> Markdown version of [/jobs/ext/135697-information-systems-security-officer](https://www.wearedevelopers.com/jobs/ext/135697-information-systems-security-officer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Information Systems Security Officer - **Company:** Take2 Consulting - **Location:** Germantown, MD, United States - **Experience:** Experienced - **Contract:** Permanent contract - **Skills:** Cyber Security, Federal Information Processing Standards (FIPS), Information Security Management - **Published:** May 22, 2026 - **Apply:** https://www.clearancejobs.com/jobs/8931343/information-systems-security-officer ## About the Role Minimum of 3 years' experience as an ISSO or in a closely related RMF-focused cybersecurity compliance role. Hands-on experience supporting RMF lifecycle activities, security monitoring, and continuous authorization processes. Proficiency with security frameworks and standards such as NIST SP 800-37, 800-53, 800-60, FIPS 199, and CNSSI 1253. Strong capability to interpret data from security tools and apply NIST guidelines accurately. Experience using eGRC platforms (e.g., Archer) for documentation, risk tracking, and POA&M management. Active Top Secret (TS) clearance is required to ensure access to sensitive information. Core Skills: Risk assessment, system categorization, and control implementation. Detailed and clear documentation of security controls and findings. Excellent written and verbal communication skills, with the ability to explain technical issues to diverse audiences. Proven ability to support audit activities and manage compliance initiatives. Why Join Us? ## Description Are you a dedicated cybersecurity professional with a passion for safeguarding organizational information assets? We are seeking an experienced Information System Security Officer (ISSO) to lead our cybersecurity compliance and risk management initiatives, ensuring the security posture aligns with federal standards and frameworks., Lead and support the entire Risk Management Framework (RMF) lifecycle, including system categorization, control selection, and authorization processes. Conduct continuous cybersecurity monitoring and assessments, ensuring compliance with applicable standards. Collect, analyze, and interpret security evidence to support system authorization and security controls validation. Prepare clear, comprehensive documentation including System Security Plans (SSPs), control implementation, and risk assessment findings. Facilitate internal and external audits, providing technical expertise and necessary documentation to auditors. Communicate risk posture, remediation strategies, and security requirements effectively to both technical teams and non-technical stakeholders. Collaborate with various teams to implement security controls and coordinate incident response and mitigation activities. ## Related Videos - [Don't Be A Naive Developer: How To Avoid Basic Cybersecurity Mistakes](https://www.wearedevelopers.com/videos/498-don-t-be-a-naive-developer-how-to-avoid-basic-cybersecurity-mistakes) - [OLAP for AI Applications and why you should care](https://www.wearedevelopers.com/videos/100212-olap-for-ai-applications-and-why-you-should-care) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [One Pipeline, Three Regulator - SBOM Compliance for the Developer](https://www.wearedevelopers.com/videos/100169-one-pipeline-three-regulator-sbom-compliance-for-the-developer) - [You can’t hack what you can’t see](https://www.wearedevelopers.com/videos/41-you-can-t-hack-what-you-can-t-see) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [The Overflow: Security and Privacy](https://www.wearedevelopers.com/magazine/715-the-overflow-security-and-privacy) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Best Paying Jobs in Technology](https://www.wearedevelopers.com/magazine/256-best-paying-jobs-in-technology)