> Markdown version of [/jobs/ext/1995853-information-systems-security-officer-isso](https://www.wearedevelopers.com/jobs/ext/1995853-information-systems-security-officer-isso). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Information Systems Security Officer (ISSO) - **Company:** Leidos, Inc. - **Location:** Oxon Hill, MD, United States (Remote available) - **Salary:** $131,300.0 - $237,350.0 - **Contract:** Permanent contract - **Skills:** Amazon Web Services, Microsoft Azure, Software as a Service, Configuration Management, Complex Networks, Cyber Security, Information Systems, Firmware, Information Security Management, Cloud Platform System, HybridCloud - **Published:** August 8, 2026 - **Apply:** https://www.careerjet.com/job/usf369ce4367b8ecb96f33992d07045cb3/eaa ## About the Role * Bachelor's Degree and 12 years of IT Security, ISSO/ISSE experience directly supporting the customer. Additional years of experience in lieu of degree may be considered. * Public, private and hybrid Cloud experience (AWS, Microsoft Azure, etc.). * Active Public Trust Clearance or Ability to obtain a Public Trust Clearance. * Experience working with ATO and security protocols with cloud application solutions. * Exceptional attention to detail, necessary to produce outstanding accreditation products * Outstanding written and verbal communication skills. ## Description Join the Digital Sector! We're on the lookout for a dynamic and experienced Information Systems Security Officer (ISSO) with 12+ years of expertise to help drive IT mission-critical cybersecurity initiatives. In this high-impact role, you'll support Accreditation & Authorization (A&A) efforts across multiple tiers of the customer organization, playing a key role in strengthening security at the program level and beyond. If you're ready to lead, collaborate, and make a difference - this is your moment! Candidate MUST: Be currently located in the United States. Have the ability to obtain a level 4 Public Trust Clearance. This role is primarily remote, with rare onsite requirements. Candidates must be local to the DC Metro area and available to attend in-person meetings in Washington, DC as needed. Responsibilities: Other skills and responsibilities include, but are not limited to: * Perform Certification & Accreditation (C&A), System Assessment & Authorization (SA&A) as part of NIST SP 800-37 Risk Management Framework (RMF) system and application accreditation. * Possess multi-tasking skills, be able to handle multiple A&A systems / projects simultaneously, as well as being a good communicator / facilitator. Comfortable communicating at all levels from developer / engineer to senior contractor / customer staff. * Knowledge of complex network environments involving shared networks and multiple security enclaves. * Develops, reviews, evaluates, and verifies security requirements meet or exceed Federal Government security policies and controls within a cloud environments. * Possess the ability to bridge the technical implementation (i.e. engineering talk) into commonly understood security verbiage. * Evaluation of the assigned information systems' security control compliance with the federal requirements and the client's monitoring strategy. * Management of emerging and defined risks associated with the administration and use of assigned information systems. * Coordination with the client's Cybersecurity team to achieve and maintain the information systems' compliance and authorization to operate (ATO). * Ensuring systems are operated, maintained, and disposed of in accordance with policies outlined in the approved security authorization package. * Performing annual assessments to ensure compliance with the client's policies and standards. * Support the Change Control Board (CCB) to ensure configuration management for Cybersecurity-relevant software, hardware, and firmware is maintained and documented. * Ensuring information system security requirements are addressed during all phases of information systems lifecycle. * Work within a team environment to provide technically sound guidance order to adhere to the cybersecurity industry's best practices and the client's monitoring strategy. * Analyze collected information to identify vulnerabilities and potential for exploitation and effectively present the results and guidance derived from scans to system owners or other leadership, as required. * Effectively communicate orally and in writing to track and detail the demands, efforts, and shortcomings in meeting the goals of the client's information system monitoring strategy. * Support the integration/testing, operations, and maintenance of systems security. * Develops, updates, and maintains internal Standard Operating Procedures for all internal assigned functions. * Document the various security control implementations as well as gather the artifacts that support the Risk Management Framework (RMF) and ICD 503 Security Accreditation for the various Assessment and Authorization (A&A) efforts. * Document and obtain a general understanding of the architecture being developed or that was developed for each project in order to write the Systems Security Plans (SSP) / CONOPS. * Gather the information by working with various systems owners, project managers, and engineering team members in order to write various additional A&A related documents such as Contingency Plan (CP), General User Guide (GUG), Privileged User Guide (PUG), Standard Operating Procedures (SOP's), etc. * Document the Plans of Actions and Milestones (POA&Ms) implementation responses or mitigations, as well as provide all required artifacts (i.e. evidence gathering from the system owners, PMs, and engineering teams). * Coordinating with various contractor and customer personnel to obtain the A&A content, as well as working with various customer security organizations to navigate the customer's A&A process to achieve Authority to Develop (ATD), Interim Authority to Operation (IATT), and Authority to Operate (ATO) for each of the primary and secondary assigned systems. * Provide appropriate support for ATO'ed systems that are in continuous monitoring., JOB SUMMARY: Andy Frain Services is looking for a highly motivated individual that is multi-task-oriented to manage a Security contract. Manages the accountability of all Supervi… + 22 hours ago, JOB SUMMARY: Andy Frain Services is looking for a highly motivated individual that is multi-task-oriented to manage a Security contract. Manages the accountability of all Supervi… + 22 hours ago + ## Related Videos - [DevSecOps culture](https://www.wearedevelopers.com/videos/783-devsecops-culture) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [Playing Pong on a shoulder press machine](https://www.wearedevelopers.com/videos/100140-playing-pong-on-a-shoulder-press-machine) - [Cyber Security: Small, and Large!](https://www.wearedevelopers.com/videos/259-cyber-security-small-and-large) - [Agent Smith Gets Hardware: Autonomous IoT Hacking From Debug Port to Cloud API](https://www.wearedevelopers.com/videos/100258-agent-smith-gets-hardware-autonomous-iot-hacking-from-debug-port-to-cloud-api) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) ## Related Articles - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [Best Paying Jobs in Technology](https://www.wearedevelopers.com/magazine/256-best-paying-jobs-in-technology) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Fully Remote Software Engineer Jobs](https://www.wearedevelopers.com/magazine/447-fully-remote-software-engineer-jobs) - [IT Salaries in UK](https://www.wearedevelopers.com/magazine/288-it-salaries-in-uk) - [Is Software Engineering Over-Saturated?](https://www.wearedevelopers.com/magazine/418-is-software-engineering-over-saturated)