> Markdown version of [/jobs/ext/2026635-information-systems-security-officer-isso](https://www.wearedevelopers.com/jobs/ext/2026635-information-systems-security-officer-isso). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Information Systems Security Officer (ISSO) - **Company:** AnaVation, LLC - **Location:** San Antonio, TX, United States - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** Agile Methodology, Software System Penetration Testing, Cloud Computing Security, Cyber Security, Integrated Development Environments, OpenShift, Zero Trust Network Access, Software Factory, Software Vulnerability Management, SARS Software Products, Cloud Platform System, Kubernetes, Information Technology, Cyber Warfare, Devsecops - **Published:** August 11, 2026 - **Apply:** https://jobs.localjobnetwork.com/apply/add/87995770/1 ## About the Role * Clearance: U.S. Citizen, TS/SCI cleared within last 2 years; CI Polygraph within last 5 years * Education: Bachelor's degree in Cybersecurity, Computer Science, Engineering, Information Technology, or related field * Certification: One or more of the following: Security+, CySA+, CASP+ or Equivalent DoD 8140 certification * Location: Full-time on-site in San Antonio, TX. * Experience and knowledge: + Nine or more years supporting Department of Defense cybersecurity missions. + Nine or more years supporting RMF implementation and cybersecurity compliance activities. + Experience maintaining SSPs, POA&Ms, SARs, and RMF documentation. + Experience supporting vulnerability management, STIG implementation, and continuous monitoring. + Experience supporting Agile or SAFe software development environments. + Experience supporting DevSecOps or enterprise cloud environments. + Working knowledge of NIST RMF, NIST SP 800-53, CNSSI guidance, DoD cybersecurity policy, and DISA STIGs. + Experience using cybersecurity compliance and vulnerability management tools. + Excellent written and verbal communication skills., * Clearance: TS/SCI w/CI Poly * Education: Advanced degree in Cybersecurity, Computer Science, Engineering, Information Assurance, or related field. * Certification: One or more of the following: CISSP, CAP, Certified Cloud Security Professional (CCSP). * Experience an Knowledge: + Ten or more years supporting Department of Defense cybersecurity missions. + Experience supporting software factories. + Experience supporting Kubernetes and OpenShift. + Experience supporting Iron Bank or hardened container environments. + Experience supporting Continuous Authority to Operate (cATO). + Experience implementing Zero Trust security controls. + Experience supporting enterprise DevSecOps pipelines. + Experience supporting IL4/IL5/IL6 cloud environments. + Experience supporting Cyber Operations Teams. + Experience supporting Cyber Penetration Teams. + Experience supporting multiple military services and Combatant Commands. ## Description AnaVation is seeking a highly motivated Information Systems Security Officer (ISSO) who will be responsible for implementing cybersecurity, Risk Management Framework (RMF), and continuous monitoring activities supporting Department of Defense software factories and enterprise cloud environments. The ISSO will serve as an embedded cybersecurity professional supporting one or more mission agile teams, working directly with Government leadership, Information Systems Security Managers (ISSMs), Information Systems Security Engineers (ISSEs), Cyber Operations Teams (COT), Cyber Penetration Teams (CPT), Product Owners, software developers, and DevSecOps engineers to maintain secure cloud-native capabilities while enabling rapid software delivery through Continuous Authority to Operate (cATO). This position is full-time support within classified environments in San Antonio, Texas., Position Responsibilities: The Information Systems Security Engineer (ISSO) provides support to enterprise cybersecurity operations across multiple mission value streams and classified environments by executing RMF activities, maintaining cybersecurity documentation, supporting continuous monitoring, and ensuring compliance with Department of Defense cybersecurity policies and mission security standards., * Execute Risk Management Framework (RMF) activities supporting system authorization, continuous monitoring, and Continuous Authority to Operate (cATO). * Maintain RMF documentation including SSPs, POA&Ms, SARs, hardware/software inventories, and security artifacts. * Support cybersecurity assessments conducted by Security Control Assessors, penetration testing teams, and Authorizing Officials. * Monitor system cybersecurity posture and coordinate remediation of vulnerabilities and assessment findings. * Perform vulnerability management, STIG implementation, configuration compliance validation, and security control assessments. * Support implementation of Zero Trust security principles, cloud security controls, Kubernetes/OpenShift security, container hardening, and DevSecOps security practices. * Collaborate with Government leadership, ISSMs, ISSEs, software developers, cloud engineers, Cyber Operations Teams (COT), and Cyber Penetration Teams (CPT) to integrate cybersecurity into Agile software development. * Maintain continuous monitoring documentation, audit evidence, and cybersecurity reporting. * Evaluate cybersecurity findings and recommend corrective actions to improve system security posture. * Assist with annual cybersecurity inspections, assessments, audits, and operational readiness activities. * Prepare technical documentation, executive reports, and cybersecurity metrics supporting Government decision-making. * Support cybersecurity operations across Unclassified, Secret, and SCI environments. ## Related Videos - [DevSecOps culture](https://www.wearedevelopers.com/videos/783-devsecops-culture) - [DevSecOps: Injecting Security into Mobile CI/CD Pipelines](https://www.wearedevelopers.com/videos/273-devsecops-injecting-security-into-mobile-ci-cd-pipelines) - [Understanding Kubernetes in a visual way](https://www.wearedevelopers.com/videos/100085-understanding-kubernetes-in-a-visual-way) - [This Is Not Your Father's .NET](https://www.wearedevelopers.com/videos/967-this-is-not-your-father-s-net) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Organizational Change Through The Power Of Why - DevSecOps Enablement](https://www.wearedevelopers.com/videos/478-organizational-change-through-the-power-of-why-devsecops-enablement) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again](https://www.wearedevelopers.com/magazine/751-how-we-built-a-worry-free-system-that-runs-for-10-years-and-what-we-d-do-again) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [The Overflow: Security and Privacy](https://www.wearedevelopers.com/magazine/715-the-overflow-security-and-privacy) - [Now is the time for industrialized software development](https://www.wearedevelopers.com/magazine/601-now-is-the-time-for-industrialized-software-development)