- Company Name
- Docebo
- Job Title
- Information Systems Security Officer (ISSO)
- Job Description
-
**Job title**
Information Systems Security Officer (ISSO)
**Role Summary**
The ISSO safeguards the confidentiality, integrity, and availability of the organization’s digital assets by managing the FedRAMP authorization lifecycle, continuous monitoring, and compliance with NIST and DoD frameworks. This role leads cross‑functional coordination, policy development, and risk administration to maintain and advance FedRAMP and DoD RMF authorizations.
**Expectations**
- Own end‑to‑end FedRAMP/DoD RMF authorization for assigned systems.
- Maintain program documentation, continuous monitoring telemetry, and incident response processes.
- Act as primary liaison among product, engineering, security, legal, sales, and government stakeholders.
- Deliver timely audits, risk assessments, and training to sustain strong security posture.
- Drive automation, documentation quality, and process improvement to scale authorization efforts.
**Key Responsibilities**
- Manage FedRAMP/DoD RMF lifecycle (strategy, authorization, continuous monitoring, ATO maintenance).
- Define program governance, roles, and responsibilities; coordinate with sponsors and authorizing officials.
- Create, maintain, version‑control SSP, SAR, POA&Ms, annexes, and all ATO package deliverables.
- Design and run Continuous Monitoring program: telemetry, dashboards, vulnerability ingestion, thresholds, incident reporting.
- Triage vulnerabilities, own POA&M remediation tracks, and ensure closure meets FedRAMP/customer expectations.
- Select, engage, and coordinate with 3PAOs and external assessors; ensure assessments and SARs are accurate and timely.
- Conduct Security Impact Analyses for architectural or operational changes; own risk acceptance processes.
- Integrate change control with Continuous Monitoring to keep control baselines intact.
- Lead cross‑functional working groups; conduct weekly syncs and drive stakeholder communication.
- Support pre‑sales and customer conversations on FedRAMP posture and timelines.
- Build program timelines, identify schedule risks, and report status to management.
- Develop and update security policies, control implementations, and procedures aligned with current FedRAMP, NIST SP 800‑53/37/137, and DoD RMF guidance.
- Provide training to engineers, product managers, and GRC teams on FedRAMP requirements and evidence collection.
- Coordinate security incidents affecting FedRAMP‑scope systems into the Continuous Monitoring program; update POA&Ms and governance.
- Capture lessons learned, refine processes, and drive automation to scale the program.
**Required Skills**
- 8+ years in information systems security, specialized in NIST and DoD compliance.
- Deep knowledge of FedRAMP, NIST SP 800‑37, NIST SP 800‑53, and DoD 8510.01.
- Experience obtaining FedRAMP ATO.
- Proficiency in technical writing (SOPs, work instructions, senior‑level briefs).
- Strong risk and vulnerability assessment skills.
- Competence in security infrastructure design and continuous monitoring.
- Excellent stakeholder management, cross‑functional leadership, and training delivery.
- Ability to automate evidence collection and control attestation processes.
**Required Education & Certifications**
- Bachelor’s degree in Computer Science, Information Systems, Cybersecurity, or related field.
- Certifications (preferred):
- Certified Information Systems Security Professional (CISSP)
- Certified Information Security Manager (CISM)
- FedRAMP Authorized Assessment Team (FAT) or equivalent
- NIST SP 800‑37, 800‑53, or DoD RMF training certificates.