By Light HQ

Information Systems Security Officer

Job Locations US-Remote
Posted Date 22 hours ago(1/8/2026 8:20 AM)
ID
2026-10713
# of Openings
1
Category
Information Technology
Clearance
Tier 4 - High Risk (Public Trust)

Position Overview

The Senior Information System Security Officer (ISSO) will provide expert cybersecurity oversight, governance, and continuous monitoring support for mission critical systems within the Department of Veterans Affairs (VA). This role requires deep familiarity with VA security policies, ATO processes, enterprise tools, and the unique operational environment of federal healthcare IT. The ISSO will partner closely with system owners, engineering teams, auditors, and VA cybersecurity leadership to ensure systems remain compliant, secure, and aligned with federal and VA specific requirements.

Responsibilities

Security Governance & Compliance

  • Lead security compliance activities in alignment with VA, NIST, FISMA, and federal cybersecurity frameworks
  • Manage and maintain system security documentation including SSPs, SARs, POA&Ms, and risk assessments
  • Support and guide systems through the full ATO lifecycle, including initial authorization, continuous monitoring, and renewals
  • Ensure adherence to VA Handbook 6500, VA security directives, and TIC/Zero Trust initiatives

Continuous Monitoring & Risk Management

  • Oversee vulnerability management, patch compliance, and security control assessments
  • Conduct regular reviews of audit logs, scan results, and security events
  • Identify, document, and track risks; develop mitigation strategies and compensating controls
  • Coordinate with VA CSOC, privacy teams, and engineering groups to resolve findings

Technical & Operational Support

  • Provide security guidance during system design, integration, and modernization efforts
  • Review architecture diagrams, data flows, and configuration changes for security impact
  • Support incident response activities and root cause analysis
  • Advise development and operations teams on secure engineering practices

Stakeholder Engagement

  • Serve as the security liaison between program leadership, system owners, and VA cybersecurity offices
  • Prepare and deliver briefings, dashboards, and status updates for executives and auditors
  • Collaborate with cross functional teams to ensure security requirements are understood and implemented

Required Experience/Qualifications

  • 7+ years of experience as an ISSO or similar cybersecurity role supporting federal agencies
  • Direct experience working within the VA environment (e.g., ATO processes, eMASS, Archer, CSAM, VA Handbook 6500)
  • Strong understanding of NIST SP 800 53, RMF, FISMA, and federal cybersecurity governance
  • Experience managing POA&Ms, vulnerability remediation, and continuous monitoring activities
  • Ability to interpret technical system details and translate them into security requirements
  • Excellent communication skills, including executive level reporting

Preferred Experience/Qualifications

  • Experience supporting VA OIT, EHRM, VBA, VHA, or enterprise ICAM programs
  • Familiarity with cloud security (AWS, Azure, VAEC)
  • CISSP, CAP, Security+, or equivalent certifications
  • Experience with Zero Trust, identity modernization, or largescale federal IT transformations

Special Requirements/Security Clearance

  • Ability to obtain and maintain a Public Trust

Options

Sorry the Share function is not working properly at this moment. Please refresh the page and try again later.
Share on your newsfeed