> Markdown version of [/jobs/ext/1323611-information-system-security-officer-isso-hybrid](https://www.wearedevelopers.com/jobs/ext/1323611-information-system-security-officer-isso-hybrid). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Information System Security Officer (ISSO) - Hybrid - **Company:** Coalfire Federal - **Location:** Washington, DC, United States - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** Cloud Computing, Configuration Management, Information Systems, Desktop Computing, Information Security Management, Cloud Services, Mobile Security, Enterprise Data Management, Information Technology, Network Server, Plan of Action and Milestones - **Published:** July 17, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=6ba983420c8aa437 ## About the Role * Strong working knowledge and familiarity with NIST publications and privacy frameworks. * Demonstrated understanding of cloud service models, hybrid models, financial applications, and mobile security technologies and tools. * Demonstrated experience supporting an industry risk management tool executing A&A activities., Completed Bachelor's degree from an accredited university in an IT related field. Clearance / Suitability Ability to obtain a clearance or a Public Trust is preferred, however all clearance levels and non-cleared applicants will also be considered. Certifications One or more of the following certifications: CRISC, CISM, or CISSP is strongly preferred Years of Experience At minimum 5+ years of hands-on work experience with ISSO duties; performing systems security assessments, preparing system security documentation, and/or performing security upgrades for live networks, desktop systems, servers, and enterprise data bases leading to successful security authorization of such systems. Why you'll want to join us ## Description As an ISSO you'll be supporting as the principal advisor to the information system owner (SO), ISSM, CISO on all matters (technical and otherwise) involving the security of assigned information systems (on prem, vendor, and cloud-based). What you'll do: * Maintain detailed knowledge and expertise required to manage the security aspects of assigned information systems. * Ensure that the appropriate operational cybersecurity posture is maintained for assigned systems to provide confidentiality, integrity, and availability of information systems. * For each system assigned to an ISSO, the ISSO will be responsible to complete and keep updated security documentations, such as SIA, SSP, POA&M, Configuration Management Plan, Vulnerability Reports, etc. * Participate in planning and management of all phases of the Risk Management Framework (RMF) Security Assessment and Authorization (SAA) process. * Advise system owners on all matters, technical and otherwise, involving the security of assigned IT systems. * In coordination with SO team, develop standard operating procedures in accordance with security control requirements. * Perform continuous monitoring of implemented security controls to ensure that they are implemented correctly, operating as intended and producing the desired outcome with respect to meeting the cybersecurity requirements for assigned IT systems. Conduct continuous monitoring activities, to include: + Maintenance of current ATO + Conducting periodic system self-assessments + Conducting periodic scans + Conducting log reviews + Ensuring proper sanitization of media prior to disposal * Work with technical teams to mitigate security control deficiencies and scan vulnerabilities for assigned IT systems. * Assess the cybersecurity impact of changes to assigned IT systems and document findings in a security impact analysis (SIA) report. * Conduct self-assessments of security controls, identify weaknesses and track remediation activities in POA&M. * Manage the plan of action and milestone (POA&M) process for designated IT systems to provide timely detection, identification and alerting of non-compliance issues. In coordination with System Owner staff, create POA&Ms or remediation plans for vulnerabilities identified during risk assessments, audits, inspections, etc. * Provide the required system access, information, and documentation to security assessment and audit teams. * Participate in security assessments and audits for assigned systems and facilitate evidence and/or data collection for data requests related to assigned systems. * Complete required A&A activities on assigned IT systems. * Brief senior management and ISSM on the security status of assigned authorization boundaries. Perform other duties as assigned. ## Related Videos - [Leverage Cloud Computing Benefits with Serverless Multi-Cloud ML ](https://www.wearedevelopers.com/videos/78-leverage-cloud-computing-benefits-with-serverless-multi-cloud-ml) - [Green Cloud Computing](https://www.wearedevelopers.com/videos/592-green-cloud-computing) - [DevSecOps culture](https://www.wearedevelopers.com/videos/783-devsecops-culture) - [Kubernetes Security - Challenge and Opportunity](https://www.wearedevelopers.com/videos/412-kubernetes-security-challenge-and-opportunity) - [Cloud-nativeApplications- What’s the buzz about](https://www.wearedevelopers.com/videos/55-cloud-nativeapplications-what-s-the-buzz-about) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) ## Related Articles - [How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again](https://www.wearedevelopers.com/magazine/751-how-we-built-a-worry-free-system-that-runs-for-10-years-and-what-we-d-do-again) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Best Paying Jobs in Technology](https://www.wearedevelopers.com/magazine/256-best-paying-jobs-in-technology) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [The Overflow: Security and Privacy](https://www.wearedevelopers.com/magazine/715-the-overflow-security-and-privacy)