> Markdown version of [/jobs/ext/1547266-information-system-security-officer-isso](https://www.wearedevelopers.com/jobs/ext/1547266-information-system-security-officer-isso). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Information System Security Officer (ISSO) - **Company:** Koniag Services, Inc. - **Location:** Chantilly, VA, United States - **Experience:** Experienced - **Contract:** Permanent contract - **Skills:** Xacta, User Authentication, Authentication Protocols, Cloud Computing, CompTIA Security+, Cyber Security, Information Systems, Multi-Factor Authentication, Federal Information Processing Standards (FIPS), Identity and Access Management, Information Security Management, Information Systems Security Architecture Professional, Microsoft Security Essentials, OAuth, OpenID, Public Key Infrastructure, Openid Connect, Azure Active Directory, Zero Trust Network Access, Security Assertion Markup Language (SAML), Security Information and Event Management, Single Sign-On, SARS Software Products, Okta, Cyberark, Information Technology, Nessus, Plan of Action and Milestones, Vulnerability Analysis - **Published:** July 5, 2026 - **Apply:** https://dejobs.org/x/x/0B3E98B0D77C4A93A270B46A939D16D2/job/ ## About the Role Koniag IT Systems (KITS), a Koniag Government Services company, is seeking an experienced ICAM ISSO (Identity, Credential, and Access Management Information System Security Officer) to support critical cybersecurity and identity management initiatives. The ideal candidate is a detail-oriented security professional with a strong background in ICAM frameworks, federal security compliance, and risk management. The successful candidate will bring a combination of technical expertise and strong communication skills to ensure the security and integrity of identity and access management systems. Ability to obtain or maintain the required security clearance to support our government customer., * Bachelor's degree in Cybersecurity, Information Technology, Computer Science, or a related field from an accredited college or university. * 5+ years of experience in information security, with at least 2 years of direct experience in an ISSO role or equivalent security capacity. * Demonstrated experience supporting the NIST Risk Management Framework (RMF) and ATO processes. * Experience working with ICAM technologies and frameworks, including identity proofing, PKI, MFA, and access management solutions. * Active or ability to obtain the required security clearance. Preferred: * Experience supporting federal government IT security programs. * Familiarity with federal ICAM guidance, including FICAM Roadmap, NIST SP 800-63, and NIST SP 800-53., * Exceptional communication skills in English - both written and oral - with the ability to communicate effectively with technical and non-technical stakeholders, including government leadership. * Strong working knowledge of the NIST Risk Management Framework (RMF), including NIST SP 800-53, NIST SP 800-37, and FIPS 199/200. * Proficiency in developing and maintaining ATO documentation, including SSPs, POA&Ms, Security Assessment Reports (SARs), and Interconnection Security Agreements (ISAs). * Knowledge of ICAM concepts including identity lifecycle management, credentialing, authentication protocols (MFA, PIV/CAC), privileged access management (PAM), and single sign-on (SSO). * Experience with continuous monitoring programs and security information and event management (SIEM) tools. * Ability to analyze and interpret vulnerability scan results (e.g., Nessus, Tenable) and work with system teams to remediate findings. * Familiarity with federal cybersecurity policies, directives, and mandates, including FISMA, HSPD-12, EO 14028, and OMB Memoranda. * Strong analytical and problem-solving skills with attention to detail in reviewing security controls and documentation. * Ability to manage multiple priorities and deliver quality work products within defined timelines. * Ability to obtain and maintain the required security clearance. Desired Skills and Competencies: * Experience working in a federal government IT or cybersecurity environment. * Knowledge of Zero Trust Architecture (ZTA) principles and implementation strategies, particularly as they relate to identity and access management. * Familiarity with Privileged Access Management (PAM) tools such as CyberArk, BeyondTrust, or similar platforms. * Experience with identity governance and administration (IGA) platforms. * Knowledge of SAML, OAuth2, OpenID Connect (OIDC), and other authentication and federation protocols. * Familiarity with cloud-based ICAM solutions and platforms (e.g., Azure Active Directory, Okta, AWS IAM). * One or more of the following certifications: * Certified Information Systems Security Professional (CISSP) * Certified Information Security Manager (CISM) * CompTIA Security+ CAP (Certified Authorization Professional) * GIAC Security Essentials (GSEC) * Experience with GRC (Governance, Risk, and Compliance) tools such as XACTA, eMASS, or Archer. ## Description The ICAM ISSO will serve as the primary security point of contact responsible for ensuring confidentiality, integrity, and availability of identity, credentials, and access management systems. This individual will work closely with system owners, program managers, and security teams to maintain system authorization, manage risks, and ensure compliance with federal security standards and ICAM policies. Principal responsibilities will include, but are not limited to: * Serve as the Information System Security Officer (ISSO) for one or more ICAM-related information systems, ensuring continuous monitoring and compliance with applicable federal security frameworks. * Develop, maintain, and update System Security Plans (SSPs), Plans of Action and Milestones (POA&Ms), and other Authorization to Operate (ATO) documentation in accordance with NIST and agency-specific requirements. * Support the Assessment and Authorization (A&A) process, including facilitating security assessments, coordinating with Security Control Assessors (SCAs), and preparing authorization packages. * Monitor and manage the security posture of ICAM systems, including identity proofing, credentialing, authentication, and access control solutions. * Review and analyze audit logs, security alerts, and system events to identify anomalies, potential threats, and compliance gaps. * Coordinate with system administrators, developers, and engineers to ensure security controls are properly implemented and functioning as intended. * Identify and document system vulnerabilities and risks, coordinating remediation efforts and tracking progress through the POA&M process. * Support the implementation and governance of ICAM policies, procedures, and standards in alignment with federal mandates such as FICAM, HSPD-12, EO 14028, and OMB Memoranda. * Participate in security incident response activities, including investigation, containment, and reporting of security events related to identity and access management systems. * Conduct periodic security reviews and assessments to ensure ongoing compliance with security requirements and ICAM best practices. * Provide security guidance and recommendations to program teams regarding identity management, privileged access management (PAM), multi-factor authentication (MFA), and zero trust principles. * Collaborate with cross-functional teams including IT, compliance, and operations staff to align security practices with organizational and mission objectives. * Prepare and deliver security briefings, reports, and documentation for government stakeholders and leadership. ## Related Videos - [Keeping applications secure by evolving OAuth 2.0 and OpenID Connect](https://www.wearedevelopers.com/videos/100152-keeping-applications-secure-by-evolving-oauth-2-0-and-openid-connect) - [Organizational Change Through The Power Of Why - DevSecOps Enablement](https://www.wearedevelopers.com/videos/478-organizational-change-through-the-power-of-why-devsecops-enablement) - [Delay the AI Overlords: How OAuth and OpenFGA Can Keep Your AI Agents from Going Rogue](https://www.wearedevelopers.com/videos/1637-delay-the-ai-overlords-how-oauth-and-openfga-can-keep-your-ai-agents-from-going-rogue) - [One Pipeline, Three Regulator - SBOM Compliance for the Developer](https://www.wearedevelopers.com/videos/100169-one-pipeline-three-regulator-sbom-compliance-for-the-developer) - [Advanced Cypress: custom assertions and tasks](https://www.wearedevelopers.com/videos/790-advanced-cypress-custom-assertions-and-tasks) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Building Security Champions](https://www.wearedevelopers.com/magazine/87-building-security-champions) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [The Overflow: Security and Privacy](https://www.wearedevelopers.com/magazine/715-the-overflow-security-and-privacy)