’ll Do
- Support continuous A&A, ATO, ATU, and SSP activities for endpoint-management and endpoint-security capabilities.
- Develop, maintain, update, and coordinate required security authorization documentation and supporting evidence .
- Support implementation and documentation of applicable NIST security controls and federal/HHS cybersecurity requirements.
- Develop and maintain System Security Plans (SSPs) , including security-control implementation information, supporting evidence, dependencies, and updates.
- Support security assessments, findings, remediation activities, exceptions, and POA&M tracking through closure.
- Coordinate with endpoint-platform, Microsoft Defender, program-management, and Government stakeholders to collect and validate technical security evidence.
- Support Government security reviews, assessments, audits, oversight activities, and cybersecurity compliance requests.
- Develop accurate and traceable audit and review evidence packages and support required Government response timelines, including the PWS requirement for requested audit artifacts within three business days unless otherwise approved .
- Maintain security findings, exceptions, remediation items, owners, due dates, aging, closure evidence, and recurrence status.
- Support authorization and compliance activities associated with enterprise technologies including Microsoft Intune, MECM, Microsoft Defender, Azure Arc, and JAMF/macOS .
- Support endpoint configuration and security baseline evidence, macOS/JAMF authorization artifacts, and operational-readiness documentation.
- Assist with risk assessments, security assessment evidence, configuration-management documentation, incident-response documentation, and other authorization artifacts as applicable.
- Maintain organized, current security documentation and authorization records supporting transition, knowledge transfer, and operational continuity.
Required Qualifications
- Demonstrated experience supporting federal information-system security, Assessment and Authorization (A&A), and authorization lifecycle activities .
- Hands-on experience developing, maintaining, or supporting System Security Plans (SSPs) and ATO/authorization documentation.
- Strong working knowledge of NIST security controls and federal cybersecurity compliance requirements.
- Experience collecting, validating, organizing, and maintaining security-control implementation evidence .
- Experience supporting security assessments, findings, remediation activities, POA&Ms , exceptions, and closure evidence.
- Experience supporting federal security audits, assessments, oversight reviews, and authorization evidence requests .
- Ability to work directly with technical engineering teams to translate platform configurations and operational controls into defensible security/compliance evidence.
- Strong technical-writing, documentation, organization, and stakeholder-communication skills.
- Ability to manage multiple authorization artifacts, findings, dependencies, deadlines, and Government review comments simultaneously.
- Ability and willingness to satisfy applicable post-award Government security, privacy, training, background-investigation, NDA, and system-access requirements.
Preferred Qualifications
- Experience supporting cybersecurity authorization or ISSO functions for HHS, NIH, or another federal civilian agency .
- Experience with NIST SP 800-53 , FISMA, FIPS 200, OMB A-130, and federal security authorization processes.
- Experience supporting enterprise Microsoft environments involving Intune, MECM, Microsoft Defender for Endpoint, Microsoft Defender Antivirus, Azure/Defender for Cloud, or JAMF/macOS .
- Experience supporting large, distributed federal IT environments.
- Experience producing audit-ready evidence packages under short Government response deadlines.
- Experience with configuration-management, security-baseline, vulnerability/remediation, and exception-management processes.
- Relevant cybersecurity certification such as CISSP, CGRC, Security+, CISM, or equivalent .
Equal Employment Opportunity
Essnova Solutions, Inc. is an Equal Opportunity Employer. We are committed to providing equal employment opportunities to all qualified applicants and employees without regard to race, color, religion, sex, pregnancy, sexual orientation, gender identity, national origin, age, disability, genetic information, veteran status, or any other characteristic protected by applicable federal, state, or local law.
Essnova Solutions, Inc. also provides reasonable accommodations to qualified individuals with disabilities and applicants with disabilities throughout the hiring process, consistent with applicable law.
This position is contingent upon contract award. Employment for this opportunity will be dependent upon Essnova Solutions, Inc. receiving the applicable contract award and the candidate satisfying all position, customer, and applicable Government requirements.
Similar roles you might like
See all →This is an external listing. JobSpring does not represent or verify the employer. Report this listing
