> Markdown version of [/jobs/ext/1180361-information-system-security-officer-isso-lead-remote](https://www.wearedevelopers.com/jobs/ext/1180361-information-system-security-officer-isso-lead-remote). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Information System Security Officer (ISSO) Lead (Remote) - **Company:** OXLEY ENTERPRISES INC - **Location:** Stafford, VA, United States (Remote available) - **Experience:** Expert - **Salary:** $111,776.0 - $164,390.0 - **Contract:** Permanent contract - **Skills:** Data Analysis, Cyber Security, Data Security, Information Security Management, Internet Service Provider, Information Systems Security Architecture Professional, Software Engineering, Plan of Action and Milestones - **Published:** July 4, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=9c52cbc6276a9f7b ## About the Role Minimum/General Experience: 10 years of experience in information systems security Minimum Education: Bachelor's Degree in cybersecurity, information assurance, or related field; Certified Information Systems Security Professional (CISSP) or Certified Authorization Professional (CAP) (preferred) Essential Skills/Qualifications: * Expert knowledge of National Institute of Standards and Technology (NIST) Risk Management Framework (RMF) process (e.g., Categorize, Select, Implement, Assess, Authorize, and Monitor) * Excellent ability to initiate actions required to establish new ATOs/ATCs * Excellent ability to maintain existing authorizations * Excellent ability to attend or conduct security audits * Excellent experience drafting assessment finding mitigation plans * Excellent knowledge of multi-tenant ATO inheritance frameworks * Excellent ability to support authorization boundary management between platform and tenant layers * Above average ability to maintain security documentation (e.g., Privacy Threshold Analysis (PTA), Privacy Impact Assessment (PIA), Security Impact Analysis (SIA), Business Impact Analysis (BIA), Data Security Categorization (DSC), hardware/software lists, and Ports, Protocols, and Services Management (PPSM) documents) * Experience supporting a federal agency * Excellent verbal and written communication skills ## Description Lead the authorization integrity of one of the Department of Veterans Affairs (VA's) most complex multi-tenant cloud platforms. As the Information System Security Officer (ISSO) Lead, you will manage Authorization to Operate (ATO)/Approval to Connect (ATC) sustainment, security audits, and continuous monitoring across a platform undergoing active authorization boundary restructuring., Position Description: The ISSO Lead manages all Authorization to Operate (ATO)/Approval to Connect (ATC activities, coordinates security audits and assessments, and oversees Plan of Action and Milestones (POA&M) lifecycle management across the tiered multi-tenant authorization environment., * Sedentary Work - Exerting up to 10 pounds of force occasionally and/or a negligible amount of force frequently or constantly to lift, carry, push, pull or otherwise move objects. * Typing, communicating, repetitive motions. * Close visual acuity to prepare and analyze data, view computer monitors and read. May need to view presentation screens and other visual aids in a virtual setting. * Inside environmental conditions with protection from outside elements. Security: Active Federal Civilian Public Trust clearance * U.S. Citizenship or Permanent Resident that has lived in the United States for at least 3 years Federal Civilian Public Trust Consists of a review of up to but not limited to: * Covers 10 year period and in some instances lifetime events * OPM Security Investigations Index (SII) * DOD Defense Central Investigations Index (DCII) * National Agency Check (NAC) records * FBI name check * FBI fingerprint check * Credit report check * Written inquiries to previous employers and references listed on the application for employment * Potential interviews with the subject, spouse, neighbors, supervisor, coworkers * Law enforcement check * Court records check * Education check - Attendance and Degrees Acceptable Credentials Tasks/activities include, but are not limited to: * Initiates actions required to establish new ATOs and ATCs * Maintains all existing authorizations including periodic assessment oversight and staffing of all ATO audits * Coordinates all RMF activities with the AO, ISSO counterparts, ISO, and designated stakeholders * Attends or conducts all security audits including General (IG), Security Assessment and Validation Data (SAVD), Cybersecurity Compliance Task Force (CCTF), Office of Information Security (OIS), Information Security Risk Management (ISRM), Governance Risk and Compliance (GRC), and Information Security PolicyStrategy (ISPS) assessments * Attends closeout meetings and reviews all reported findings for accuracy * Drafts assessment finding mitigation plans including roadmap and timeline * Submits Plans of Action and Milestones (POA&M) for all prescribed remediations * Maintains program security documents, diagrams, and artifacts required for ATO/ATC upkeep including PTA, PIA, SIA, BIA, DSC, hardware lists, software lists, and PPSM documents * Collaborates with application development teams and platform architects to establish and maintain Interconnection Diagrams (ICD), High Level Diagrams (HLD), and security assessment boundary diagrams * Supports the Multi-Tenant Platform Evolution Strategy ensuring ATO inheritance frameworks and authorization boundaries between platform and tenant layers are clearly defined * Ensures no lapse in ATO status for any platform capability, service, or hosted application * Contributes to the monthly RMF, security, and ATO status report including authorization posture, renewal timelines, and control implementation status ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [Crypto-secure Data Management with In-Database Blockchain](https://www.wearedevelopers.com/videos/632-crypto-secure-data-management-with-in-database-blockchain) - [Data Science in Retail](https://www.wearedevelopers.com/videos/586-data-science-in-retail) - [Cyber Sleuth: Finding Hidden Connections in Cyber Data](https://www.wearedevelopers.com/videos/893-cyber-sleuth-finding-hidden-connections-in-cyber-data) - [Web-based Information Visualization](https://www.wearedevelopers.com/videos/84-web-based-information-visualization) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Best Paying Jobs in Technology](https://www.wearedevelopers.com/magazine/256-best-paying-jobs-in-technology) - [Fully Remote Software Engineer Jobs](https://www.wearedevelopers.com/magazine/447-fully-remote-software-engineer-jobs) - [Is Software Engineering Over-Saturated?](https://www.wearedevelopers.com/magazine/418-is-software-engineering-over-saturated)