> Markdown version of [/jobs/ext/1394290-information-systems-security-officer-isse](https://www.wearedevelopers.com/jobs/ext/1394290-information-systems-security-officer-isse). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Information Systems Security Officer ISSE - **Company:** NVS Limited Company - **Location:** Lorton, VA, United States (Remote available) - **Experience:** Expert - **Salary:** $160,000.0 - **Contract:** Permanent contract - **Skills:** Amazon Web Services, Microsoft Azure, Cloud Computing, Cyber Security, Computer Networks, Wireless Access Point, Virtual Reality, Firewalls (Computer Science), Information Technology, Data Pipelines - **Published:** July 23, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=0345a33b8f1d57e2 ## About the Role * Process Knowledge: Minimum of 2 years of active experience navigating formal DoD connection pipelines (e.g., DSAWG via the Sponsor Guidance System, or corresponding Service-level authorizing tracks). Must speak fluent "DISA/Title 10" governance. * Boundary Analysis Reflexes: Proven conceptual understanding of network traffic enforcement, data-diode behaviors, DMZ architecture, Next-Gen Firewalls (NGFW), or Cloud Access Points (CAP). Ability to read data flow diagrams and spot boundary flaws. * Risk Management Tradecraft: Proven experience authoring custom waivers, STIG tailoring, or Risk Acceptance Memorandums for complex, non-compliant, or mission-critical hardware/software baselines. * Communication: Exceptional verbal and written communication skills, with proven experience presenting complex risk profiles, technical trade-offs, and out-of-the-box mitigations directly to senior government leadership (GS-15/O-6 level). ## Description * Mission Enablement Risk Engineering: Apply a comprehensive risk tradecraft equation-balancing Threat, Vulnerability, Policy, Mitigation, and Residual Risk. Confidently recommend alternative paths to "yes" for senior leadership, including structured Risk Acceptance Memorandums (RAM), Exceptions to Policy (ETP), or transferring risk entirely via reasonable accommodation (e.g., telework routing). * Architectural & Enterprise CDS Gatekeeping: Serve as the principal technical reviewer for DTRA organizations onboarding onto pre-accredited Enterprise CDS (ECDS) and Raise the Bar (RTB) compliant Cloud CDS providers (e.g., AWS/Azure CDS). Evaluate customer design artifacts to ensure data pipelines "hit the mark" before board submission. * Dynamic Information Technology Evaluation: Act as the primary advisor for evaluating non-standard, emerging technologies (e.g., virtual reality training platforms, mobile medical devices, standalone scanning configurations) against rigid DoD guidelines. Systematically dissect hardware/software interfaces to isolate threat vectors and design creative compensating controls. * Board Representation & Intermediary Advocacy: Act as the formal technical advocate and bridge between DTRA development teams, external cloud providers (AWS/DISA), and formal authorizing panels. Represent the CDSE at Cross Domain Technical Advisory Board meetings to defend risk profiles and secure Approvals to Connect (ATC). * Documentation Quality Assurance: Review, edit, and validate customer-authored Cross Domain packages to guarantee strict compliance with NSA "Raise the Bar" (RTB) standards before formal registry submission into the Sponsor Guidance System (SGS). ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Why and when should we consider Stream Processing frameworks in our solutions](https://www.wearedevelopers.com/videos/1085-why-and-when-should-we-consider-stream-processing-frameworks-in-our-solutions) - [Developer Tools for Microsoft Azure](https://www.wearedevelopers.com/videos/450-developer-tools-for-microsoft-azure) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [Python-Based Data Streaming Pipelines Within Minutes](https://www.wearedevelopers.com/videos/1233-python-based-data-streaming-pipelines-within-minutes) - [Develop enterprise-ready applications for Microsoft Teams with Azure resources on modern web technologies](https://www.wearedevelopers.com/videos/187-develop-enterprise-ready-applications-for-microsoft-teams-with-azure-resources-on-modern-web-technologies) ## Related Articles - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again](https://www.wearedevelopers.com/magazine/751-how-we-built-a-worry-free-system-that-runs-for-10-years-and-what-we-d-do-again) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities)