> Markdown version of [/jobs/ext/1471943-information-systems-security-officer](https://www.wearedevelopers.com/jobs/ext/1471943-information-systems-security-officer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Information Systems Security Officer - **Company:** Legato, LLC - **Location:** Howard County, MD, United States - **Experience:** Expert - **Salary:** $160,000.0 - $180,000.0 - **Contract:** Permanent contract - **Skills:** Xacta, Configuration Management, Communications Protocols, Cyber Security, Information Systems, Firmware, Security Content Automation Protocol, Software Requirements Analysis, Software Security, Information Technology, Nessus, Vulnerability Analysis - **Published:** July 28, 2026 - **Apply:** https://www.dice.com/job-detail/b870ff2c-6dbc-4e68-aa01-dfe23f2996fe ## About the Role * Ten (10) years of experience as an Information Systems Security Officer (ISSO) supporting programs or contracts of similar scope, type, and complexity. * Experience supporting the National Institute of Standards and Technology (NIST) Risk Management Framework (RMF) and security authorization processes. * Experience preparing and maintaining System Security Plans (SSPs), Risk Assessment Reports (RARs), Assessment and Authorization (A&A) packages, and System Requirements Traceability Matrices (SRTMs). * Experience performing vulnerability assessments, risk analysis, continuous monitoring activities, and configuration management of security-related hardware, software, and firmware. * Experience evaluating the security impact of system changes and maintaining compliance with information assurance policies, standards, and procedures. * Experience supporting the day-to-day security operations of multiple information systems, typically managing a portfolio of approximately 10-15 System Security Plans (SSPs). * Strong written and verbal communication skills with the ability to collaborate effectively with system owners, engineers, cybersecurity professionals, and government stakeholders. * Bachelor's degree in Computer Science or a related technical discipline from an accredited college or university. Four (4) additional years of ISSO experience may be substituted for a bachelor's degree. * Current IAT Level II certification or higher. Desired (not required): * Experience with eMASS, Xacta, or similar RMF management tools. * Experience supporting classified systems * Knowledge of Security Technical Implementation Guides (STIGs), Security Content Automation Protocol (SCAP), and vulnerability scanning tools such as ACAS, Nessus, or Tenable Security Center. * Knowledge of current security tools, hardware and software security implementation, communication protocols, and encryption technologies. * Experience supporting security control assessments, audits, and continuous monitoring activities. ## Description Legato, LLC recruiters () would love to speak with you regarding the following position: Information Systems Security Officer (ISSO) in Hanover, MD. Security Clearance Required: TS/SCI w/ Polygraph Salary Range: $160,000-$180,000, depending on experience. What You Will Do: The Information Systems Security Officer (ISSO) will support the security posture of mission-critical information systems by implementing, maintaining, and enforcing information assurance policies, standards, and procedures throughout the system lifecycle. This role is responsible for ensuring systems remain compliant with security requirements while supporting the Risk Management Framework (RMF) authorization process for classified environments. The ISSO will maintain the day-to-day operational security of assigned information systems, supporting approximately 10-15 System Security Plans (SSPs). They will work closely with system owners, engineers, ISSMs, and cybersecurity teams to ensure security controls are implemented, documented, and maintained in accordance with customer and regulatory requirements. The successful candidate will prepare, review, and maintain RMF documentation, including System Security Plans (SSPs), Risk Assessment Reports (RARs), Security Assessment and Authorization (A&A) packages, and System Requirements Traceability Matrices (SRTMs). They will support security authorization activities in accordance with the National Institute of Standards and Technology (NIST) Risk Management Framework (RMF) and assist with vulnerability assessments, risk analysis, and continuous monitoring activities. The ISSO will evaluate security solutions to ensure they meet security requirements for processing classified information, support configuration management activities for security-related hardware, software, and firmware, and assess the security impact of system changes. They will also coordinate with stakeholders to implement information system security policies, maintain compliance, and support ongoing cybersecurity operations. ## Related Videos - [Playing Pong on a shoulder press machine](https://www.wearedevelopers.com/videos/100140-playing-pong-on-a-shoulder-press-machine) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [One Pipeline, Three Regulator - SBOM Compliance for the Developer](https://www.wearedevelopers.com/videos/100169-one-pipeline-three-regulator-sbom-compliance-for-the-developer) - [Agent Smith Gets Hardware: Autonomous IoT Hacking From Debug Port to Cloud API](https://www.wearedevelopers.com/videos/100258-agent-smith-gets-hardware-autonomous-iot-hacking-from-debug-port-to-cloud-api) - [DevSecOps culture](https://www.wearedevelopers.com/videos/783-devsecops-culture) - [When Agents Meet Legacy: Never Change a Running System](https://www.wearedevelopers.com/videos/100320-when-agents-meet-legacy-never-change-a-running-system) ## Related Articles - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [The Overflow: Security and Privacy](https://www.wearedevelopers.com/magazine/715-the-overflow-security-and-privacy) - [Best Paying Jobs in Technology](https://www.wearedevelopers.com/magazine/256-best-paying-jobs-in-technology)