> Markdown version of [/jobs/ext/2000619-information-systems-security-officer](https://www.wearedevelopers.com/jobs/ext/2000619-information-systems-security-officer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Information Systems Security Officer - **Company:** Open Systems Inc. - **Location:** Annapolis Junction, MD, United States - **Contract:** Permanent contract - **Skills:** Xacta, Configuration Management, CompTIA Security+, Cyber Security, Information Security Management, Software Vulnerability Management, Tenable Nessus, Operating System Security, Plan of Action and Milestones - **Published:** August 9, 2026 - **Apply:** https://www.wayup.com/i-j-Information-Systems-Security-Officer-Open-Systems-Technologies-Corporation-153581193129013/ ## About the Role + Active TS/SCI with Polygraph security clearance. + U.S. Citizenship. + Experience supporting Information Assurance, Cybersecurity, or ISSO activities within classified environments. + Strong understanding of the Risk Management Framework (RMF) process. + Knowledge of: o Authority to Operate (ATO) processes o Security Control implementation and assessment o Continuous Monitoring (ConMon) o Risk assessment methodologies + Experience with RMF and cybersecurity compliance tools, including: o LATTEART o XACTA o BISCOTTI o WATCHCAT o STE + Experience with compliance and configuration scanning tools. + Familiarity with: o NIST SP 800-53 Revision 3 and/or Revision 5 o NIST SP 800-37 + Strong written and verbal communication skills. + Ability to work independently and collaboratively in a mission-focused environment., + Strong attention to detail. + Excellent organizational skills. + Effective communication and collaboration abilities. + Sound risk-based decision-making. + Ability to balance mission requirements with cybersecurity compliance. + A proactive approach to identifying and mitigating security risks. ## Description Open Systems Technologies Corporation (OST) is seeking Information System Security Officers (ISSOs) to support mission-critical Government programs. The ISSO will be responsible for ensuring systems maintain compliance with security requirements throughout the Risk Management Framework (RMF) lifecycle while supporting accreditation, continuous monitoring, and cybersecurity operations activities. The ideal candidate will possess strong RMF expertise, experience working with cybersecurity compliance and assessment tools, and the ability to collaborate effectively with System Administrators, System Owners, Information System Security Managers (ISSMs), and Government stakeholders. Responsibilities + Support the full Risk Management Framework (RMF) lifecycle for classified information systems. + Develop, maintain, and update RMF documentation and security authorization packages. + Coordinate activities required to obtain and maintain Authority to Operate (ATO) approvals. + Conduct security control assessments and compliance reviews. + Monitor and track vulnerabilities, findings, and remediation efforts. + Support Continuous Monitoring (ConMon) activities and ongoing security assessments. + Review system configurations and scan results to ensure compliance with security requirements. + Collaborate with System Administrators and System Owners to implement and maintain security controls. + Monitor privileged user activities and support oversight requirements. + Participate in security audits, inspections, and cybersecurity reviews. + Provide recommendations for risk mitigation and system security improvements., Candidates should have experience developing, reviewing, or maintaining security documentation, including: + System Security Plans (SSP) + Plans of Action and Milestones (POA&M) + Security Plan Findings (SPFs) and Exception Documentation + Business Impact Assessments (BIA) + Configuration Management Plans (CMP) + After Action Reports (AAR) + Contingency Plans (CP) + Security Assessment Reports (SAR) + Risk Assessment Reports (RAR) Preferred Qualifications + Experience supporting classified Government systems. + Familiarity with auditing and compliance requirements. + Experience coordinating with Authorizing Officials, Security Control Assessors, ISSMs, and System Owners. + Understanding of vulnerability management and remediation processes. + Knowledge of system administration concepts and operating system security. + Security certifications such as: o CompTIA Security+ o CISSP o CAP o CASP+ o CISM ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [DevSecOps culture](https://www.wearedevelopers.com/videos/783-devsecops-culture) - [Cyber Security: Small, and Large!](https://www.wearedevelopers.com/videos/259-cyber-security-small-and-large) - [Maturity assessment for technicians or how I learned to love OWASP SAMM](https://www.wearedevelopers.com/videos/351-maturity-assessment-for-technicians-or-how-i-learned-to-love-owasp-samm) - [Less Is More: How Lagom and Agile Can Create Harmonious Workflows](https://www.wearedevelopers.com/videos/1993-less-is-more-how-lagom-and-agile-can-create-harmonious-workflows) ## Related Articles - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [The Overflow: Security and Privacy](https://www.wearedevelopers.com/magazine/715-the-overflow-security-and-privacy) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking)