Mid-Level Information System Security Officer (ISSO) / System Owner Support
K2UnitedAbout the role
Ā
K2United is an organization that houses two distinct, national, customer-facing brands tied together by a shared purpose: setting the standard for an extraordinary workplace. Through our brands, K2Share and CareerSafe, we provide advisory services in cyber risk management and online education for workforce readiness.
Our four core values define how we show up every day:
- Respect Others - We lead with respect, building trust and connection.
- Internally Driven - We are relentlessly compelled to accomplish our objectives.
- Collaborative Innovation - We create by listening, sharing, and working together.
- Client Success - We hold our clients' mission as our own.
We believe in people who are accountable, curious, and motivated to make an impact that matters.
Our programs make a meaningful difference. CareerSafe supports more than two million users each year, while K2Share delivers cybersecurity and IT solutions that strengthen federal agencies. As part of our team, you'll help solve complex challenges in a mission-driven, small-business environment that values professional growth, collaboration, and work-life balance.
K2Share is seeking an Information System Security Officer (ISSO) to support a federal health-sector client. In this role, you will serve as a trusted security advisor to system owners, business owners, and technical teams, helping guide systems through the Risk Management Framework (RMF) and supporting their Authority to Operate (ATO) throughout the system lifecycle.
You will develop and maintain authorization documentation, continuous monitoring strategies, contingency planning, and security guidance while helping ensure client systems remain compliant with federal cybersecurity requirements. This role supports authorization package development while maintaining appropriate independence from formal Security Control Assessment (SCA) and Final Assessment Report (SAR) validation activities for the same systems.
About You
You are an experienced cybersecurity professional who enjoys helping organizations successfully navigate the Risk Management Framework while balancing mission objectives and security requirements. You understand that effective RMF implementation requires more than documentation. It requires collaboration, sound technical judgment, and the ability to translate complex security requirements into practical guidance.
You are comfortable working directly with system owners, engineers, privacy professionals, and leadership to develop authorization packages, continuous monitoring strategies, and security documentation that withstands rigorous review. You communicate clearly, stay organized across multiple systems, and take ownership of helping programs achieve and maintain compliance.
You thrive in an environment where you can combine technical expertise with consulting, mentorship, and process improvement to strengthen an organization's overall cybersecurity posture.
Your Impact
As the Information System Security Officer, you will help guide client systems through every phase of the RMF and ATO lifecycle. Your expertise will support secure system design, authorization, continuous monitoring, and operational readiness while serving as a key resource for system owners and stakeholders.
In this role, you will:
- Develop and maintain RMF authorization artifacts, including the System Security Plan (SSP), Business Impact Analysis (BIA), FIPS 199 categorization, Privacy Threshold and Privacy Impact Assessments (PTA/PIA), Configuration Management Plan (CMP), and e-Authentication documentation.
- Create foundational system documentation, including Boundary Scope Memorandums (BSM), System Architecture diagrams, and Authorization Boundary and Network Diagrams (ABND).
- Assist system owners with security control scoping, tailoring, inheritance, and identification of applicable overlays, including the client's AI Overlay where applicable.
- Apply the NIST AI Risk Management Framework (AI RMF 1.0) and relevant OMB guidance for systems incorporating Artificial Intelligence or Machine Learning capabilities.
- Support development of Interconnection Security Agreements (ISAs), Memorandums of Understanding (MOUs), and other authorization documentation.
- Validate technical evidence, including configuration artifacts, scan reports, and system documentation, to ensure compliance with NIST SP 800-53 Rev. 5 prior to authorization package submission.
- Develop and maintain system-level Contingen
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights ā in under 60 seconds.
Apply Now āGenerate Application KitFree account required ā sign up in 30s