About this role
Information System Security Officer (ISSO)
Position / LCAT: DE-0002
Work Arrangement: Onsite 3–5 days per week
Clearance: Active Secret clearance required
Period of Performance:
August 31, 2026 – May 21, 2027 nformation System Security Officer (ISSO)
Position / LCAT: DE-0002
Work Arrangement: Onsite 3–5 days per week
Clearance: Active Secret clearance required
Position Overview
We are seeking an Information System Security Officer (ISSO) to support the day-to-day cybersecurity posture and compliance of Department of Defense information systems. The ISSO will work closely with system owners, engineers, administrators, cybersecurity leadership, and other technical stakeholders to maintain system authorization and ensure compliance with DoD and NIST cybersecurity requirements.
This is a hands-on cybersecurity role with significant responsibility for Risk Management Framework (RMF) activities, continuous monitoring, vulnerability management, security documentation, POA&M management, and eMASS administration.
Key Responsibilities
- Maintain and update System Security Plans (SSPs) and supporting RMF documentation.
- Support the full RMF lifecycle, including categorization, control implementation, assessment, authorization, and continuous monitoring.
- Create, maintain, and track Plans of Action and Milestones (POA&Ms).
- Maintain system authorization and compliance records within eMASS.
- Review and analyze vulnerability scan results using tools such as ACAS/Tenable.
- Review and validate DISA STIG compliance findings.
- Track vulnerabilities and coordinate remediation activities with system administrators, engineers, and other technical teams.
- Support continuous monitoring activities, including security control validation, log review, documentation updates, and security status tracking.
- Collect and maintain audit and authorization evidence.
- Support incident-response activities affecting assigned systems.
- Work with system owners, administrators, engineers, ISSMs, and other stakeholders to resolve cybersecurity and compliance issues.
- Maintain accurate, audit-ready security documentation throughout the authorization lifecycle.
Required Qualifications
- Active Secret security clearance.
- Typically 2–4 years of cybersecurity, information assurance, ISSO, or related experience.
- Working knowledge of the Risk Management Framework (RMF) and NIST SP 800-53.
- Experience developing or maintaining SSPs and POA&Ms.
- Experience with vulnerability management and security compliance.
- Familiarity with eMASS.
- Familiarity with ACAS/Tenable, STIG Viewer, or comparable vulnerability/compliance tools.
- Strong documentation, analytical, organizational, and issue-tracking skills.
- Ability to communicate effectively with both technical and non-technical stakeholders.
Preferred Qualifications
- Bachelor's degree in Cybersecurity, Information Technology, Computer Science, or a related discipline.
- Relevant DoD 8140 cybersecurity certification; CISSP or comparable certification is strongly preferred.
- Experience supporting DoD information systems.
- Experience with ATO packages and continuous monitoring.
- Ability to operate effectively in a fast-paced, compliance-driven environment.
- Strong judgment when evaluating cybersecurity risk and mission requirements.
- Strong attention to detail in authorization, documentation, vulnerability remediation, and continuous monitoring.
Candidates must be able to support an onsite schedule of approximately 3–5 days per week.
