> Markdown version of [/jobs/ext/1147347-information-systems-security-officer](https://www.wearedevelopers.com/jobs/ext/1147347-information-systems-security-officer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Information Systems Security Officer - **Company:** Booz Allen Hamilton Inc. - **Location:** Chantilly, VA, United States - **Experience:** Expert - **Salary:** $77,600.0 - $176,000.0 - **Contract:** Permanent contract - **Skills:** Microsoft Windows, Audit Trail, Cyber Security, Information Systems, Identity and Access Management, Information Security Management, Network Security, Red Hat Enterprise Linux, Software Vulnerability Management, Splunk, Plan of Action and Milestones, Vulnerability Analysis - **Published:** July 2, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=565a9174b8c869c9 ## About the Role * 5+ years of experience with NIST 800-53, ICD 503, RMF, and secure system operations * Experience developing and maintaining A&A artifacts * Experience with STIGs, Tenable scanning, mitigation of ACAS results, CVE research, and vulnerability remediation coordination * Experience solving technical problems quickly and identifying opportunities to automate repetitive processes * Experience building or reviewing SPLUNK dashboards and audit analysis * Experience with Cybersecurity in the IC community * Knowledge of network security principles and practices * TS/SCI clearance with a polygraph * HS diploma or GED * IAM Level III certification, such as CISSP, GSLC, or CISM Nice If You Have: * Experience as an ISSO, ISSM, ISSE, or SCA supporting classified programs * Experience coordinating and documenting data spill response activities * Possession of strong communication and leadership skills * Bachelor's degree in a Cybersecurity or IT related field preferred * CCNA, Red Hat, or Windows certification ## Description Support mission-critical national security programs as the lead Information Systems Security Officer (ISSO) overseeing the full lifecycle of Risk Management Framework (RMF) authorization activities. You will rely on cybersecurity and Information Assurance (IA) background to be a technical leader and support Enterprise activities and Booz Allen customers throughout multiple classified computing domains. You will assume responsibility for ensuring all Information System Security policies, standards, and directives are enforced to support assessment, authorization and continued operation of information systems processing classified information. You will define security expectations, drive the remediation of vulnerabilities, and collaborate across multidisciplinary teams to ensure systems remain authorized, protected, and mission ready. How You'll Contribute. * Lead RMF authorization activities, including system categorization, control selection, assessment preparation, authorization packages, technical vulnerability assessments, and ongoing monitoring. * Oversee vulnerability management cycles, including ACAS reviews, CVE analysis, plugin evaluation, POA&M development, and mitigation coordination. * Direct the development, maintenance, and accuracy of all A&A artifacts, such as SSP, POA&M, CONOPS, and monitoring plans. * Manage audit log collection, review, dashboard analysis, and reporting through SPLUNK and other enterprise tools. * Ensure system incident response and recovery efforts follow approved procedures and maintain full security functionality. * Serve as the central point of contact for security posture, policy interpretation, and compliance guidance. As an ISSO in a high-visibility mission space, you will protect systems critical to national security. You will be empowered to drive RMF excellence, influence system design and security decisions, and mentor technical teams in secure operations. ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Resilient by Design: Building Robust Architectures in High-Stakes Financial Systems](https://www.wearedevelopers.com/videos/2106-resilient-by-design-building-robust-architectures-in-high-stakes-financial-systems) - [Our journey with Spring Boot in a microservice architecture](https://www.wearedevelopers.com/videos/511-our-journey-with-spring-boot-in-a-microservice-architecture) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [One Pipeline, Three Regulator - SBOM Compliance for the Developer](https://www.wearedevelopers.com/videos/100169-one-pipeline-three-regulator-sbom-compliance-for-the-developer) - [Organizational Change Through The Power Of Why - DevSecOps Enablement](https://www.wearedevelopers.com/videos/478-organizational-change-through-the-power-of-why-devsecops-enablement) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Best Paying Jobs in Technology](https://www.wearedevelopers.com/magazine/256-best-paying-jobs-in-technology) - [Building Security Champions](https://www.wearedevelopers.com/magazine/87-building-security-champions) - [The Overflow: Security and Privacy](https://www.wearedevelopers.com/magazine/715-the-overflow-security-and-privacy) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed)