Match your resume skills with our AI powered skill match!
Upload your resume and we draft a letter for this exact role, tailored to what it asks for.
The System Security Officer will lead security and compliance efforts for federal financial systems, ensuring adherence to NIST and RMF frameworks. Responsibilities include managing the Authority to Operate (ATO) process, overseeing vulnerability management, and coordinating incident response activities.
SMX is seeking a highly motivated and experienced System Security Officer (SSO) to lead the security and compliance efforts for our innovative CFO Control Tower Budget and Spend (BAS) solution. The CFO Control Tower is a pre-built planning and reporting tool designed specifically for the federal government, operating on the SAP Analytics Cloud (SAC) platform. This is a full-time position that is 100% remote and will require minimal travel <20% and requires a federal security clearance.
Essential Duties & Responsibilities:
This role is critical in establishing and maintaining the system's security posture, navigating the federal authorization process, and ensuring the confidentiality, integrity, and availability of sensitive government financial data. The ideal candidate is a proactive security professional with a deep understanding of federal compliance frameworks (NIST, RMF, FedRAMP) and experience securing cloud-based SaaS/PaaS solutions.
Key Responsibilities
• Security Authorization: Coordinate with the customer’s security team, ensuring they receive all the necessary FedRAMP documentation, and manage which security controls fall on the SMX implementation team vs. the customer, also providing the necessary support needed for the Risk Management Framework (RMF) process to achieve and maintain its Authority to Operate (ATO).
• System Security Plan (SSP): Support the development, documentation, and maintenance of the SSP and related security documents, including the System Architecture, Contingency Plan, and Incident Response Plan.
• Vulnerability Management: Support a comprehensive vulnerability management program, including regular scanning, risk assessment, and oversight of the Plan of Actions & Milestones (PO&AM).
• Continuous Monitoring: Oversee the design and monitoring strategy to ensure the system complies with federal mandates and organizational policies.
• Cloud Security: Serve as the subject matter expert for the SAP Analytics Cloud (SAC) environment, understanding and managing the inheritance of FedRAMP controls and liaising with the platform provider on security matters.
• Auditing & Logging: Ensure security and audit logs are being collected, reviewed, and retained in accordance with federal requirements; investigate and report on security incidents.
• Stakeholder Collaboration: Act as the primary security point of contact, collaborating with federal clients, system owners, developers, and the Authorizing Official (AO) to communicate risk and manage security requirements.
• Policy & Compliance: Ensure the system’s configuration, operations, and procedures are in compliance with NIST SP 800-53, FIPS publications, and other relevant federal policies.
• Incident Response: Lead and coordinate incident response activities, from detection and analysis to containment, eradication, and recovery.
• Manage: Support 4-6 active projects based on the ATO stage, and 2-3 monitoring projects with monthly or quarterly check-ins.
Required Skills & Experience:
• Bachelor’s degree in Cybersecurity, Information Technology, or a related field. Additional years of experience in lieu of degree will be considered.
• 5+ years of experience in a cybersecurity role (e.g., ISSO, ISSM, Security Engineer) directly supporting U.S. Federal Government systems.
• The candidate must have completed a government Authority to Operate (ATO) process at least once within the past two years.
• Demonstrated experience with the NIST Risk Management Framework (RMF) and the ATO lifecycle.
• Strong understanding of NIST SP 800-53, 800-37, and continuous monitoring principles.
• Professional security certification such as CISSP, CISM, CAP, or Security+.
• Experience with security scanning and assessment tools (e.g., Tenable, Nessus, Burp Suite).
• Excellent written and verbal communication skills, with the ability to translate complex security concepts to technical and non-technical audiences.
• Must be a US Citizen and have the ability to obtain a Public Trust clearance.
Desired Skills & Experience
• Direct experience securing applications on the SAP Analytics Cloud (SAC) platform or other major enterprise SaaS/PaaS solutions.
• Experience with SAP NS2.
• Experience with federal financial management systems and an understanding of CFO Act agency requirements.
• Familiarity with the FedRAMP framework and the security responsibilities within a shared cloud model.
• Experience securing systems within major cloud environments (SAP S/4HANA, AWS, Azure, and Google Cloud).
# LI-SA1
#CJPOST
The SMX salary determination process takes into account a number of factors, including but not limited to, geographic location, Federal Government contract labor categories, relevant prior work experience, specific skills, education and certifications. At SMX, one of our Core Values is to Invest in Our People so we offer a competitive mix of compensation, learning & development opportunities, and benefits. Some key components of our robust benefits include health insurance, paid leave, and retirement.
At SMX®, we are a team of technical and domain experts dedicated to enabling your mission. From priority national security initiatives for the DoD to highly assured and compliant solutions for healthcare, we understand that digital transformation is key to your future success.
We share your vision for the future and strive to accelerate your impact on the world. We bring both cutting edge technology and an expansive view of what’s possible to every engagement. Our delivery model and unique approaches harness our deep technical and domain knowledge, providing forward-looking insights and practical solutions to power secure mission acceleration.
SMX is an Equal Opportunity employer including disabilities and veterans.
Selected applicant may be subject to a background investigation and/or education verification.
SMX does not sponsor a new applicant for employment authorization or immigration related support for this position (i.e. H1B, F-1 OPT, F-1 STEM OPT, F-1 CPT, J-1, TN, E-2, E-3, L-1 and O-1, or any EADs or other forms of work authorization that require immigration support from an employer).
Stop the endless job search. Our AI finds and applies to the best jobs for you.
Featuring 217,826+ Jobs in Others
Answer easy questions
217,826+ jobs across 15+ categories
Get your best job matches
Only hand-screened, legit jobs
Find a remote job faster
No ads, scams, or junk
“I was the first applicant for a remote marketing position that got listed on the company website the same day I applied. Had an interview within 48 hours!”