> Markdown version of [/jobs/ext/2042968-information-system-security-officer-isso](https://www.wearedevelopers.com/jobs/ext/2042968-information-system-security-officer-isso). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Information System Security Officer (ISSO) - **Company:** ALLIED UNIVERSAL TOPCO LLC - **Location:** Woodlawn, MD, United States - **Experience:** Experienced - **Salary:** $69,550.0 - $125,725.0 - **Contract:** Permanent contract - **Skills:** Xacta, Microsoft Word, Microsoft Excel, Confluence, JIRA, CompTIA Security+, Cyber Security, Information Systems, Federal Information Processing Standards (FIPS), Information Security Management, Microsoft Office, Microsoft PowerPoint, Microsoft SharePoint, SARS Software Products, Information Technology, Servicenow, Plan of Action and Milestones, Vulnerability Analysis - **Published:** August 13, 2026 - **Apply:** https://www.careerjet.com/jobad/us239b3ddac60ce7decaf5213babd9ac0f ## About the Role * Bachelor's degree in cybersecurity, information systems, information technology, computer science, or a related field. * 3 4 years of experience supporting federal information security programs, including direct involvement with the NIST Risk Management Framework (NIST SP 800-37) and security control implementation based on NIST SP 800-53. * Demonstrated experience assisting with or conducting Security Control Assessments (SCAs) and supporting preparation of security authorization documentation such as System Security Plans (SSPs), Security Assessment Reports (SARs), and POA&Ms. * Working knowledge of federal information security regulatory frameworks and standards, including FISMA, FedRAMP, OMB A-130, FIPS publications, and HIPAA as they apply to federal systems. * Ability to gather requirements, assess security-related requests, and communicate effectively with ISSOs, technical stakeholders, and agency personnel to support documentation and remediation efforts. * Experience authoring or contributing to System Security Plans with limited oversight, incorporating stakeholder input and aligning documentation to applicable security control baselines. * Familiarity with SA&A tools (e.g., ServiceNow, Xacta, eMASS, or equivalent) used to create, maintain, and track system security documentation throughout the RMF lifecycle. * Proficiency with Microsoft Office 365 products, including Word, Excel, PowerPoint, Teams, and SharePoint, for documentation, reporting, and stakeholder collaboration. * Strong written and verbal communication skills, with the ability to independently facilitate stakeholder meetings and present security-related findings and recommendations clearly., * Prior experience supporting information security programs at a federal civilian agency, particularly within an environment subject to FISMA continuous monitoring requirements. * Familiarity with SSA security operations, including SSA's SA&A processes, security boundary structure, or agency-specific RMF implementation guidance. * Experience facilitating POA&M remediation efforts and coordinating with technical teams to develop and implement risk mitigation strategies. * Knowledge of OMB Security and Privacy Memoranda and DHS Binding Operational Directives and their operational impact on federal agency security programs. * Experience supporting or participating in Targeted Control Assessments or third-party security assessments in a preparation or coordination capacity. * Relevant certifications such as CompTIA Security+, Certified Authorization Professional (CAP/CGRC), CISSP, or equivalent information security certifications. * Experience using JIRA, Confluence, or similar platforms for task tracking, documentation, and reporting in support of security program operations. ## Description Prudent is seeking to supports the Social Security Administration (SSA) Risk Management Framework (RMF) program by assisting the Information System Security Officer (ISSO), Security Authorization Manager (SAM), Designated SAM Representative (DSR), and system stakeholders with the development and maintenance of security authorization documentation. Leverages SSA's Security Assessment & Authorization (SA&A) tool to complete, update, and track all required system security artifacts across assigned system boundaries, supporting activities spanning the full NIST RMF lifecycle from categorization through continuous monitoring., * Assist the ISSO, SAM, and DSR with RMF documentation development and maintenance in SSA's Security Authorization Tool (e.g., ServiceNow), supporting Planning, Categorization, Control Selection, Implementation, Assessment, Authorization, and Monitoring activities. * Support the completion of Authorization to Operate (ATO) packages, including System Security Plans (SSPs), security control documentation, and supporting artifacts for assigned information systems. * Assist with establishing and maintaining SI-2 (Flaw Remediation) and RA-5 (Vulnerability Scanning) reports for each assigned security boundary in coordination with the ISSO and technical stakeholders. * Provide support to the ISSO and stakeholders during Targeted Control Assessments and Continuous Monitoring Assessments, including gathering and organizing required evidence and artifacts. * Assist the ISSO and stakeholders in reviewing Security Assessment Reports (SARs), understanding identified risks, and recommending potential mitigation strategies. * Facilitate the remediation of Plan of Actions and Milestones (POA&Ms) by coordinating with technical stakeholders to address vulnerabilities identified through audits, assessments, continuous monitoring, and system maintenance activities. * Track and report POA&M remediation status to the supervisor and ISSOs on a regular basis, ensuring timely closure and accurate documentation of mitigation activities. * Conduct semi-annual quality assurance reviews of assigned security boundaries and deliver results to the ISSO and relevant stakeholders. * Analyze new and emerging federal laws, directives, regulations, and standards (e.g., OMB A-130, FIPS, NIST Special Publications, DHS Binding Operational Directives, Executive Orders) for their impact on SSA information security operations. * Assist the ISSO team with the support and remediation of agency audit findings, coordinating corrective action documentation and evidence collection as required. * Communicate task status, risks, and schedule changes to the appropriate supervisor or Work Order Manager in a timely and professional manner. * Document all contractor activities and deliverables in accordance with SSA reporting requirements. ## Related Videos - [Improving quality with Agentic AI with Rovo Dev and Xray](https://www.wearedevelopers.com/videos/2005-improving-quality-with-agentic-ai-with-rovo-dev-and-xray) - [42 x 2 Canvases Later: Two Years, Two Minds, Many Lessons](https://www.wearedevelopers.com/videos/1458-42-x-2-canvases-later-two-years-two-minds-many-lessons) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [A Founder's Journey : From Startup Chaos to Purposeful Growth](https://www.wearedevelopers.com/videos/1926-a-founder-s-journey-from-startup-chaos-to-purposeful-growth) - [Collaboration Quantified: Lessons from Open Source Developer Networks](https://www.wearedevelopers.com/videos/1422-collaboration-quantified-lessons-from-open-source-developer-networks) - [One Pipeline, Three Regulator - SBOM Compliance for the Developer](https://www.wearedevelopers.com/videos/100169-one-pipeline-three-regulator-sbom-compliance-for-the-developer) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again](https://www.wearedevelopers.com/magazine/751-how-we-built-a-worry-free-system-that-runs-for-10-years-and-what-we-d-do-again) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks)