> Markdown version of [/jobs/ext/1925788-information-system-security-officer](https://www.wearedevelopers.com/jobs/ext/1925788-information-system-security-officer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Information System Security Officer - **Company:** XPECT Solutions Inc. - **Location:** Arlington, VA, United States - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** Agile Methodology, Amazon Web Services, Audit Trail, Microsoft Azure, Cloud Computing Security, Cyber Security, Information Systems, Information Security Management, Zero Trust Network Access, Software Vulnerability Management, Webinspect, Information Security Management System, Google Cloud, Containerization, Information Technology, Patch Management, Nessus, Devsecops, Qualys, Plan of Action and Milestones, Vulnerability Analysis - **Published:** August 5, 2026 - **Apply:** https://www.clearancejobs.com/jobs/9075298/information-system-security-officer ## About the Role * Must Be Able to Obtain Public Trust Level 6C * Bachelor's Degree in Physics, Mathematics, Information Technology, Computer Science, Business, or related discipline * Minimum of 5 years of professional experience in cybersecurity, information assurance, or related technical roles. * Demonstrable expertise in NIST RMF, NIST 800-53, NIST 800-37, and DHS 4300A requirements * Knowledge and experience of information security practices within federal and/or state government environments. * Excellent written and oral skills * Ability to work on-site in Crystal City, Virginia,1 day per week Preferred Additional Skills and Qualifications: * CISSP, CCSK, GCIH, or other advanced cybersecurity certification * Experience with FedRAMP, FISMA, or other federal compliance frameworks * Hands-on experience with vulnerability assessment tools (Nessus, WebInspect, Qualys, etc.) * Experience in Zero Trust architecture design and implementation * Knowledge of cloud security (AWS, Azure, GCP) and containerized environments * Experience working with Security Operations Centers (SOCs) and incident response teams * Demonstrated success working with Agile/DevSecOps practices and sprint-based development environments ## Description XPECT Solutions seeks an experienced Information Systems Security Officer (ISSO) to lead compliance and security operations for government information systems. In this role, you will navigate the full NIST Risk Management Framework, ensure adherence to NIST 800-53 controls and DHS 4300A requirements, and oversee continuous authorization and monitoring activities. You will partner with Government Security Assurance Management teams, IT Program Managers, and security operations centers to protect critical systems and maintain compliance posture. This role demands deep technical security expertise, regulatory knowledge, and the ability to communicate complex security concepts to diverse stakeholders. Core Responsibilties (to include but not limited to): Risk Management Framework & Authorization * Participate in all phases of the NIST 800-37 Risk Management Framework (Prepare, Categorize, Select, Implement, Assess, Authorize, Monitor) * Ensure systems comply with NIST 800-53 security controls and DHS 4300A requirements * Prepare comprehensive security documentation and collect security artifacts in advance of assessments * Conduct self-assessments and support Security Control Assessment activities Security Compliance & Remediation * Evaluate effectiveness of proposed solutions to audit findings, Security Control Assessments, and other security weaknesses * Perform root cause analysis of audit findings and security incidents * Develop requirements for security control remediation activities * Review vulnerability scans from security assessment tools (Nessus, WebInspect, DbProtect, etc.) * Develop security control implementation statements and review supporting procedures and work instructions Security Documentation & Planning * Review and update the System Security Plan (SSP) and supporting security documentation * Work with Government Security Assurance Management (SAM) on Plan of Action and Milestones (POA&M) closure requests * Prepare status reports on security control accuracy and completeness * Interpret security principles and requirements for remediation plans * Brief Security Assurance Management and support teams on security posture and remediation strategies Configuration & Change Management * Perform security impact analysis of proposed configuration changes * Review security implications of system changes with Government IT Program Managers (ITPMs) and support staff Continuous Monitoringg & Ongoing Operations Once a system is operational, the ISSO performs recurring activities-ad hoc, daily, weekly, monthly, quarterly, and annually-documented in the continuous monitoring plan: * Support all Authorization to Operate (ATO) and continuous authorization activities * Plan of Action and Milestones (POA&M) Management to track identified system weaknesses to resolution * Information Security Vulnerability Management (ISVM)-review system scans at least monthly for new weaknesses, missed patches, unauthorized assets, or configuration changes * Patch Management to ensure all systems are patched regularly and compliance is maintained * Document and monitor any security issues or inconsistencies * Review ISVM findings for applicability and create POA&Ms or take corrective action as required * Audit Log Monitoring and Event Management-periodically review logs for security incidents, unauthorized access attempts, and anomalous activity * Awareness and Training-ensure all system users complete security awareness and role-based security training annually * Work with federal product managers to prioritize security-related POA&Ms or enhancements into active sprints and releases * Provide 24×7 on-call support for security incidents and escalations * Ensure compliance with Zero Trust cybersecurity principles and support agency adoption of zero trust network architectures ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [DevSecOps: Injecting Security into Mobile CI/CD Pipelines](https://www.wearedevelopers.com/videos/273-devsecops-injecting-security-into-mobile-ci-cd-pipelines) - [DevSecOps culture](https://www.wearedevelopers.com/videos/783-devsecops-culture) - [DevSecOps: Security in DevOps](https://www.wearedevelopers.com/videos/36-devsecops-security-in-devops) - [You can’t hack what you can’t see](https://www.wearedevelopers.com/videos/41-you-can-t-hack-what-you-can-t-see) - [Organizational Change Through The Power Of Why - DevSecOps Enablement](https://www.wearedevelopers.com/videos/478-organizational-change-through-the-power-of-why-devsecops-enablement) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [The Overflow: Security and Privacy](https://www.wearedevelopers.com/magazine/715-the-overflow-security-and-privacy) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing)