Information Systems Security Officer (ISSO)As an ISSO, you will maintain the security posture of assigned systems and support Risk Management Framework (RMF) activities across the system life cycle. The ISSO partners with system owners, security leadership, assessors, administrators, and mission stakeholders to manage authorization documentation, monitor compliance, track vulnerabilities, and ensure systems operate within approved risk parameters.
What will you do?- Maintain the operational security posture of assigned information systems in coordination with system owners, ISSM/CISO, administrators, and authorization stakeholders.
- Support RMF activities, including control implementation, assessment support, authorization package development, continuous monitoring, and ongoing authorization.
- Develop and maintain security artifacts, including SSPs, SARs, POA&Ms, risk assessments, continuous monitoring evidence, and supporting procedures.
- Coordinate security control implementation with engineering, infrastructure, cloud, application, and operations teams throughout the system life cycle.
- Conduct or support audit log reviews, vulnerability scans, configuration reviews, internal assessments, and compliance monitoring.
- Track, validate, and report remediation of vulnerabilities, findings, control deficiencies, POA&M items, and risk acceptance decisions.
- Assess the security impact of system changes, software, cloud services, interconnections, and configuration updates.
- Support security event review, incident response coordination, escalation, reporting, and lessons learned.
- Prepare cybersecurity status updates, metrics, briefings, and compliance reports for leadership, customers, auditors, and assessors.
RequirementsCapabilities that will enable your success- Bachelor's degree in Cybersecurity, Information Systems, Computer Science, Information Technology, or related field; relevant experience may substitute when contractually permitted.
- 5+ years of cybersecurity, information assurance, security engineering, compliance, cloud security, or RMF experience.
- Experience supporting RMF authorization activities, including SSP, SAR, POA&M, risk assessment, continuous monitoring, vulnerability management, and audit review.
- Working knowledge of NIST RMF, NIST SP 800-37, NIST SP 800-53, and system life cycle security practices.
- Experience creating or maintaining cybersecurity policies, procedures, standards, security plans, and compliance documentation.
- Current role-aligned certification such as Security+, CySA+, CGRC, CISSP, CISM, CCSK, CCSP, or equivalent.
- Ability to communicate risk, compliance status, findings, and remediation priorities to technical and non-technical audiences.
Preferred Qualifications- Experience with federal or defense authorization packages, eMASS or similar GRC tools, vulnerability management platforms, cloud environments, and security assessments.
- Active U.S. Security Clearance and experience in DoD, Intelligence Community, federal, or cleared contractor environments.
Clearance Requirements- Applicants must be a U.S. Citizen and willing and eligible to obtain a U.S. Security Clearance at the Secret or Top-Secret level. Existing clearance is preferred.
BenefitsAt TheIncLab we recognize that innovation thrives when employees are provided with ample support and resources. Our benefits packages reflect that:
- Hybrid and flexible work schedules
- Professional development programs
- Training and certification reimbursement
- Extended and floating holiday schedule
- Paid time off and Paid volunteer time
- Health and Wellness Benefits include options for Medical, Dental, and Vision insurance along with access to Wellness, Mental Health, and Employee Assistance Programs.
- 100% Company Paid Benefits that include STD, LTD, and Life Insurance.
- Supplemental Life Insurance options for employees and family members.
- 401(k) Plan Options with employer matching
- Incentive bonuses for eligible clearances, performance, and employee referrals.
- A company culture that values your individual strengths, career goals, and contributions to the team.
**Salary range guidance provided is not a guarantee of compensation. Offers of employment may be at a salary range that is outside of this range and will be based on qualifications, experience, and possible contractual requirements.**This is a direct hire position, and we do not accept resumes from third-party recruiters or agencies.