> Markdown version of [/jobs/ext/1951746-information-system-security-officer-isso](https://www.wearedevelopers.com/jobs/ext/1951746-information-system-security-officer-isso). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Information System Security Officer (ISSO) - **Company:** Illumination Works - **Location:** United States (Remote available) - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** Application Programming Interfaces (APIs), Amazon Web Services, Microsoft Azure, Cloud Computing Security, Cyber Security, Information Security Management, Systems Architecture, Systems Integration, Software Vulnerability Management, SC Clearance, Information Technology, Api Design, Plan of Action and Milestones - **Published:** August 6, 2026 - **Apply:** https://www.clearancejobs.com/jobs/9077823/information-system-security-officer-isso ## About the Role * Must hold active Secret Clearance * Experience with DoD RMF processes, especially for FM systems, including preparing for FISCAM audits, FM control implementation, POA&M management, and ATO support * Experience supporting FISCAM, FIAR, or other Federal audit activities * Knowledge of NIST 800-53 security controls and continuous monitoring practices * Experience performing security assessments and validating system compliance * Familiarity with vulnerability management tools (e.g., ACAS, Tenable, or similar) * Experience using eMASS to manage RMF packages and security documentation * Understanding of cloud security principles (AWS/Azure, GovCloud, or similar environments) * Experience proposing, coordinating, implementing, and enforcing information systems security policies, standards, and methodologies, preferably on a large software or IT program * Experience securing enterprise data integrations, APIs, or system interfaces * Strong documentation skills, particularly for RMF artifacts (e.g., SSP) and compliance reporting * Strong analytical, problem-solving, and organizational skills * Ability to work collaboratively across engineering, architecture, and cybersecurity teams * Must have excellent interpersonal skills * Security+ certification required (or higher DoD 8570/8140 equivalent) * 5+ years of experience in information system security, cybersecurity, or related roles * Bachelor's degree in Computer Science, Cybersecurity, or comparable academic discipline * Ability to pass required background screening and drug testing ## Description We are seeking an experienced Information System Security Officer (ISSO) to support implementing and maintaining the cybersecurity posture of mission-critical finance-related systems. This role is responsible for supporting Risk Management Framework (RMF) compliance, Authority to Operate (ATO) activities, continuous monitoring, cybersecurity audit readiness, and security compliance across enterprise data environments. The successful candidate will work closely with cybersecurity, engineering, system architecture, and Government stakeholders to implement and maintain security controls in a cloud environment while supporting recurring FISCAM, NIST, RMF, and financial management security compliance activities., * Support implementation and enforcement of cybersecurity policies and controls in accordance with DoD RMF, NIST 800-53, and Air Force guidance * Support security compliance activities for enterprise financial data and system integrations via implementing and maintaining RMF Financial Management (FM) Overlay security controls * Support ATO lifecycle activities, including control implementation, validation, and continuous monitoring * Develop, maintain, and update RMF documentation, including System Security Plans (SSPs), POA&Ms, security control implementation evidence, assessment artifacts, and other ATO and FISCAM audit readiness documentation * Support recurring Government cybersecurity and financial audits by preparing documentation, responding to auditor requests, and participating in technical walkthroughs * Evaluate and validate security controls for systems, applications, and integrations, including cloud and API-based architectures * Support incident response activities, including detection, reporting, and coordination with cybersecurity teams * Track, document, and support remediation of security findings through Corrective Action Plans (CAPs) * Provide support to the Information System Security Manager (ISSM) for maintaining the appropriate operational IA posture for a system/program/enclave Do you have what it takes? Are you driven to implement creative solutions that unravel complex and ever-changing challenges? We value passion, curiosity, and perseverance with an ability to communicate ideas and results to diverse audiences. We look for people who thrive in collaborative and independent assignments, have the aptitude to learn new data quickly, and who are willing to mentor junior team members. ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [API Design - Getting Started](https://www.wearedevelopers.com/videos/33-api-design-getting-started) - [One Pipeline, Three Regulator - SBOM Compliance for the Developer](https://www.wearedevelopers.com/videos/100169-one-pipeline-three-regulator-sbom-compliance-for-the-developer) - [Enabling automated 1-click customer deployments with built-in quality and security](https://www.wearedevelopers.com/videos/83-enabling-automated-1-click-customer-deployments-with-built-in-quality-and-security) - [Cyber Security: Small, and Large!](https://www.wearedevelopers.com/videos/259-cyber-security-small-and-large) ## Related Articles - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [The Overflow: Security and Privacy](https://www.wearedevelopers.com/magazine/715-the-overflow-security-and-privacy) - [Best Paying Jobs in Technology](https://www.wearedevelopers.com/magazine/256-best-paying-jobs-in-technology)