Support the RMF lifecycle for federal information systems, including categorization, control implementation, and continuous monitoring. Assist in developing security documentation such as SSPs and POA&Ms while tracking vulnerability remediation.
Dragonfli Group is a cybersecurity and IT consulting firm providing services to federal agencies and Fortune 100 enterprises. Headquartered in Washington, DC, Dragonfli supports clients in securing mission-critical systems across on-site, hybrid, and fully remote environments.
Dragonfli is looking for a Junior Information System Security Officer (ISSO) to join a federal cybersecurity team supporting a large-scale system authorization and continuous monitoring program under the NIST Risk Management Framework (RMF). This is an entry-level opportunity for candidates who bring a strong foundation in IT, security, or a related military background but may not yet have direct ISSO experience. You'll work alongside senior ISSOs and security engineers to help maintain System Security Plans (SSPs), track Plans of Action and Milestones (POA&Ms), and support the day-to-day activities that keep federal systems authorized to operate. Candidates with 0–2 years of relevant experience, including recent certification holders and veterans transitioning into cybersecurity, are strongly encouraged to apply.
Candidates with any previous federal contracting experience are preferred. U.S. Citizenship or Permanent Residency is required. If hired, all work related to this role must be performed within the continental U.S.
Responsibilities
- Support RMF lifecycle activities for assigned federal information systems, including categorization, control implementation, assessment, and continuous monitoring, under the guidance of senior team members
- Assist in developing and updating system security documentation, including SSPs, Security Assessment Reports (SARs), and POA&Ms
- Help track and document security control deviations and vulnerabilities through to closure
- Support continuous monitoring activities, including log review and vulnerability scan analysis, alongside senior ISSOs
- Assist in maintaining system inventory, hardware/software baselines, and interconnection agreements
- Support incident response documentation, escalation tracking, and remediation follow-up
- Participate in security reviews, audits, and inspections as part of the broader team
- Coordinate with Information System Owners (ISOs) and other stakeholders on routine compliance tasks
- Build working knowledge of federal directives including FISMA and OMB A-130 through applied, on-the-job training
Requirements
Must-Have
- 0–2 years of experience in IT, cybersecurity, information assurance, or a related military/government role (direct ISSO experience is not required)
- Working knowledge of the NIST Risk Management Framework (RMF) and NIST SP 800-53 security controls, gained through training, coursework, or certification study
- U.S. Citizenship required; must be able to pass a background investigation for a Public Trust position
- Ability to work remotely and collaborate during core business hours (9am–5pm ET)
- Strong written communication skills
Preferred / Nice-to-Have
- Background in IT, communications, electronics, or a security-adjacent role
- Exposure to GRC/compliance tools such as eMASS or Xacta
- Bachelor's degree in IT, cybersecurity, or a related field (or equivalent experience)
- Prior experience in identity and access management (IAM), credentialing, or access control
- Familiarity with FISMA and OMB A-130 requirements
- Active CompTIA Security+ or (ISC)² Certified in Cybersecurity (CC) certification
Skill(s)
Technical Skills
- RMF fundamentals and the ATO lifecycle
- NIST 800-53 control families (foundational awareness)
- Identity and access management / access control concepts
- Exposure to GRC or vulnerability scanning tools (e.g., ACAS, STIGs) a plus
- Documentation and technical writing (SSPs, POA&Ms)
- MS Office / SharePoint
Soft Skills
- Clear, professional written and verbal communication
- Attention to detail and follow-through
- Ability to learn quickly and take direction from senior team members
- Collaboration across distributed, remote teams
- Discretion and trustworthiness handling sensitive information
- Self-motivation in a remote work environment
Benefits
- Medical — Multiple POS health plan options including an HSA-compatible plan
- Dental — PPO coverage for preventive, basic, and major services
- Vision — Annual exam, frames, lenses, and contact lens allowance
- 401(k) — Employer match up to 5% of eligible compensation
- Long-Term Disability — 100% employer-paid coverage at 50% of pre-disability earnings
- Life Insurance & AD&D — 100% employer-paid coverage valued at $10,000 each
- PTO
- 11 Paid Federal Holidays
Travel
null