> Markdown version of [/jobs/ext/1047699-cleared-information-system-security-officer-isso-l3](https://www.wearedevelopers.com/jobs/ext/1047699-cleared-information-system-security-officer-isso-l3). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Cleared Information System Security Officer (ISSO) - L3 - **Company:** Virtual, Inc. - **Location:** Lorton, VA, United States - **Experience:** Expert - **Salary:** $140,000.0 - $180,000.0 - **Contract:** Permanent contract - **Skills:** Microsoft Windows, Cloud Computing Security, Cyber Security, Information Systems, Linux, Information Security Management, SAP (Applications), Security Software, Virtualization Technology, Software Vulnerability Management, SARS Software Products, Information Technology, Splunk, Vulnerability Analysis - **Published:** June 15, 2026 - **Apply:** https://www.clearancejobs.com/jobs/8976149/cleared-information-system-security-officer-isso-l3 ## About the Role * 5-7+ years of cybersecurity, information assurance, or information systems security experience. * Bachelor's degree in Cybersecurity, Information Technology, Computer Science, Information Systems, or a related field (or equivalent experience). * Experience supporting DoD RMF processes and cybersecurity compliance efforts, with working knowledge of JSIG requirements, NIST SP 800-53 security controls, STIG implementation, and vulnerability management., * Experience supporting SAP, SCI, or other classified environments. * Experience with Windows, Linux, and virtualized environments; familiarity with Cross Domain Solutions (CDS). * Experience with ACAS, Splunk, Tenable, Trellix ePO, or similar cybersecurity tools. * Knowledge of cloud security requirements within DoD environments., * Must be within driving distance of Lorton, VA OR willing to relocate there (Relocation Assistance Package Available) * Must be willing to work onsite (This role may include the need to work outside of core hours on high priority investigations and may also include on-call responsibilities) * Active TS/SCI clearance required. * Current DoD 8570/8140 compliant certification such as CISA, CASP+, CISSP, or CISM. * Strong written and verbal communication skills with excellent attention to detail and documentation accuracy. * Ability to work independently and collaboratively in a mission-focused environment. * Must be willing and able to travel frequently What is Important to Us: * You are an excellent communicator in writing and speaking. * You have the ability to work independently but also value teamwork. * Your problem-solving skills are excellent. * You are looking for a job where performance appraisals occur regularly, and you look forward to advancing your career. * You seek a community of virtue-centered co-workers and clients. ## Description Virtual Service Operations is searching for an Information System Security Officer (ISSO) to join our dynamic team in Lorton, Virginia. As an ISSO, you will be responsible for supporting the cybersecurity, compliance, and risk management activities of DoD information systems operating within classified and/or controlled environments. You will work closely with the ISSM, system administrators, engineers, program managers, and government stakeholders to ensure systems maintain compliance with JSIG, DoD RMF, and applicable IC and DoD directives. If you have a strong background in information assurance, RMF processes, and a passion for securing mission-critical systems, we want to hear from you!, * Support the implementation and maintenance of cybersecurity requirements in accordance with JSIG, RMF, and applicable DoD policies. * Develop and maintain RMF documentation including System Security Plans (SSPs), Security Control Traceability Matrices (SCTMs), Plans of Action and Milestones (POA&Ms), Security Assessment Reports (SARs), and Continuous Monitoring Plans. * Conduct continuous monitoring activities and review vulnerability scan results from tools such as ACAS to maintain system authorization. * Track remediation efforts, validate closure of identified vulnerabilities, and assist with risk assessments and mitigation strategies. * Coordinate and support security audits, inspections, and assessments; investigate and document cybersecurity incidents. * Verify proper implementation of system hardening standards, review proposed system changes, and enforce least privilege and separation of duties principles. * Maintain accurate cybersecurity documentation and prepare reports and briefings for program leadership, the ISSM, and government representatives. ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Docker network without Docker](https://www.wearedevelopers.com/videos/1418-docker-network-without-docker) - [Our journey with Spring Boot in a microservice architecture](https://www.wearedevelopers.com/videos/511-our-journey-with-spring-boot-in-a-microservice-architecture) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [One Pipeline, Three Regulator - SBOM Compliance for the Developer](https://www.wearedevelopers.com/videos/100169-one-pipeline-three-regulator-sbom-compliance-for-the-developer) - [DevSecOps culture](https://www.wearedevelopers.com/videos/783-devsecops-culture) ## Related Articles - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Fully Remote Software Engineer Jobs](https://www.wearedevelopers.com/magazine/447-fully-remote-software-engineer-jobs) - [Best Paying Jobs in Technology](https://www.wearedevelopers.com/magazine/256-best-paying-jobs-in-technology) - [The Overflow: Security and Privacy](https://www.wearedevelopers.com/magazine/715-the-overflow-security-and-privacy) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed)