> Markdown version of [/jobs/ext/1973585-senior-information-system-security-officer](https://www.wearedevelopers.com/jobs/ext/1973585-senior-information-system-security-officer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Senior Information System Security Officer - **Company:** CACI International Inc. - **Location:** Washington, DC, United States - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** Configuration Management, Cyber Security, Information Systems, Information Security Management, Requirements Traceability, Vulnerability Analysis - **Published:** August 7, 2026 - **Apply:** https://us.experteer.com/career/view-jobs/senior-information-system-security-officer-washington-dc-usa-58839000 ## About the Role * Develop contingency and incident response plans; perform risk and security assessments and vulnerability testing * Design security architectures, requirement traceability, and authorization boundary diagrams; advise leadership on cybersecurity matters * Prepare remediation plans for audit findings; maintain daily FISMA scorecard analysis * Maintain hardware/software inventories; ensure proper access controls for system and facility access * Produce Security Test Plans/reports, Risk Assessment Reports, and periodic program reports to track progress * Research and apply current security tools, techniques, and countermeasures against vulnerabilities Tasks * U.S. Citizenship required * Active Top Secret security clearance required * FEMA EOD suitability or current DHS/FEMA EOD preferred * BS/BA + 15 years of information security experience * IAT Level III qualification: CISSP or CISM or CASP+ * 10+ years in information security * Strong RMF, NIST, FISMA, and DHS 4300 Series knowledge * Experience developing SSPs, POA&Ms, and Configuration Management Plans * Knowledge of NIST SP 800-37/800-53 and DHS 4300 Series requirements Key requirements * flexible time off * robust learning resources * healthcare * retirement benefits * continuing education * time off benefits ## Description Experteer Overview In this Senior ISSO role, you will lead RMF activities to secure FEMA information systems and ensure compliant security posture. You'll act as the main security liaison for the Cyber Security Division, guiding ATO decisions and security documentation. You will work with system owners and cybersecurity professionals to design and implement controls, contingency and incident response plans, and continuous monitoring. You will help protect mission-critical FEMA data and systems in a fast-paced government environment. This is a chance to influence security posture across multiple programs and drive safe, compliant operations. Compensation / Benefits * Lead RMF activities for ATO decisions, including categorization, control selection, self-assessments, POA&Ms, and continuous monitoring * Develop and maintain System Security Plans (SSPs), control baselines, and inventories * Create and maintain Configuration Management Plans; approve change requests and test config changes * Develop contingency and incident response plans; perform risk and security assessments and vulnerability testing * Design security architectures, requirement traceability, and authorization boundary diagrams; advise leadership on cybersecurity matters * Prepare remediation plans for audit findings; maintain daily FISMA scorecard analysis * Maintain hardware/software inventories; ensure proper access controls for system and facility access * Produce Security Test Plans/reports, Risk Assessment Reports, and periodic program reports to track progress * Research and apply current security tools, techniques, and countermeasures against vulnerabilities Tasks * U.S. Citizenship required * Active Top Secret security clearance required * FEMA EOD suitability or current DHS/FEMA EOD preferred * BS/BA + 15 years of information security experience * IAT Level III qualification: CISSP or CISM or CASP+ * 10+ years in information security * Strong RMF, NIST, FISMA, and DHS 4300 Series knowledge * Experience developing SSPs, POA&Ms, and Configuration Management Plans * Knowledge of NIST SP 800-37/800-53 and DHS 4300 Series requirements Key requirements * flexible time off * robust learning resources * healthcare * retirement benefits * continuing education * time off benefits ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [How to Cause (or Prevent) a Massive Data Breach- Secure Coding and IDOR](https://www.wearedevelopers.com/videos/39-how-to-cause-or-prevent-a-massive-data-breach-secure-coding-and-idor) - [Microservices? Monoliths? An Annoying Discussion!](https://www.wearedevelopers.com/videos/970-microservices-monoliths-an-annoying-discussion) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [Reporting Active Exploits in 24 Hours: Are You Ready for the CRA?](https://www.wearedevelopers.com/videos/100248-reporting-active-exploits-in-24-hours-are-you-ready-for-the-cra) - [One Pipeline, Three Regulator - SBOM Compliance for the Developer](https://www.wearedevelopers.com/videos/100169-one-pipeline-three-regulator-sbom-compliance-for-the-developer) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Best Paying Jobs in Technology](https://www.wearedevelopers.com/magazine/256-best-paying-jobs-in-technology) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [The Overflow: Security and Privacy](https://www.wearedevelopers.com/magazine/715-the-overflow-security-and-privacy)