Aderas is looking for a Junior Information Systems Security Officer to assist in managing system security packages, tracking vulnerabilities, maintaining continuous monitoring data, and utilizing government GRC tools to support FedRAMP 20x automated validation.
Key Responsibilities
- Maintain and update FedRAMP security package components (SSP, SAP/SAR support, POA&M, control evidence).
- Support implementation and documentation of NIST SP 800-53 controls and NIST RMF (800-37) activities.
- Assist with continuous monitoring (ConMon): monthly/quarterly evidence collection, vulnerability status reporting, patch compliance, configuration baselines.
- Participate in change management and security impact analysis for system changes.
- Track and remediate findings; support POA&M creation, updates, milestones, and risk narratives.
- Support incident response documentation and coordination (per policy).
- Prepare for and support 3PAO testing and customer/government reviews.
- Help improve evidence workflows (e.g., templates, checklists, and basic automation).
Knowledge & Technical Skills
- JCAM & GRC Tools: Entry-level experience to Governance, Risk, and Compliance platforms like JCAM, CSAM, or eMASS to update control data and pull security reports.
- SharePoint Document Control: Experience using Microsoft SharePoint for organizing the Body of Evidence (BoE), managing access control for sensitive compliance artifacts, and tracking document workflows.
- FedRAMP 20x Automation: Basic understanding of machine-readable compliance architecture (OSCAL JSON/YAML formats) and utilizing automated continuous tracking methods.
- Vulnerability & Log Management: Experience gathering outputs from cloud security posture management (CSPM) utilities and continuous validation scanning infrastructure.
Certifications, Preferred (one or more):
- CompTIA Security+ (strongly preferred)
- (ISC)² SSCP or ISC2 Certified in Cybersecurity (CC)
- AWS/Azure/GCP foundational cert (e.g., AWS Cloud Practitioner / Azure Fundamentals)
- CAP (ISC2), CRISC, or vendor security specialty certs
- NIST RMF training/certifications
Required Degrees & Experience
- Bachelor's Degree in Cybersecurity, Computer Science, Information Technology, or equivalent technical training.
- 1-3 years of experience in IT compliance, federal auditing, or cybersecurity operations.
Security Requirement
- Active DoD Secret clearance
Location
- Hybrid/On-site requirements
Join the Aderas team!
Aderas is looking to recruit and retain only the best and brightest. If you like working with emerging technologies, using your unique personal skills to solve technical, functional, and organizational issues, and can easily adapt to the ever-changing IT market, then Aderas is the place for you! We are a vibrant company delivering implementation services & support for enterprise solutions and custom application development. We strive to form long-term partnerships with our clients to foster an environment based on trust, a proven history of delivery, and camaraderie.
Why Aderas?
We sincerely try to shape our employees' lives by administering a generous package of employee benefits. Our company culture encourages collaboration, creative thinking, and growth. Headquartered in Reston Town Center, in Reston, VA, the Aderas main office is a short step away from shopping, dining, and a movie theater.
Beyond the tangible and intangible rewards, Aderas provides the following:
- Pay for Life, AD&D, Short-term disability, and Long-term disability at no cost to the employee.
- Employer contribution toward monthly health insurance premiums.
- 401k plan which employees are eligible for after being with the company for 3 months.
- Safe Harbor plan in which Aderas contributes 3% of employees' salaries once a year.
- A week of paid training and reimbursement for approved professional courses and tests.
- Monthly allowance for cell phone bills.