> Markdown version of [/jobs/ext/1279935-information-systems-security-officer-isso](https://www.wearedevelopers.com/jobs/ext/1279935-information-systems-security-officer-isso). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Information Systems Security Officer (ISSO) - **Company:** VTG LLC - **Location:** Tysons, VA, United States - **Experience:** Expert - **Salary:** $140,000.0 - $200,000.0 - **Contract:** Permanent contract - **Skills:** Microsoft Windows, Amazon Web Services, Confluence, JIRA, Microsoft Azure, Bash Shell, CentOS, Cloud Computing, Configuration Management, Communications Protocols, Cyber Security, Information Systems, Elasticsearch, Networking Hardware, Intrusion Detection Systems, Python (Programming Language), Lightweight Directory Access Protocols (LDAP), Network Architecture, Citrix Systems, Nmap, Open Source Technology, Windows PowerShell, Red Hat Enterprise Linux, TCP/IP, Scripting, Computer Networking Systems, In-Plane Switching (IPS), Information Technology, Nessus, Nexpose, Splunk, Cisco, Vmware - **Published:** July 15, 2026 - **Apply:** https://www.clearancejobs.com/jobs/9030503/information-systems-security-officer-isso ## About the Role Members of the ISSO team support the assessment and authorization (A&A) process for information systems. The successful candidate will have requisite cyber security experience with methods and tools used to improve the security posture of critical systems such as identifying risks, vulnerabilities, anomalies, patching, auditing, automation, security hardening, best practices, and evaluating system changes. In addition, the candidate will collaborate with developers and engineers on projects to create a secure hybrid-cloud environment., * Strong verbal and written communication/cooperation within a team context * Supported control implementation assessment and reporting and monitoring processes using cyber security and assessment management systems * Understanding of perimeter controls (firewalls), access control mechanisms, and network architectures * Demonstrated essential understanding of methods for hardening operating systems (e.g., CentOS, RedHat, Windows) * Skilled with and/or demonstrated technical aptitude with vulnerability and risk assessment tools such as Elasticsearch or Splunk SIEMs, Rapid7 Nexpose, and IDS/IPS monitoring and alerting * Strong understanding of methodologies for researching and documenting software and hardware vulnerabilities * Experienced working closely with stakeholders, developers, and external teams, including customer security manages (ISSMs), organizational leadership, and key personnel * Applied experience with the customer's assessment and authorization tracking tools * Knowledgeable regarding Common Control Provider (CCP) requirements and methodology * Demonstrated knowledge and experience with networking topologies and hardware, including commonly used/referenced network devices, IDS and IPS, etc. * Applied experience with open-source and commercial tools and systems such as nmap, Nessus, Rapid7, Splunk, Nipper, Elasticsearch, Jira, Confluence, Cisco, VMware, Citrix, or Trellix, as well as GOTS tools used by the customer * Demonstrated experience with the design and implementation of defense-in-depth solutions * Skilled in cross-team collaboration and effective communication to fulfill specific authorization requirements * Demonstrated skill documenting processes and procedures in CONOPS and system security, contingency, configuration management and other plans * Demonstrated ability to facilitate customer concurrences required for risk-based decisions, especially those requiring waivers * Experience assisting the customer with decisions impacting the security posture and compliance of their systems and networks with requirement as documented in NIST 800-53 and its revisions * Extensive familiarity with communications protocols, such as TCP/IP, UDP, HTTP/S, SSH, LDAP, etc. * Demonstrated experience with security, monitoring and auditing cloud-based technologies, products and services, such as Amazon Web Services (AWS) or Microsoft Azure * Knowledge of the customer's organization, their network systems and infrastructure, processes and procedures, and request and approval tools * Ability to work within fast-paced customer environments DESIRED SKILLS * Experience in scripting/program languages such as Bash, PowerShell, or Python, * Bachelor's degree in Cybersecurity, IT, or other related technical discipline; or the equivalent combination of education, technical training, or work/military experience * Minimum eight (8) years applied experience or relevant degree plus five (5) years of Cybersecurity expertise with demonstrated ability to successfully shepherd IT projects of varying types through the authorization lifecycle ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [How Cisco embraced a DevOps culture within its network engineering team](https://www.wearedevelopers.com/videos/99-how-cisco-embraced-a-devops-culture-within-its-network-engineering-team) - [Collaboration Quantified: Lessons from Open Source Developer Networks](https://www.wearedevelopers.com/videos/1422-collaboration-quantified-lessons-from-open-source-developer-networks) - [DevSecOps culture](https://www.wearedevelopers.com/videos/783-devsecops-culture) - [Computer Vision from the Edge to the Cloud done easy](https://www.wearedevelopers.com/videos/263-computer-vision-from-the-edge-to-the-cloud-done-easy) - [Integrate your Cognitive Assistant with 3rd-party DBs and software](https://www.wearedevelopers.com/videos/249-integrate-your-cognitive-assistant-with-3rd-party-dbs-and-software) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing)