> Markdown version of [/jobs/ext/1263565-100-remote-dmv-area-isso-cybersecurity-analyst](https://www.wearedevelopers.com/jobs/ext/1263565-100-remote-dmv-area-isso-cybersecurity-analyst). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # (100% Remote / DMV Area ) ISSO / Cybersecurity Analyst - **Company:** ASGN Incorporated - **Location:** Washington, DC, United States (Remote available) - **Experience:** Expert - **Salary:** $139,360.0 - $149,760.0 - **Contract:** Temporary to permanent - **Skills:** Cloud Computing Security, Configuration Management, Cyber Security, Information Systems, Requirements Traceability, Software Asset Management, Information Technology, Vulnerability Analysis - **Published:** July 14, 2026 - **Apply:** https://www.clearancejobs.com/jobs/9027133/100-remote-dmv-area-isso-cybersecurity-analyst ## About the Role Top Secret Clearance (Eligible) - Security+CE - 7+ Years of Overall/Combined Experience in Cyber/IT Security/ISSO/ISSE/ISSM or Similar - Experience executing the RMF lifecycle and ATO activities - Experience conducting security control assessments, vulnerability assessments, and Security Impact Analyses - Experience developing security documentation including SSPs, POA&Ms, and Contingency Plans ## Description The ISSO will execute Risk Management Framework activities for ATO decisions and ensure systems meet compliance requirements while ensuring confidentiality, integrity, and availability of Information Systems through proper security control implementation. - This position requires implementing security controls and conducting system assessments to identify vulnerabilities and gaps, as well as developing and maintaining System Security Plans, Configuration Management Plans, and Contingency Plans. - ISSO will conduct Security Impact Analyses and test configuration changes pre- and post-deployment, support continuous monitoring of IT systems, and develop and track POA&Ms for identified vulnerabilities. - Responsibilities include developing security requirement traceability matrices and managing hardware and software inventory lists, supporting cloud security initiatives, and participating in Change Advisory Board (CAB) reviews. - The position involves conducting technical vulnerability assessments, providing audit support documentation, and responding to cybersecurity data calls with timely information to leadership. Critical deliverables include preparing Security Test Plans 90 days prior to testing and Security Test Reports within 15 days after testing, generating POA&Ms within 0 to 15 days after vulnerability identification, and updating System Security Plans, Configuration Management Plans, and Contingency Plans annually or when changes occur. - The ISSO will conduct Security Impact Analysis Reports within 5 business days after change notification, analyze Risk Assessment Reports and FISMA Scorecard Analysis on a daily basis, and produce Weekly Activity Reports and Monthly Program Reports. - This position requires following the Information Systems Security Officer (ISSO) Guide when developing, updating, or reviewing required security artifacts and tracking and suggesting technologies, processes, and practices designed to protect networks, devices, programs, and data from malicious attack, damage, or unauthorized access. PLEASE NOTE: Candidates must be able to obtain and/or maintain a Department of Defense Public Trust Security Clearance as a condition and continuation of employment* ## Related Videos - [One Pipeline, Three Regulator - SBOM Compliance for the Developer](https://www.wearedevelopers.com/videos/100169-one-pipeline-three-regulator-sbom-compliance-for-the-developer) - [Enabling intelligent logistics automation: home-grown Industrial IoT platform at Austrian Post](https://www.wearedevelopers.com/videos/2018-enabling-intelligent-logistics-automation-home-grown-industrial-iot-platform-at-austrian-post) - [Microservices? Monoliths? An Annoying Discussion!](https://www.wearedevelopers.com/videos/970-microservices-monoliths-an-annoying-discussion) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [Demystifying Crypto & Web3: A Technical Journey Through 15 Years of Innovation](https://www.wearedevelopers.com/videos/1516-demystifying-crypto-web3-a-technical-journey-through-15-years-of-innovation) - [Cyber Security: Small, and Large!](https://www.wearedevelopers.com/videos/259-cyber-security-small-and-large) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again](https://www.wearedevelopers.com/magazine/751-how-we-built-a-worry-free-system-that-runs-for-10-years-and-what-we-d-do-again) - [The Overflow: Security and Privacy](https://www.wearedevelopers.com/magazine/715-the-overflow-security-and-privacy) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking)