1

Fisma Jobs in Ohio (NOW HIRING)

Technical Engineer III

Continental, OH · On-site +1

$145K - $154K/yr

Experience with NIST RMF, FISMA, and Zero Trust Architecture. * TOGAF, CISSP, Azure Solutions Architect, or similar technical certification. Compensation Expected Salary Range: $145,000-$154,000 ...

Technical Engineer III

Continental, OH · On-site

$145K - $154K/yr

Experience with NIST RMF, FISMA, and Zero Trust Architecture. * TOGAF, CISSP, Azure Solutions Architect, or similar technical certification. Compensation Expected Salary Range: $145,000-$154,000 ...

Technical Engineer III

Continental, OH · On-site

$145K - $154K/yr

Experience with NIST RMF, FISMA, and Zero Trust Architecture. * TOGAF, CISSP, Azure Solutions Architect, or similar technical certification. Compensation Expected Salary Range: $145,000-$154,000 ...

Familiarity with FISCAM and/or FISMA frameworks also acceptable * Excellent verbal and written communications skills * Proficiency with Microsoft Office Suite (Outlook, Word, Excel) Knowledge in the ...

Familiarity with FISCAM and/or FISMA frameworks also acceptable * Excellent verbal and written communications skills * Proficiency with Microsoft Office Suite (Outlook, Word, Excel) Knowledge in the ...

Sr AWS Engineer - Hybrid

Columbus, OH · On-site

$60 - $70/hr

The Senior AWS Engineer serves as the technical lead for a FedRAMP Authorized (Moderate FISMA) cloud environment supporting a SaaS platform. This role involves translating security controls into ...

Showing results 21-40

Fisma information

See Ohio salary details

$33.3K

$53.5K

$75.1K

How much do fisma jobs pay per year?

As of Aug 17, 2026, the average yearly pay for fisma in Ohio is $53,476.00, according to ZipRecruiter salary data. Most workers in this role earn between $35,700.00 and $71,300.00 per year, depending on experience, location, and employer.

What is a FISMA job?

FISMA jobs are roles focused on ensuring compliance with the Federal Information Security Management Act (FISMA), a United States law that requires federal agencies and their contractors to protect sensitive information and maintain effective information security programs. Professionals in FISMA jobs are responsible for developing, implementing, and monitoring security policies, conducting risk assessments, and ensuring that systems meet federal security standards. These roles are critical for maintaining cybersecurity and protecting government data from threats and vulnerabilities.

What are the biggest challenges FISMA compliance professionals face when working with cross-functional teams?

FISMA compliance professionals often encounter challenges when coordinating with cross-functional teams, as each department may have different priorities, technical knowledge, and levels of security awareness. Ensuring that everyone understands and follows federal security standards can require extensive communication and documentation. Additionally, balancing the need for security with operational efficiency and managing tight deadlines for audits or reporting are common challenges. Building collaborative relationships and providing clear guidance are key to overcoming these obstacles.

What are the key skills and qualifications needed to thrive as a FISMA compliance analyst, and why are they important?

To thrive as a FISMA Compliance Analyst, you need a strong understanding of information security concepts, risk management frameworks, and knowledge of federal cybersecurity regulations, typically supported by a degree in information technology or cybersecurity. Familiarity with tools like NIST Risk Management Framework (RMF), vulnerability scanners, and compliance management software, as well as certifications such as CISSP or Security+, is often required. Attention to detail, analytical thinking, and effective communication are crucial soft skills for collaborating with stakeholders and ensuring thorough documentation. These skills ensure federal agencies meet regulatory requirements, safeguard sensitive data, and minimize security risks.

What is the difference between Fisma vs Cybersecurity Analyst?

AspectFismaCybersecurity Analyst
Required CertificationsFISMA-specific training, CISSP, CISACISSP, Security+, CEH
Work EnvironmentGovernment agencies, federal contractorsPrivate sector, corporations, government
Industry UsagePrimarily federal and defense sectorsBroad across industries including finance, healthcare
Job FocusImplementing FISMA compliance, managing federal info securityIdentifying vulnerabilities, incident response, security monitoring

Fisma professionals focus on ensuring compliance with the Federal Information Security Management Act (FISMA) within government and federal contractor environments. In contrast, Cybersecurity Analysts work across various industries to protect organizational data through threat detection, vulnerability assessment, and incident response. While both roles require security certifications and involve protecting information systems, Fisma specialists are more compliance-oriented, whereas Cybersecurity Analysts focus on proactive security measures.

What are popular job titles related to Fisma jobs in Ohio?

For Fisma jobs in Ohio, the most frequently searched job titles are:

Infographic showing various Fisma job openings in Ohio as of August 2026, with employment types broken down into 100% Full Time. Highlights an 100% In-person job distribution, with an average salary of $53,476 per year, or $25.7 per hour.

Senior Information Assurance Specialist

The Copper River Family of Companies

Dayton, OH

$125K - $140K/yr

Full-time

Posted 12 days ago


Job description

TACG is seeking an experienced Senior Information Assurance Specialist to serve as an Information System Security Officer (ISSO) supporting Department of Defense (DoD) information systems. This position is responsible for leading cybersecurity and information assurance initiatives, ensuring compliance with DoD cybersecurity policies, and supporting the full lifecycle of Assessment and Authorization (A&A) activities under the Risk Management Framework (RMF).

The ideal candidate possesses extensive experience supporting classified and unclassified information systems, developing Authorization to Operate (ATO) packages, implementing cybersecurity controls, and collaborating with government stakeholders to maintain secure, compliant systems.

Responsibilities (include but are not limited to):

  • Lead the development, maintenance, and submission of Assessment & Authorization (A&A) packages in accordance with the DoD Risk Management Framework (RMF).
  • Develop and maintain Authorization to Operate (ATO) documentation, including Security Plans, Cybersecurity Strategies, POA&Ms, Security Assessment Reports, and supporting artifacts.
  • Utilize eMASS, ITIPS, and other DoD cybersecurity tools to manage authorization packages and system compliance.
  • Conduct continuous monitoring activities throughout the System Development Life Cycle (SDLC) to identify, assess, and mitigate cybersecurity risks.
  • Perform vulnerability assessments using tools such as Nessus, analyze DISA STIG compliance, review IAVAs, and validate security configurations.
  • Evaluate system security posture through source code reviews, security testing, and compliance assessments.
  • Develop, implement, and maintain Information Assurance (IA) policies, procedures, and security architectures aligned with DoD and federal cybersecurity requirements.
  • Ensure compliance with NIST, FISMA, DoD cybersecurity directives, and applicable security standards.
  • Serve as the primary cybersecurity liaison between Program Management Offices (PMOs), development teams, system owners, government ISSMs, and other stakeholders.
  • Review vendor deliverables, assess technical security risks, recommend mitigation strategies, and validate cybersecurity documentation.
  • Provide guidance and recommendations on cybersecurity best practices to support secure system development and operations.
  • Communicate technical security concepts effectively to both technical and non-technical stakeholders.

Essential Job Qualifications and Requirements:

  • Security Clearance
    • Active Secret Clearance required
  • Education:
    • Bachelor's degree in Cybersecurity, Information Technology, Computer Science, or related field preferred.
  • Required Experience:
    • Experience working with NIST SP 800-53 Revision 5 (preferred)
    • Hands-on experience supporting DoD Information Systems and cybersecurity processes
    • Experience developing and supporting Authorization to Operate (ATO) packages
    • Hands-on experience implementing and assessing Risk Management Framework (RMF) security controls
    • Experience supporting SIPRNet information system authorization packages, including artifact development, control implementation, and security test documentation
    • Experience using eMASS to manage RMF and ATO activities
    • Experience supporting cybersecurity compliance throughout the System Development Life Cycle (SDLC)
  • Required Skill and Competencies
    • Strong understanding of DoD Information Assurance principles and cybersecurity compliance requirements
    • Experience with vulnerability management tools, including Nessus, DISA STIGs, and IAVA compliance
    • Excellent analytical, organizational, and problem-solving skills
    • Strong written and verbal communication skills with the ability to explain complex technical concepts to diverse audiences
    • Advanced proficiency with Microsoft Office Suite, including:
      • Microsoft Excel (PivotTables, VLOOKUP/XLOOKUP, formulas, and data analysis)
      • Microsoft Word (professional documentation and technical reports)
      • Microsoft PowerPoint (executive-level presentations)
  • Work Location Requirements
    • On-site in Kettering, OH
    • Must be willing to travel to the Pentagon or Fairfax, VA as required
Position Pay Range
$125,000—$140,000 USD

About Copper River & The Native Village of Eyak:

Owned by the Native Village of Eyak (NVE), a federally recognized Alaska Native Tribe, the Copper River Family of Companies are a collection of entities that deliver a complementary set of solutions and services to support the diverse missions and requirements of our clients. Proud participants of the Small Business Administration's (SBA) 8(a) Business Development Program since 2006, our companies consist of both current and graduation SBA 8(a) entities. It is our collective purpose to support the Tribe and diversify the NVE's ability to facilitate economic advancement.

The income generated from our companies helps the Native Village of Eyak fund health and social services, economic development, natural resource/environmental education, jobs, job training, and other benefits to the NVE in a manner that is consistent with Alaskan Native cultural values and traditions.

Copper River's Culture

The Copper River Family of Companies has a positive, supportive, and thriving culture. At the foundation of our culture is a focus on collaboration. No matter your role or which operating company you work for, we are ONE TEAM working toward the same goals for our customers and for our collective owner- The Native Village of Eyak. How we treat each other is just as important as the work we deliver.

Benefits

  • Comprehensive medical, dental, and vision coverage
  • Flexible Spending Account - healthcare and dependent care
  • Health Savings Account - high deductible medical plan
  • Retirement 401(k) with employer match
  • Open leave policy and paid holidays
  • Additional benefits including tuition reimbursement, transportation expense account, employee assistance program, and more!

Note: Benefits are offered based on employment classification and applicable contract requirements. Eligibility may vary by position.

Disclaimer:

The Copper River Family of Companies provides equal employment opportunities to all employees and applicants for employment and prohibits discrimination and harassment of any type without regard to race, color, religion, age, sex, national origin, disability status, genetics, protected veteran status, sexual orientation, gender identity or expression, or any other characteristic protected by federal, state, or local laws.