> Markdown version of [/jobs/ext/1380344-information-systems-security-officer](https://www.wearedevelopers.com/jobs/ext/1380344-information-systems-security-officer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Information Systems Security Officer - **Company:** JOSEPH & ASSOCIATES LLC - **Location:** McLean, VA, United States - **Experience:** Experienced - **Contract:** Temporary contract - **Skills:** Cyber Security, Systems Development Life Cycle, Software Vulnerability Management, Information Technology - **Published:** July 22, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=d3053c3a738b995a ## About the Role * Bachelors Degree in Information Security or related degree * Working knowledge of federal information security regulations, cybersecurity frameworks, and compliance requirements. * Experience supporting security and compliance initiatives within federal government or highly regulated IT environments. * Strong understanding of risk management frameworks, security authorization processes, and continuous monitoring programs. * Ability to communicate technical cybersecurity concepts clearly to both technical and non-technical audiences. * Excellent organizational, coordination, and technical documentation skills. * Minimum of three (3) to five (5) years of experience supporting cybersecurity, information assurance, or IT security programs. * Professional cybersecurity certification such as CISSP, CISM, CAP, Security+, or an equivalent credential is preferred. * Ability to obtain a DHS Public Trust ## Description This candidate will provide enterprise cybersecurity, risk management, and compliance support for IHSC Health IT systems and initiatives. This position serves as a key advisor in establishing and maintaining Authority to Operate (ATO) packages for multiple systems while helping ensure compliance with DHS, ICE, and federal cybersecurity requirements. The Information Systems Security Officer (ISSO) supports security governance, authorization activities, risk assessments, and continuous monitoring efforts across the Health IT environment. This role functions in an advisory and oversight capacity, providing guidance, coordination, and compliance validation without performing system administration, configuration, implementation, or operational control activities., * Assist in the planning, execution, and oversight of cybersecurity risk management activities, including system security planning and security control assessments. * Coordinate and support ATO efforts, including the development, review, tracking, and maintenance of authorization documentation and artifacts. * Monitor compliance activities and support vulnerability management, remediation tracking, and continuous monitoring initiatives. * Provide cybersecurity recommendations and validation support during system development, integration, modernization, and enhancement efforts. * Work closely with program managers, system owners, technical teams, and stakeholders to ensure security requirements are effectively addressed. * Support incident response coordination, security reporting, and risk communication activities. * Promote compliance with applicable federal cybersecurity laws, regulations, and frameworks, including NIST, FISMA, DHS, and ICE security requirements. * Maintain security-related documentation, including risk registers, Plans of Action and Milestones (POA&Ms), audit evidence, and assessment records. * Provide leadership with analysis of cybersecurity risks, emerging threats, and recommended mitigation strategies., All cybersecurity support provided under this position is performed in a compliance, advisory, oversight, and validation capacity. The ISSO works collaboratively with Government system owners, program managers, and authorized vendors to support security objectives while ensuring that responsibility for system administration, configuration, and operational control remains with designated Government personnel and authorized service providers. ## Related Videos - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [Enabling intelligent logistics automation: home-grown Industrial IoT platform at Austrian Post](https://www.wearedevelopers.com/videos/2018-enabling-intelligent-logistics-automation-home-grown-industrial-iot-platform-at-austrian-post) - [Navigating the AI Revolution in Software Development](https://www.wearedevelopers.com/videos/1266-navigating-the-ai-revolution-in-software-development) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Cyber Sleuth: Finding Hidden Connections in Cyber Data](https://www.wearedevelopers.com/videos/893-cyber-sleuth-finding-hidden-connections-in-cyber-data) - [Cyber Security: Small, and Large!](https://www.wearedevelopers.com/videos/259-cyber-security-small-and-large) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Best Paying Jobs in Technology](https://www.wearedevelopers.com/magazine/256-best-paying-jobs-in-technology) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again](https://www.wearedevelopers.com/magazine/751-how-we-built-a-worry-free-system-that-runs-for-10-years-and-what-we-d-do-again) - [7 Important Tips That Every Software Developer Should Know](https://www.wearedevelopers.com/magazine/101-7-important-tips-that-every-software-developer-should-know)