> Markdown version of [/jobs/ext/1509979-4189-isso](https://www.wearedevelopers.com/jobs/ext/1509979-4189-isso). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # 4189 ISSO - **Company:** Procession Systems - **Location:** Tysons, VA, United States - **Contract:** Permanent contract - **Skills:** Cyber Security, Fault Tolerance, Identity and Access Management, Information Technology, Atlassian Tools, Vulnerability Analysis - **Published:** July 30, 2026 - **Apply:** https://www.clearancejobs.com/jobs/8434489/4189-isso ## About the Role * Will serve as the central point of contact for all security issues. * Is able to demonstrate the following skills and competencies and an ability to meet the following requirements: + Expert-level knowledge and experience ensuring the security of Identity Management or other Information Technology systems of similar size and complexity as the IDM. Experience with and enforcement of NIST and CMS security documentation listed in Attachment J-5 CMS Security and Privacy for Information and Information Security of this SOO, including but not limited to NIST 800-53, NIST 800-63, CMS Acceptable Risk Safeguards (ARS), CMS Risk Management Handbook (RMH) and CMS Federal Information Security Management Act (FISMA) Controls Tracking System (CFACTS) is preferred + Ability to provide required documentation for, and coordinate, all Authority to Operate (ATO) and related audits; + Ability to execute security scans and interpret the results, and then guide the appropriate response; + Ensure continuous monitoring for security breaches; + Ability to evaluate reports of results from all testing and monitoring activities and ensuring security threats are detected and remediated; + Ability to work directly with project development teams to enable successful project implementation applying the recommended security tools, technologies and techniques; + Ability to provide security expertise to project team engineers as needed; + Ability to work with CMS product organization to develop secure business requirements, develop the security architecture and integrate into CMS' longer term platform strategy; + Ability to develop and enhance the Security Architecture for highly scalable and fault-tolerant applications that adhere to expected standards and discipline from a security posture; + Experience with Agile tools, including but not limited to Jira and Confluence, is preferred. ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [The Future of Developer Experience with GenAI: Driving Engineering Excellence](https://www.wearedevelopers.com/videos/1107-the-future-of-developer-experience-with-genai-driving-engineering-excellence) - [System Resilience: Surviving the Software Storm](https://www.wearedevelopers.com/videos/874-system-resilience-surviving-the-software-storm) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [The AI-Fluent Team: A Playbook for Driving Enterprise AI Transformation](https://www.wearedevelopers.com/videos/100068-the-ai-fluent-team-a-playbook-for-driving-enterprise-ai-transformation) - [Fault Tolerance and Consistency at Scale: Harnessing the Power of Distributed SQL Databases](https://www.wearedevelopers.com/videos/1520-fault-tolerance-and-consistency-at-scale-harnessing-the-power-of-distributed-sql-databases) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again](https://www.wearedevelopers.com/magazine/751-how-we-built-a-worry-free-system-that-runs-for-10-years-and-what-we-d-do-again) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [Now is the time for industrialized software development](https://www.wearedevelopers.com/magazine/601-now-is-the-time-for-industrialized-software-development) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing)