> Markdown version of [/jobs/ext/1977241-information-system-security-officer](https://www.wearedevelopers.com/jobs/ext/1977241-information-system-security-officer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Information System Security Officer - **Company:** Peraton Inc - **Location:** Washington, VA, United States - **Experience:** Experienced - **Contract:** Permanent contract - **Skills:** Identity and Access Management, Information Security Management, SAP (Applications), Security Content Automation Protocol, Software Vulnerability Management, Plan of Action and Milestones - **Published:** August 7, 2026 - **Apply:** https://us.experteer.com/career/view-jobs/information-system-security-officer-washington-va-usa-58834371 ## About the Role via vulnerability management, config compliance, patch coordination, scan triage, risk acceptance, remediation verification * Review and approve security-relevant changes via configuration/change control; validate security configs after major upgrades * Support incident response and reporting: investigations, containment actions, evidence preservation, lessons learned * Ensure least privilege/access governance: account management oversight, privileged access workflows, periodic access reviews, audit compliance * Translate security requirements into implementation guidance that engineering teams can operationalize (clear, testable, automatable) Tasks * Active Top Secret clearance with SCI eligibility * 5 years with BS/BA; 3 years with MS/MA (4 years additional relevant experience may be considered in lieu of BS) * Security+ or equivalent (DoD 8570 IAM Level II) * Experience with SAP assessments and authorizations * 3+ years experience with Authority to Operate (ATO) process, continuous aaa reviews, POA&Ms, Security Authorizations (SA), NIST 800-37/800-53 Rev4/Rev5; working with ISO and PM * Experience with SCAP, STIGs, and other compliance tools * Proven written and verbal communication skills; ability to work well with team members * Active TS clearance with ability to obtain SCI Key requirements * overtime * shift differential * discretionary bonus ## Description Experteer Overview In this role you will support the ISSM across multiple environments to ensure information assurance and RMF compliance. You will drive secure authorization processes and continuous monitoring while collaborating with engineering teams and program managers. You'll translate security requirements into actionable guidance and uphold least-privilege controls to protect critical systems. This onsite role offers TS/SCI-level access in a mission-focused setting with opportunities to influence security posture at scale. Compensation / Benefits * Assist the ISSM with information assurance efforts across environments * Perform ISSO responsibilities per JSIG and regulations * Lead RMF activities: control oversight, evidence collection, assessment support, POA&M management, continuous monitoring * Maintain security authorization artifacts (SSP, narratives, diagrams, control inheritance, CM plan, incident handling, contingency artifacts, procedures) * Operate continuous monitoring: vulnerability management, config compliance, patch coordination, scan triage, risk acceptance, remediation verification * Review and approve security-relevant changes via configuration/change control; validate security configs after major upgrades * Support incident response and reporting: investigations, containment actions, evidence preservation, lessons learned * Ensure least privilege/access governance: account management oversight, privileged access workflows, periodic access reviews, audit compliance * Translate security requirements into implementation guidance that engineering teams can operationalize (clear, testable, automatable) Tasks * Active Top Secret clearance with SCI eligibility * 5 years with BS/BA; 3 years with MS/MA (4 years additional relevant experience may be considered in lieu of BS) * Security+ or equivalent (DoD 8570 IAM Level II) * Experience with SAP assessments and authorizations * 3+ years experience with Authority to Operate (ATO) process, continuous monitoring, POA&Ms, Security Authorizations (SA), NIST 800-37/800-53 Rev4/Rev5; working with ISO and PM * Experience with SCAP, STIGs, and other compliance tools * Proven written and verbal communication skills; ability to work well with team members * Active TS clearance with ability to obtain SCI Key requirements * overtime * shift differential * discretionary bonus ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Starting business without breaking the bank: Self hosted OSS productivity ecosystem](https://www.wearedevelopers.com/videos/1219-starting-business-without-breaking-the-bank-self-hosted-oss-productivity-ecosystem) - [Beyond the Numbers: Engineering Recruiting Excellence Through Quality, Data, and Team Empowerment](https://www.wearedevelopers.com/videos/1491-beyond-the-numbers-engineering-recruiting-excellence-through-quality-data-and-team-empowerment) - [Independently together: how micro-applications improve developer experience + app performance](https://www.wearedevelopers.com/videos/452-independently-together-how-micro-applications-improve-developer-experience-app-performance) - [Organizational Change Through The Power Of Why - DevSecOps Enablement](https://www.wearedevelopers.com/videos/478-organizational-change-through-the-power-of-why-devsecops-enablement) - [Building Well-Architected applications](https://www.wearedevelopers.com/videos/691-building-well-architected-applications) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Best Paying Jobs in Technology](https://www.wearedevelopers.com/magazine/256-best-paying-jobs-in-technology)