Information Systems Security Officer (ISSO)Position Description:We are seeking an Information System Security Officer (ISSO) to support the day-to-day cybersecurity posture of assigned information systems. This role is responsible for maintaining RMF documentation, supporting continuous monitoring, tracking vulnerabilities, managing POA&Ms, and helping ensure systems remain compliant with DoD and NIST security requirements. ISSOs are typically the hands-on security practitioners closest to the system and its operational controls.
Location: Onsite 3-5 days a week
Key Responsibilities- Maintain and update the System Security Plan (SSP) and related RMF artifacts
- Support continuous monitoring activities, including log review, control checks, and security status tracking
- Create, update, and track POA&Ms for identified weaknesses and remediation actions
- Analyze vulnerability scan results and validate DISA STIG compliance findings Support RMF steps including categorization, control implementation, assessment, authorization, and monitoring
- Maintain system records in eMASS and support package updates
- Coordinate incident response activities for assigned systems
- Partner with system owners, admins, engineers, and the ISSM to resolve security issues
Requirements
Required Qualifications- Bachelor's degree in Cybersecurity, Information Technology, Computer Science, or related field preferred
- Typically, 2-4 years of cybersecurity or information assurance experience
- Active Secret clearance
- Relevant DoD 8140 certifications such as CISSP strongly preferred
- Working knowledge of NIST SP 800-53, and DoD cybersecurity compliance processes
- Experience with SSPs, POA&Ms, vulnerability management, and audit evidence collection
- Familiarity with eMASS, ACAS/Tenable, STIG Viewer, and related compliance tools
- Strong documentation, analytical, and issue-tracking skills
- Ability to work with technical and non-technical stakeholders
Preferred Qualifications- Ability to operate in fast-paced, compliance-driven environments
- Strong judgment in evaluating cyber risk and balancing mission needs
- Proven ability to build trust with technical teams and senior leadership
- Detail-oriented approach to documentation, authorization, and continuous monitoring requirements