> Markdown version of [/jobs/ext/1207027-information-systems-security-officer-isso](https://www.wearedevelopers.com/jobs/ext/1207027-information-systems-security-officer-isso). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Information Systems Security Officer (ISSO) - **Company:** LightGrid, LLC - **Location:** Fort Meade, MD, United States - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** Cyber Security, Computer Networks, Automated Information System (AIS), Internet Protocol Telephony, Information Technology, Plan of Action and Milestones - **Published:** July 8, 2026 - **Apply:** https://www.clearancejobs.com/jobs/9018265/information-systems-security-officer-isso ## About the Role Bachelor's in Information Assurance, Information Technology, or Cybersecurity CompTIA Security+ Required 7+ years with RMF, ATO, NIST 800-53 Rev. 4 & Rev. 5, POA&M, ACAS, STIGs, DoD security policies, eMASS. * Work independently to manage and execute all assigned information assurance and security duties. * Strong written and verbal communication skills are required to advise the government, prepare documentation, and coordinate with team members. ## Description Please Note: Must be able to Report to Fort Meade, MD a few times a week as needed. The contractor shall perform Information Systems Security Manager and Information Systems Security Officer duties. Key responsibilities include: * Ensuring the EVS unclassified and classified VoIP systems remain compliant with all applicable DISA, Joint Force Head Quarters-DoD Information Network, and United States Cyber Command security policies and directives. * Creating, maintaining, and updating security documentation and artifacts to obtain and sustain a DoD Authority to Operate (ATO) under the Risk Management Framework (RMF), including creating/managing Change Requests for new software. * Reviewing and providing technical recommendations and mitigations based on results from Assured Compliance Assessment Solution (ACAS) scans, Cybersecurity Service Provider (CSSP), and Host Based Security System (HBSS) reports. * Advising the Government on security matters in a continuous cycle throughout the project's period of performance. * Developing and preparing all required RMF package documentation to obtain and maintain ATO, including system registration with the DoD Information Assurance Program, control categorization, and initiation of the CNSSI 1253 review. * Facilitating the implementation and validation of assigned NIST 800-53 security controls and preparing the Security Assessment Report (SAR). * Developing and managing Security Plans of Action and Milestones (POA&M) to document and track the status of corrective actions for NIST 800-53 controls. * Providing Security Engineering Services to support the RMF lifecycle, addressing new customer requirements and system upgrades. * Maintaining the Certification and Accreditation (C&A) of the program's automated information systems in accordance with DoD compliance standards. * Responding and managing DISA Task Orders (DTOs) Security Plans of Action and Milestones (POA&M) to document and track the status of corrective actions for NIST 800-53 controls * Manage updating CMRS, Axonius, MAPS/DITPR, SNAP * Review STIGs for completion * Weighing in on Implementation plans for CAB Approvals ## Related Videos - [What makes Cybersecurity different for critical infrastructure?](https://www.wearedevelopers.com/videos/571-what-makes-cybersecurity-different-for-critical-infrastructure) - [Distributed search under the hood](https://www.wearedevelopers.com/videos/256-distributed-search-under-the-hood) - [Enabling intelligent logistics automation: home-grown Industrial IoT platform at Austrian Post](https://www.wearedevelopers.com/videos/2018-enabling-intelligent-logistics-automation-home-grown-industrial-iot-platform-at-austrian-post) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [It's not easy being green](https://www.wearedevelopers.com/videos/558-it-s-not-easy-being-green) ## Related Articles - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [How should you format your IT resume?](https://www.wearedevelopers.com/magazine/68-how-should-you-format-your-it-resume) - [The Overflow: Security and Privacy](https://www.wearedevelopers.com/magazine/715-the-overflow-security-and-privacy) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking)