Information System Security Officer (ISSO)

Joint Activities

$104K — $166K *
Information Technology
5 - 7 years of experience
Job Overview by Ladders

Qualifications

  • 6+ years of experience in IT or related technical field (or 10 years without a BS degree)
  • 4+ years supporting DoD/IC or government systems
  • Hands-on experience with RMF tasks and security authorization artifacts
  • Strong knowledge of NIST SP 800-53 controls
  • Experience with vulnerability and configuration compliance workflows
  • Familiarity with Linux environments and hardening practices
  • Active TS/SCI security clearance with current polygraph required.

Responsibilities

  • Support the system security lifecycle across development and operations
  • Execute and maintain RMF activities like control implementation and assessment support
  • Maintain security authorization artifacts including SSP and control narratives
  • Oversee continuous monitoring activities including vulnerability management and compliance
  • Review and approve security changes and validate configurations post-upgrades
  • Participate in incident response and reporting activities
  • Manage least privilege/access governance and conduct access reviews
  • Translate security requirements into actionable implementation guidance for engineering teams.

Benefits

  • Increased sign-on bonus eligibility may be available
  • Full-time on-site work environment in Laurel, MD
  • Access to mission-critical projects in a complex HPC environment
  • Collaborative work with subcontractors and customer personnel
  • Potential for professional growth in security operations.
Full Job Description
Responsibilities

Peraton Labs is seeking a poly cleared Information System Security Officer for a mission-critical, highly complex HPC environment enabling research across multiple security domains. You will own day-to-day security operations aligned to RMF, drive continuous monitoring, maintain ATO posture, and partner closely with subcontractor and customer personnel to ensure implementation and compliance.

 

This position requires full-time on-site work in Laurel, MD.

 

Key responsibilities may include

  • Act as the ISSO supporting the system security lifecycle across development, operations, and modernization
  • Execute and maintain RMF activities (e.g., control implementation oversight, evidence collection, assessment support, POA&M management, continuous monitoring)
  • Maintain security authorization artifacts (e.g., SSP, control narratives, diagrams, inheritance/leverage controls, CM plan, incident handling plan, contingency artifacts, user/admin procedures)
  • Operate continuous monitoring: vulnerability management, config compliance, patching coordination, scan result triage, risk acceptance, and remediation verification
  • Review and approve security-relevant changes through configuration/change control and validate security configurations after major upgrades
  • Support incident response and reporting: participate in investigations, coordinate containment actions, preserve evidence, and contribute to post-incident lessons learned
  • Ensure least privilege/access governance: account management oversight, privileged access workflows, periodic access reviews, and audit compliance requirements
  • Translate security requirements into implementation guidance that engineering teams can operationalize (clear, testable, and automatable where possible)

 

*This position may be eligible for an increased sign-on bonus. Eligibility, bonus amount, and applicable terms and conditions will be discussed during the recruiting process*

Qualifications

Required qualifications

  • 6+ years of experience and a BS in computer science, IT, or related technical discipline, MS and 4+ years of experience. Four years of additional experience is required in lieu of a Bachelors’ degree for a total of 10 years of experience
  • 4+ years of experience supporting DoD/IC or government systems
  • Hands-on experience executing RMF tasks and maintaining authorization artifacts (SSP, POA&Ms, continuous monitoring evidence)
  • Strong working knowledge of NIST SP 800-53 controls and how they map to technical implementations and procedures
  • Experience with vulnerability and configuration compliance workflows
  • Familiarity with Linux-based enterprise environments and common hardening concepts
  • Ability to communicate risk clearly to both technical engineers and non-technical leadership
  • Strong documentation discipline
  • Active TS/SCI security clearance with a current polygraph is required.

 

Preferred qualifications

  • Experience securing or assessing containerized workflows (e.g., container runtime hardening, image governance, supply chain considerations)
  • Experience with eMASS (or comparable GRC tooling), security control inheritance models, and assessor engagement.
  • Familiarity with vulnerability tooling and security monitoring concepts
  • Active certifications such as: CISSP, CISM, CAP, GSLC, Security+, CCSP, etc.
  • Experience with data protection requirements relevant to sensitive environments

#MDPM

#MDFSP

Target Salary Range$104,000 - $166,000. This represents the typical salary range for this position. Salary is determined by various factors, including but not limited to, the scope and responsibilities of the position, the individual’s experience, education, knowledge, skills, and competencies, as well as geographic location and business and contract considerations. Depending on the position, employees may be eligible for overtime, shift differential, and a discretionary bonus in addition to base pay.

Similar Jobs

More Jobs at Joint Activities

More Information Technology Jobs

Find similar Information System Security Officer (ISSO) jobs: