> Markdown version of [/jobs/ext/1310018-information-system-security-officer-isso-ts-sci](https://www.wearedevelopers.com/jobs/ext/1310018-information-system-security-officer-isso-ts-sci). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Information System Security Officer (ISSO) - TS/SCI - **Company:** Strategic Business Systems, Inc. - **Location:** Herndon, VA, United States (Remote available) - **Contract:** Permanent contract - **Skills:** Xacta, Amazon Web Services, Cloud Computing Security, Cyber Security, Identity and Access Management, Information Security Management, Zero Trust Network Access, Software Vulnerability Management, Cloud Platform System, RSA Archer Platform, Opsworks - **Published:** July 17, 2026 - **Apply:** https://www.clearancejobs.com/jobs/9036641/information-system-security-officer-isso-tssci ## About the Role * 5+ years of Information Assurance, Cybersecurity, or Information System Security experience. * Minimum 2 years supporting RMF and NIST SP 800-53. * Minimum 1 year supporting AWS cloud security environments. * Experience creating and maintaining complete ATO packages. * Experience with SSPs, POA&Ms, Continuous Monitoring, and Control Implementation Statements. * Working knowledge of AWS security services. * Strong understanding of vulnerability management and security compliance. * Experience with eMASS, Xacta, Keyhole, or equivalent GRC platforms. * Experience supporting DoD IL2/IL4/Secret/TS cloud environments. * Familiarity with AWS Landing Zone Accelerator (LZA). * Experience implementing Zero Trust security principles. * DoD 8570/8140 IAM Level II or IAT Level III certification. * One or more of the following: + CISSP + CISM + CAP + CASP+ * Excellent communication and documentation skills. * Strong analytical and troubleshooting abilities. * Ability to work independently in classified environments. * Experience supporting highly regulated Federal or Intelligence Community customers. ## Description SBS is seeking experienced to support Amazon Web Services (AWS) Federal customers operating within highly secure, classified cloud environments. This position is responsible for leading Risk Management Framework (RMF) activities, maintaining Authorization to Operate (ATO) packages, implementing continuous monitoring strategies, and ensuring compliance with NIST and DoD cybersecurity requirements across multiple security domains. The ideal candidate possesses a strong background in RMF, cloud security, and AWS-native security services while partnering with engineering teams to maintain secure cloud environments supporting Department of Defense and Intelligence Community missions. * Develop, maintain, and update RMF documentation supporting IATT and ATO packages. * Author and maintain: + System Security Plans (SSPs) + Security Control Family Plans (AC, IA, SC, SI, etc.) + POA&Ms + Control implementation statements + Continuous Monitoring documentation * Support the full RMF lifecycle in accordance with DoDI 8510.01 and NIST SP 800-53 Rev. 5. * Monitor security posture across AWS environments supporting IL2, IL4, Secret, and TS workloads. * Assess cloud environments against NIST 800-53 security controls. * Configure and monitor AWS security services including: + GuardDuty + Security Hub + AWS Config + IAM + AWS Organizations / SCPs * Assist engineering teams in implementing secure cloud architectures. * Review vulnerability findings and support remediation efforts. * Maintain POA&Ms and continuous monitoring activities. * Work with third-party security tools including: + Palo Alto + ACAS + Elastic * Ensure compliance with customer cybersecurity policies and accreditation requirements. * Partner with cloud engineers, ISSOs, ISSEs, architects, and customer security teams. * Participate in security assessments and authorization reviews. * Provide guidance during audits and compliance activities. * Support ongoing improvements to cloud security posture and automation. ## Related Videos - [DevSecOps culture](https://www.wearedevelopers.com/videos/783-devsecops-culture) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [One Pipeline, Three Regulator - SBOM Compliance for the Developer](https://www.wearedevelopers.com/videos/100169-one-pipeline-three-regulator-sbom-compliance-for-the-developer) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Cyber Security: Small, and Large!](https://www.wearedevelopers.com/videos/259-cyber-security-small-and-large) - [Agile work at CARIAD – Creating a customer web application for controlling the vehicle ](https://www.wearedevelopers.com/videos/200-agile-work-at-cariad-creating-a-customer-web-application-for-controlling-the-vehicle) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [The Overflow: Security and Privacy](https://www.wearedevelopers.com/magazine/715-the-overflow-security-and-privacy) - [Best Paying Jobs in Technology](https://www.wearedevelopers.com/magazine/256-best-paying-jobs-in-technology) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking)