Apply Now

Please mention DailyRemote when applying

AI Summary

The Information System Security Officer will lead security assessments and accreditation processes for federal systems using NIST RMF and ISO standards. They will also serve as a subject matter expert, advising stakeholders and managing compliance documentation through GRC tools.

Dragonfli Group is a cybersecurity and IT consulting firm providing services to federal agencies and Fortune 100 enterprises. Headquartered in Washington, DC, Dragonfli supports clients in securing mission-critical systems across on-site, hybrid, and fully remote environments.


Dragonfli Group is seeking an experienced Information System Security Officer to support a large federal agency's Assessment and Authorization (A&A) program. In this role, you will lead security assessments across a variety of applications and domains, including cloud computing environments, and apply NIST Risk Management Framework (RMF) and ISO standards to guide risk treatment and compliance decisions. You will play a central role in validating and accrediting information technology systems, use GRC tooling to manage documentation and approvals, and serve as a subject matter expert, advising stakeholders, business units, and newer A&A team members throughout the process. This is a strong opportunity for a security professional who enjoys ownership over complex, high-visibility initiatives and wants to make a lasting impact on a mission-critical federal program.


Candidates with previous federal contracting experience are preferred. U.S. Citizenship or Permanent Residency is required. If hired, all work related to this role must be performed within the continental U.S.



Responsibilities:


  • Manage security assessments across a range of applications, systems, and domains, including cloud computing environments, for projects and initiatives of significant size and complexity
  • Implement security controls, conduct risk assessments, and document compliance measures in alignment with NIST RMF and ISO standards
  • Evaluate and support documentation, validation, and accreditation processes to ensure new and existing IT systems meet information assurance (IA) and security requirements
  • Ensure appropriate treatment of risk, compliance, and assurance from both internal and external perspectives
  • Support development of security blueprints, principles, models, designs, and standards that keep enterprise IT architecture consistent, usable, secure, and aligned with business needs
  • Use network and vulnerability scanning tools and technologies to assess system configuration and status
  • Apply security architecture principles and best practices to design, implement, and maintain secure IT infrastructure in alignment with A&A policies
  • Use Governance, Risk, and Compliance (GRC) tools to manage Assessment and Authorization (A&A) processes
  • Serve as a subject matter expert (SME) for the A&A process, providing guidance to stakeholders, business units, and new A&A resources
  • Build and maintain schedules and step-by-step action plans to keep initiatives on track
  • Communicate and collaborate with cross-functional teams, business units, stakeholders, and IT professionals, including briefing executives

Requirements

Must-Have:

  • Bachelor's degree in a related field (information security, computer science, information technology, or similar), or four additional years of relevant experience in lieu of a degree
  • Demonstrated experience managing security assessments across multiple applications, systems, or domains, including cloud computing environments
  • Hands-on experience implementing security controls, performing risk assessments, and documenting compliance measures aligned to NIST RMF and ISO standards
  • Experience supporting Assessment and Authorization (A&A) or Certification and Accreditation (C&A) documentation, validation, and accreditation activities
  • Experience using Governance, Risk, and Compliance (GRC) tools to manage A&A processes
  • Experience with network and vulnerability scanning tools and technologies
  • Strong understanding of security architecture principles and secure infrastructure design
  • U.S. Citizenship or Permanent Residency
  • Ability to obtain and maintain a Public Trust security clearance, including successful completion of a background investigation
  • Ability to perform all work within the continental United States


Preferred / Nice-to-Have:

  • Previous experience supporting a federal agency contract, ideally on a large, multi-year program
  • Relevant industry certification such as CISSP, CAP, CISM, or Security+
  • Experience mentoring or onboarding junior A&A staff
  • Experience briefing senior stakeholders or executives on risk and compliance posture
  • Familiarity with named GRC platforms such as eMASS, Xacta, or RSA Archer
  • Cloud security certification (AWS, Azure, or similar)



Skill(s)

Technical Skills:

  • NIST Risk Management Framework (RMF)
  • ISO 27001 / ISO security standards
  • Assessment and Authorization (A&A) / Certification and Accreditation (C&A)
  • GRC tools (e.g., eMASS, Xacta, RSA Archer)
  • Vulnerability and network scanning tools (e.g., Nessus, Tenable)
  • Cloud security (AWS, Azure, or similar)
  • Security architecture and secure system design
  • Risk assessment methodologies


Soft Skills:

  • Executive-level briefing and communication
  • Cross-functional collaboration
  • Mentoring and knowledge transfer
  • Organizational planning and schedule management
  • Stakeholder management
  • Independent judgment and problem-solving

Benefits

  • Medical - Multiple POS health plan options including an HSA-compatible plan
  • Dental - PPO coverage for preventive, basic, and major services Vision - Annual exam, frames, lenses, and contact lens allowance
  • 401(k) - Employer match up to 5% of eligible compensation
  • Long-Term Disability - 100% employer-paid coverage at 50% of pre-disability earnings
  • Life Insurance & AD&D - 100% employer-paid coverage valued at $10,000 each
  • PTO - 15-25 days annually based on tenure
  • Paid Federal Holidays - All 11 federal holidays observed

Travel

null

Similar Jobs

See all Remote Others jobs β†’

Personalize your Remote Job Search in 3 Easy Steps!

Discover remote opportunities in Others

Answer easy questions

Answer easy questions

200,000+ jobs across 15+ categories

Get your best job matches

Get your best job matches

Only hand-screened, legit jobs

Find a remote job faster

Find a remote job faster

No ads, scams, or junk

I was the first applicant for a remote marketing position that got listed on the company website the same day I applied. Had an interview within 48 hours!

Sarah J. — Sarah J. · Marketing Manager ★★★★★ Verified