> Markdown version of [/jobs/ext/1243247-senior-information-system-security-officer](https://www.wearedevelopers.com/jobs/ext/1243247-senior-information-system-security-officer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Senior Information System Security Officer - **Company:** Caci Inc - **Location:** National, WA, United States - **Experience:** Expert - **Salary:** $105,100.0 - $231,100.0 - **Contract:** Permanent contract - **Skills:** Cloud Computing Security, Configuration Management, Cyber Security, Information Systems, Information Security Management, Smartsuite, Requirements Traceability, Security Software, Software Asset Management, EndPointSecurity, Data Processing, Information Technology, Plan of Action and Milestones, Vulnerability Analysis - **Published:** July 11, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=2f2d9adeec1e9db8 ## About the Role * U.S. Citizenship required * FEMA EOD suitability or Current DHS or FEMA EOD preferred * BS/BA + 15 years of applicable experience in information security * Must have one of the following Information Assurance Technician (IAT) Level III qualifications: * Certified Information System Security Professional (CISSP) * Certified Information Security Manager (CISM) * CompTIA Advanced Security Practitioner (CASP+) * 10+ years of experience in information security * Demonstrated expertise in RMF, Information Security processes, audits, tools, implementation, FISMA, NIST, IT security * Experience developing System Security Plans, POA&Ms, and Configuration Management Plans * Knowledge of NIST SP 800-37, NIST SP 800-53, and DHS 4300 Series requirements Desired: * Active Secret security clearance * Previous DHS or DoD experience * Experience with CSAM, RegScale, eMASS, or similar GRC tools * Experience supporting emergency operations or disaster response missions * Knowledge of cloud security and FedRAMP authorization processes * Experience with continuous monitoring and automated security tools * Strong communication skills for presenting to senior leadership ## Description CACI is searching for a Senior Information System Security Officer (Senior ISSO) to support the FEMA Office of the Chief Information Security Officer (OCISO) in Washington, D.C. As a Senior Information System Security Officer, you will play a crucial role in ensuring the security and compliance of FEMA's information systems. You will work in a dynamic environment, collaborating with IT system owners, stakeholders, and cybersecurity professionals to implement and maintain robust security controls. Your efforts will directly contribute to safeguarding FEMA's mission-critical systems and data. The Senior ISSO will serve as the single point of contact for the Cybersecurity Division on all systems security matters, leading cybersecurity engineering efforts for assigned Program Management Organizations with direct support to the Compliance Branch Lead. This includes spearheading systems' ATO efforts and maintaining a security posture in compliance with FISMA, DHS 4300 Series, NIST, and DHS and Component Directives. The Senior ISSO will execute complete Risk Management Framework (RMF) activities for Authority to Operate (ATO) decisions and ensure all security documentation is kept up to date., The Senior ISSO will execute complete Risk Management Framework (RMF) activities for Authority to Operate (ATO) decisions including system categorization, security control selection and implementation, self-assessments, POA&M development, and continuous monitoring. This position requires developing and maintaining System Security Plans (SSPs) including control baselines, inheritance, Business Impact Analyses, implementation statements, technical and system descriptions, and hardware and software inventories. The Senior ISSO will create and maintain Configuration Management Plans, conduct Security Impact Analyses, approve Change Requests, and test configuration changes. Responsibilities include developing and testing Contingency Plans and Incident Response Plans to ensure business continuity, as well as conducting Risk Assessments, annual security assessments, and vulnerability assessments across assigned systems. The position involves developing security architecture designs, requirement traceability matrices, and authorization boundary diagrams while advising system owners and senior executives on all cybersecurity matters and developing remediation work plans for audit findings. The Senior ISSO will maintain Hardware and Software Inventory Lists and conduct FISMA Scorecard Analysis on a daily basis. Critical deliverables include preparing Security Test Plans 90 days prior to testing and Security Test Reports within 15 days after testing, generating Risk Assessment Reports within 0 to 15 days after analysis completion, and producing Weekly Activity Reports and Monthly Program Reports to track progress and compliance. The Senior ISSO will ensure proper access controls are implemented for both system access and physical access to data processing facilities, track and suggest technologies, processes, and practices designed to protect networks, devices, programs, and data from malicious attack, damage, or unauthorized access, and research and maintain proficiency in tools, techniques, countermeasures, and trends in computer and network vulnerabilities, data hiding, and network and device security and encryption. ## Related Videos - [Implementing continuous delivery in a data processing pipeline](https://www.wearedevelopers.com/videos/73-implementing-continuous-delivery-in-a-data-processing-pipeline) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [What makes Cybersecurity different for critical infrastructure?](https://www.wearedevelopers.com/videos/571-what-makes-cybersecurity-different-for-critical-infrastructure) - [One Pipeline, Three Regulator - SBOM Compliance for the Developer](https://www.wearedevelopers.com/videos/100169-one-pipeline-three-regulator-sbom-compliance-for-the-developer) - [Why and when should we consider Stream Processing frameworks in our solutions](https://www.wearedevelopers.com/videos/1085-why-and-when-should-we-consider-stream-processing-frameworks-in-our-solutions) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Best Paying Jobs in Technology](https://www.wearedevelopers.com/magazine/256-best-paying-jobs-in-technology) - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks)