> Markdown version of [/jobs/ext/1315751-information-system-security-officer-isso-iii](https://www.wearedevelopers.com/jobs/ext/1315751-information-system-security-officer-isso-iii). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Information System Security Officer (ISSO) III - **Company:** Arlo Solutions Llc - **Location:** Philadelphia, PA, United States - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** Configuration Management, Cyber Security, Information Systems, Information Security Management, Software Vulnerability Management, Navsea, Information Technology, Plan of Action and Milestones, Vulnerability Analysis - **Published:** July 17, 2026 - **Apply:** https://www.dice.com/job-detail/b69dd30c-88a5-4a3b-8ae9-e9c23e097fca ## About the Role * Active Secret security clearance * Bachelor's degree in computer science, information technology, communications systems management, or equivalent STEM degree from an accredited college or university * Minimum 6 years of experience coordinating and implementing security changes, ensuring compliance with published policies, conducting cybersecurity vulnerability and threat analysis, and supporting cyber incident response * Current IAM-II certification (CAP, CASP+ CE, CISM, CISSP, GSLC, CCISO, or HCISPP) Desired Qualifications: * Experience with the DoD Information Assessment and Authorization (A&A) process * Familiarity with Risk Management Framework (RMF) implementation * Proficiency with eMASS, VRAM, and other DoD cybersecurity systems * Experience with NIST Special Publications and DoD/Navy cybersecurity directives * Experience with vulnerability management tools (ACAS, HBSS, etc.) * Knowledge of Security Technical Implementation Guides (STIGs) and Security Requirements Guides (SRGs) ## Description Position Description: The Information System Security Officer (ISSO) III will support Naval Surface Warfare Center Philadelphia Division (NSWCPD) as a contractor through Arlo Solutions, serving as a key cybersecurity professional for NSWCPD Code 104. This key personnel position is responsible for coordinating cybersecurity processes and activities for assigned systems, ensuring compliance with all applicable policies, and managing security controls implementation throughout the Risk Management Framework (RMF) lifecycle., Cybersecurity Compliance and Policy Implementation * Assist the Information System Security Managers (ISSM) in executing their duties and responsibilities * Ensure compliance with all NAVSEA, DON, and DoD cybersecurity policies * Ensure relevant cybersecurity policy and procedural documentation is current and accessible * Coordinate cybersecurity processes and activities for assigned systems * Report changes in system security posture to the ISSM Security Assessment and Authorization (A&A) Management * Maintain and report Assess Only (AO) and Assessment and Authorization (A&A) status to Program Managers, Information System Owners, and ISSMs * Provide oversight of Security Plans for assigned systems throughout their lifecycle * Manage and maintain Plan of Actions and Milestones (POA&M), tracking vulnerabilities through remediation * Assist with identification of security control baselines and applicable overlays * Coordinate the validation of security controls with Navy Qualified Validators (NQV) * Perform Risk Management Framework (RMF) Standard Operating Procedure (SOP) reviews * Adjudicate findings from Package Submitting Officer (PSO) System Security Management * Register and maintain systems in Enterprise Mission Assurance Support Service (eMASS) * Plan and coordinate security control testing during Risk Assessments and Annual Security Reviews * Maintain vulnerability data in Vulnerability Remediation Asset Manager (VRAM) * Participate in change control and configuration management processes * Ensure execution of Continuous Monitoring requirements as defined in system strategies * Review all data produced by Continuous Monitoring activities and update eMASS records as necessary * Correlate findings from non-RMF vulnerability assessments to RMF controls for holistic risk assessment Cybersecurity Analysis and Reporting * Perform analysis of logs, events, and reporting from various data collection tools * Assess impacts from observed risks and report via the Cybersecurity Program chain of command * Present data to management in a comprehensive and cohesive manner * Develop reports and produce procedural documentation as required * Evaluate system administrator, security engineer, and/or system owner proposed corrections ## Related Videos - [One Pipeline, Three Regulator - SBOM Compliance for the Developer](https://www.wearedevelopers.com/videos/100169-one-pipeline-three-regulator-sbom-compliance-for-the-developer) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [Microservices? Monoliths? An Annoying Discussion!](https://www.wearedevelopers.com/videos/970-microservices-monoliths-an-annoying-discussion) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Cyber Security: Small, and Large!](https://www.wearedevelopers.com/videos/259-cyber-security-small-and-large) - [Giving AI eyes: How to build a dashboard you can't see](https://www.wearedevelopers.com/videos/100193-giving-ai-eyes-how-to-build-a-dashboard-you-can-t-see) ## Related Articles - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Best Paying Jobs in Technology](https://www.wearedevelopers.com/magazine/256-best-paying-jobs-in-technology) - [How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again](https://www.wearedevelopers.com/magazine/751-how-we-built-a-worry-free-system-that-runs-for-10-years-and-what-we-d-do-again) - [The Overflow: Security and Privacy](https://www.wearedevelopers.com/magazine/715-the-overflow-security-and-privacy) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking)