> Markdown version of [/jobs/ext/1368839-isso](https://www.wearedevelopers.com/jobs/ext/1368839-isso). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # ISSO - **Company:** Kforce Inc. - **Location:** Huntsville, AL, United States - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** Xacta, Cyber Security, Information Systems, Disaster Recovery, Software Vulnerability Management, Information Technology, Nessus, RSA Archer Platform, Plan of Action and Milestones, Vulnerability Analysis - **Published:** July 21, 2026 - **Apply:** https://www.clearancejobs.com/jobs/9045163/isso ## About the Role Bachelor's Degree in Information Assurance, Cybersecurity, Information Technology, Computer Science, Engineering, or a related field 10+ years of cybersecurity, information assurance, ISSO, RMF, or compliance experience Experience serving as an ISSO, Information Assurance professional, or cybersecurity compliance lead Strong knowledge of Risk Management Framework (RMF) Experience supporting Authority to Operate (ATO) activities and security authorization processes Experience developing and maintaining SSPs, POA&Ms, security assessment documentation, and compliance artifacts Knowledge of NIST 800-53 security controls and federal cybersecurity requirements Experience conducting vulnerability assessments and coordinating remediation efforts Familiarity with Security Test & Evaluation (ST&E) activities Strong understanding of cybersecurity governance, risk management, and compliance principles Experience supporting continuous monitoring programs and audit readiness initiatives Excellent written, verbal, organizational, and interpersonal communication skills Ability to work independently and provide guidance to technical and non-technical stakeholders Preferred Qualifications Experience using Xacta or similar GRC platforms Experience using eMASS or other federal compliance management systems Experience supporting DoD, Intelligence Community, or other federal environments Experience supporting classified systems and secure operational environments Experience with vulnerability management tools and compliance reporting solutions Experience performing security control assessments and risk analysis activities Familiarity with incident response, auditing, and cybersecurity operations Knowledge of DISA STIGs, NIST standards, and federal security policies, Strong cybersecurity leadership within complex environments Ability to balance security requirements with mission objectives Experience guiding systems through accreditation and compliance processes Strong documentation and communication skills Ability to collaborate effectively with system owners, engineers, security personnel, and executive leadership Commitment to maintaining secure, compliant, and resilient information systems supporting critical operations ## Description We are seeking a Senior Information Systems Security Officer (ISSO) to support mission-critical federal and defense systems within a highly secure environment. This individual will serve as the principal cybersecurity advisor to system owners, business stakeholders, and information security leadership, ensuring systems maintain compliance with federal cybersecurity requirements while supporting operational mission objectives. The ideal candidate has extensive experience supporting Risk Management Framework (RMF) activities, Authorization to Operate (ATO) processes, cybersecurity compliance efforts, vulnerability management, and continuous monitoring programs within complex government environments., Serve as the primary cybersecurity advisor to the Information System Owner (ISO), Business Process Owner, ISSM, and cybersecurity leadership Ensure implementation, maintenance, and effectiveness of security controls throughout the system lifecycle Apply RMF principles and oversee compliance activities supporting authorization and accreditation requirements Guide systems through the Authority to Operate (ATO) lifecycle, including documentation development, review, submission, and maintenance Develop, review, maintain, and update cybersecurity documentation including: System Security Plans (SSPs) Contingency Plans Security Assessment documentation Policies and procedures Supporting authorization artifacts Create, update, and manage Plans of Action & Milestones (POA&Ms) based on vulnerability and compliance findings Conduct security control reviews and validate compliance with applicable federal and organizational requirements Perform and support network self-inspections, security reviews, and compliance assessments Track remediation activities and coordinate corrective actions for identified vulnerabilities and deficiencies Monitor security posture through continuous monitoring activities and vulnerability management processes Coordinate with engineers, system administrators, developers, and security teams to ensure security requirements are properly implemented Evaluate cybersecurity risks and provide recommendations to reduce operational and security exposure Prepare compliance reports, risk assessments, status updates, and executive-level briefings Support audits, inspections, security assessments, and external reviews Provide guidance regarding security architecture, operational security requirements, and system hardening activities Assist with developing and maintaining contingency planning and disaster recovery documentation, Xacta eMASS NIST 800-53 SSP Development POA&M Management Vulnerability Management ACAS Nessus STIG Compliance Security Assessments Continuous Monitoring Risk Analysis Audit Readiness Information Assurance Cybersecurity Governance Compliance Management ## Related Videos - [One Pipeline, Three Regulator - SBOM Compliance for the Developer](https://www.wearedevelopers.com/videos/100169-one-pipeline-three-regulator-sbom-compliance-for-the-developer) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [Organizational Change Through The Power Of Why - DevSecOps Enablement](https://www.wearedevelopers.com/videos/478-organizational-change-through-the-power-of-why-devsecops-enablement) - [Cyber Security: Small, and Large!](https://www.wearedevelopers.com/videos/259-cyber-security-small-and-large) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Less Is More: How Lagom and Agile Can Create Harmonious Workflows](https://www.wearedevelopers.com/videos/1993-less-is-more-how-lagom-and-agile-can-create-harmonious-workflows) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again](https://www.wearedevelopers.com/magazine/751-how-we-built-a-worry-free-system-that-runs-for-10-years-and-what-we-d-do-again) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [Now is the time for industrialized software development](https://www.wearedevelopers.com/magazine/601-now-is-the-time-for-industrialized-software-development)