> Markdown version of [/jobs/ext/1167124-information-system-security-officer-isso](https://www.wearedevelopers.com/jobs/ext/1167124-information-system-security-officer-isso). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Information System Security Officer (ISSO) - **Company:** OneZero Solutions - **Location:** Washington, DC, United States (Remote available) - **Experience:** Expert - **Salary:** $180,000.0 - $225,000.0 - **Contract:** Permanent contract - **Skills:** Training Data, Microsoft Access, Artificial Intelligence, Audit Trail, CompTIA Security+, Cyber Security, Information Systems, System Configuration, Data Transmissions, Data Integrity, Information Security Management, AI Infrastructure, Generative AI, Information Technology, Vulnerability Analysis - **Published:** July 3, 2026 - **Apply:** https://www.careerjet.com/jobad/usc9fe31c748ab271573914a4693ad5a00 ## About the Role * Bachelor's degree in Cybersecurity, Information Technology, Computer Science, Information Systems, or a closely related field * 5-8 years of total cybersecurity or information assurance experience, with demonstrated depth across the following disciplines: * 3+ years serving as an ISSO or equivalent role supporting federal, DHS, or IC programs * 3+ years supporting RMF activities including SSP development, security control assessment, continuous monitoring, and POA&M management * 2+ years working in classified environments at the TS/SCI level, including handling, storage, and processing of classified information in accordance with applicable security policies * 2+ years supporting or assessing Cross Domain Solutions (CDS), including data transfer validation, CDS policy enforcement, and coordination with accreditation authorities * 2+ years supporting AI, or data-intensive system assessments, with working knowledge of the unique security considerations for Generative AI systems including data integrity, model security, prompt injection risks, and output validation * Working knowledge of applicable federal security frameworks including NIST 800-53, NIST 800-137, ICD 503, CNSSI 1253, and DHS security policy * Familiarity with Archer GRC or equivalent governance, risk, and compliance platforms for control tracking and assessment documentation * Experience coordinating directly with ISSMs, ISSEs, system owners, and Authorizing Officials on security authorization and compliance matters * Certifications: Security+, CISSP, CISM, CAP, or equivalent ## Description Serve as the primary security point of contact for assigned systems, coordinating daily with system owners, ISSMs, ISSEs, program managers, and government stakeholder. Prepare and deliver regular security status reports covering system compliance posture, open POA&M items, continuous monitoring results, and outstanding risks. Brief system owners and program leadership on security findings, risk decisions, and authorization status changes., * Monitor and maintain the security posture of assigned TS/SCI systems, CDS, and Generative AI platforms, ensuring continuous compliance with applicable security requirements and authorization conditions * Conduct ongoing review of system configurations, user access, audit logs, and security controls to detect deviations, anomalies, and potential vulnerabilities * Perform continuous monitoring activities in accordance with NIST 800-137 and program-specific continuous monitoring strategies, including control assessments, log reviews, and security metric reporting * Track and report security-relevant changes to assigned systems, assessing the impact of changes on system authorization status and initiating re-assessment activities as required * Support and coordinate vulnerability scanning, patch compliance tracking, and remediation validation across assigned systems including AI infrastructure and CDS components * Maintain awareness of the evolving threat landscape as it pertains to Generative AI systems, including emerging risks such as prompt injection, model poisoning, data exfiltration through AI outputs, and adversarial inputs * Develop, maintain, and update complete RMF authorization packages including System Security Plans (SSP), Security Assessment Reports (SAR), Plans of Action and Milestones (POA&M), Interconnection Security Agreements (ISA), and supporting artifacts * Ensure all CDS-specific documentation requirements are met, including data transfer validation records, CDS accreditation artifacts, and coordination with the Authorizing Official and relevant accreditation bodies * Document AI-specific security considerations within authorization packages, including model provenance, training data controls, input/output validation mechanisms, and Generative AI-specific risk acceptance decisions * Coordinate with ISSEs and system architects to ensure security controls are correctly implemented, validated, and documented prior to authorization * Manage POA&M items through their full lifecycle - creation, tracking, evidence collection, remediation verification, and closure * Review remediation artifacts ## Related Videos - [One Pipeline, Three Regulator - SBOM Compliance for the Developer](https://www.wearedevelopers.com/videos/100169-one-pipeline-three-regulator-sbom-compliance-for-the-developer) - [Resilient by Design: Building Robust Architectures in High-Stakes Financial Systems](https://www.wearedevelopers.com/videos/2106-resilient-by-design-building-robust-architectures-in-high-stakes-financial-systems) - [Fireside Chat: Deep Learning, Deep Impact: Harnessing AI for Language Innovation](https://www.wearedevelopers.com/videos/612-fireside-chat-deep-learning-deep-impact-harnessing-ai-for-language-innovation) - [Your imaginations is (no longer) the limit: how Generative AI empowers people to be creative](https://www.wearedevelopers.com/videos/741-your-imaginations-is-no-longer-the-limit-how-generative-ai-empowers-people-to-be-creative) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [No Keys for the Robot: GitOps as the Control Plane for Autonomous Agents](https://www.wearedevelopers.com/videos/100095-no-keys-for-the-robot-gitops-as-the-control-plane-for-autonomous-agents) ## Related Articles - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [The Overflow: Security and Privacy](https://www.wearedevelopers.com/magazine/715-the-overflow-security-and-privacy) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Best Paying Jobs in Technology](https://www.wearedevelopers.com/magazine/256-best-paying-jobs-in-technology) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities)