> Markdown version of [/jobs/ext/1501592-isso](https://www.wearedevelopers.com/jobs/ext/1501592-isso). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # ISSO - **Company:** PROVATOHR INC - **Location:** Reston, VA, United States - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** Cyber Security, Information Systems, Information Security Management, Software Vulnerability Management, Information Technology - **Published:** July 30, 2026 - **Apply:** https://www.careerjet.com/jobad/usd2d1d6badbb0456e856f672364e4dee1 ## About the Role * 5-8 years of experience in ISSO, ISSM, or equivalent systems security role * Active TS/SCI with Full Scope Polygraph * Completion of an IC ISSO training program (or equivalent) * Strong experience with NIST RMF and ATO lifecycle management * Experience developing and maintaining SSPs and security authorization packages * Working knowledge of ICD 503, ICD 704, ICD 705 * Experience operating in classified or SCIF environments * Strong understanding of NIST 800-53 security controls and assessment processes * Ability to work independently in a highly regulated environment * Strong documentation, communication, and audit readiness skills Preferred Experience * Prior experience supporting IC or DoD classified system environments * Experience with continuous monitoring (ConMon) and control automation * Background in cloud, hybrid, or on-prem classified infrastructure environments * Experience supporting security assessments, ATO renewals, and audit remediation * Familiarity with enterprise security and vulnerability management tooling Education Bachelor's degree in Cybersecurity, Information Systems, Computer Science, or related field preferred; equivalent experience considered. ## Description Seeking a Information System Security Officer (ISSO) to serve as the security authorization authority for classified information systems operating within a SCIF environment. This is a systems security function focused on authorization, control enforcement, and compliance oversight. This role is responsible for ensuring systems are authorized, continuously monitored, and compliant with the NIST Risk Management Framework (RMF) and applicable Intelligence Community Directives (ICD 503, ICD 704, ICD 705)., System Authorization & RMF Governance * Own the Authorization to Operate (ATO) lifecycle for classified systems * Develop and maintain System Security Plans (SSPs) and RMF documentation * Lead security assessments, authorization decisions, and reauthorization activities * Ensure alignment with NIST 800-53 control requirements Continuous Monitoring & Risk Management * Operate continuous monitoring (ConMon) programs for in-scope systems * Track and manage vulnerabilities, control gaps, and remediation activities * Ensure timely resolution of findings impacting system authorization status Security Governance & Control Independence * Enforce segregation of duties between system administration and security authorization * Validate that system changes are properly reviewed, approved, and documented * Maintain oversight of privileged access and security-relevant system modifications Engineering & Platform Collaboration * Partner with Agency infrastructure, platform, and application teams on secure system design and operation * Provide security requirements during system deployment and change activities * Support remediation of audit findings and control deficiencies, This role is focused exclusively on information system security authorization and compliance, not personnel security, facility security, or clearance management. Supports SCIF-based classified systems operating under IC customer requirements and requires sustained focus on security control integrity, authorization continuity, and compliance monitoring. Powered by JazzHR ## Related Videos - [DevSecOps culture](https://www.wearedevelopers.com/videos/783-devsecops-culture) - [Microservices? Monoliths? An Annoying Discussion!](https://www.wearedevelopers.com/videos/970-microservices-monoliths-an-annoying-discussion) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [Enabling intelligent logistics automation: home-grown Industrial IoT platform at Austrian Post](https://www.wearedevelopers.com/videos/2018-enabling-intelligent-logistics-automation-home-grown-industrial-iot-platform-at-austrian-post) - [One Pipeline, Three Regulator - SBOM Compliance for the Developer](https://www.wearedevelopers.com/videos/100169-one-pipeline-three-regulator-sbom-compliance-for-the-developer) - [Demystifying Crypto & Web3: A Technical Journey Through 15 Years of Innovation](https://www.wearedevelopers.com/videos/1516-demystifying-crypto-web3-a-technical-journey-through-15-years-of-innovation) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Now is the time for industrialized software development](https://www.wearedevelopers.com/magazine/601-now-is-the-time-for-industrialized-software-development) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [How should you format your IT resume?](https://www.wearedevelopers.com/magazine/68-how-should-you-format-your-it-resume)