Title: Information Systems Security Officer (ISSO)
Location: Clarksburg, MD (Onsite)
Type: Direct Hire
Compensation: $150,000/year (salary)
Schedule: 40 hours/week
Clearance Required: Active TS/SCI with Polygraph (required to start)
Role OverviewWe're hiring an
Information Systems Security Officer (ISSO) to support
mission-critical, classified environments. In this role, you'll help ensure information systems stay compliant throughout the
Risk Management Framework (RMF) lifecycle-supporting
ATO packages, continuous monitoring, assessments, and audit readiness. You'll partner closely with technical teams and security stakeholders to drive secure, compliant system operations.
What You'll Do (Key Responsibilities) - Support the full RMF lifecycle for classified information systems
- Build and maintain security authorization packages and RMF documentation
- Coordinate and support Authority to Operate (ATO) efforts
- Perform/control security assessments, compliance reviews, and control validation
- Track vulnerabilities, findings, and remediation activities (POA&Ms, etc.)
- Support Continuous Monitoring (ConMon) and ongoing security activities
- Review scan results/configurations to ensure alignment with security requirements
- Work with system teams to implement/maintain required security controls
- Participate in audits, inspections, and cybersecurity compliance reviews
- Provide risk-based recommendations to improve security posture
Required Qualifications (Must-Haves) - Active TS/SCI with Polygraph
- Experience in ISSO / Information Assurance / cybersecurity compliance in classified environments
- Strong knowledge of RMF and the security authorization process (ATO)
- Familiarity with:
- NIST SP 800-53 (Rev 3 and/or Rev 5)
- NIST SP 800-37
- Experience with compliance/configuration scanning and assessment workflows
- Strong communication skills (written + verbal) and comfort working cross-functionally
Tools/Platforms (Experience With)Experience with RMF/cyber compliance tools such as:
- XACTA
- LATTE / ART
- BISCOTTI
- WATCHCAT
- STE
(Experience with similar tools is also valuable.)
Documentation You Should Be Comfortable WithHands-on experience developing/reviewing security documentation such as:
- SSP, POA&M, SAR, RAR
- CMP, CP, BIA
- SPFs / exceptions and related artifacts
- AARs and audit support documentation
Preferred / Nice-to-Have - Prior support of classified government systems
- Experience partnering with ISSMs, System Owners, Security Control Assessors, and Authorizing Officials
- Familiarity with vulnerability remediation and system administration security concepts
- Certifications like Security+, CISSP, CAP, CASP+, or CISM
System One not only serves as a valued partner for our clients, but we offer eligible employees health and welfare benefits coverage options including medical, dental, vision, spending accounts, life insurance, voluntary plans, as well as participation in a 401(k) plan.
#M-1
#LI-
Ref: #851-Rockville-S1