> Markdown version of [/jobs/ext/2105913-information-security-systems-officer](https://www.wearedevelopers.com/jobs/ext/2105913-information-security-systems-officer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Information Security Systems Officer - **Company:** TechSur Solutions - **Location:** Washington, United States - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** Software System Penetration Testing, Confluence, JIRA, Code Review, CompTIA Security+, Databases, Federal Information Processing Standards (FIPS), Information Security Management, Open Source Technology, Software Vulnerability Management, SolarWinds (Software), Splunk, Devsecops, Servicenow, Plan of Action and Milestones, Static Application Security Testing, Vulnerability Analysis, Dynamic Application Security Testing - **Published:** August 18, 2026 - **Apply:** https://www.dice.com/job-detail/d19fed2c-d2c4-4233-a7d6-4eba9770f4f5 ## About the Role * 5+ years of federal cybersecurity, ISSO, RMF, ATO, or security compliance experience. * Hands-on experience with FISMA Moderate, NIST 800-53, RMF, POA&M management, vulnerability management, security documentation, and ATO support. * Experience Supporting Department of Labor IT programs is REQUIRED. * Experience coordinating remediation across application, database, infrastructure, and DevSecOps teams. * Strong understanding of federal security documentation, security control assessment findings, remediation planning, and continuous monitoring. * U.S. Citizenship and ability to obtain and maintain DOL Public Trust suitability. * Prior DOL OCIO, ETA, CSAM, ATO, or federal civilian ISSO experience. * Security+, CISSP, CISM, CAP, CGRC, CEH, or equivalent security certification. * Experience with Splunk, ServiceNow, Jira, Confluence, SolarWinds, SAST/DAST, and vulnerability scanning tools. ## Description TechSur is seeking an Information System Security Officer to support DOL OCIO/ETA SWARAS security compliance, authorization, continuous monitoring, vulnerability management, POA&M remediation, risk register maintenance, and security documentation. This role serves as the security compliance lead for a FISMA Moderate application ecosystem and coordinates with DOL OCIO cybersecurity stakeholders, application teams, database teams, and program leadership., * Lead SWARAS FISMA Moderate compliance support, including NIST 800-53 controls, NIST 800-171 alignment, FIPS, HSPD-12/PIV, TIC, and DOL security policy compliance. * Maintain CSAM artifacts, system security documentation, security/privacy plans, risk registers, POA&Ms, audit responses, and ATO support documentation. * Analyze vulnerability scan results, audit findings, penetration testing results, and security control assessments, then coordinate remediation with DevSecOps, DBA, and system owner stakeholders. * Track POA&M milestones, remediation timelines, evidence packages, and closure documentation within Government-defined timelines. * Support secure SDLC controls, code review evidence, static/dynamic testing evidence, third-party/open-source component tracking, and security release gates. * Support incident response requirements, including rapid escalation for PII-related incidents and coordination with DOL OCIO security stakeholders. * Provide security input for CPIC reporting, portfolio data calls, continuous monitoring, and governance reviews. ## Related Videos - [Kubernetes and Microservices with Multi-Model Databases](https://www.wearedevelopers.com/videos/382-kubernetes-and-microservices-with-multi-model-databases) - [Our journey with Spring Boot in a microservice architecture](https://www.wearedevelopers.com/videos/511-our-journey-with-spring-boot-in-a-microservice-architecture) - [Improving quality with Agentic AI with Rovo Dev and Xray](https://www.wearedevelopers.com/videos/2005-improving-quality-with-agentic-ai-with-rovo-dev-and-xray) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Fault Tolerance and Consistency at Scale: Harnessing the Power of Distributed SQL Databases](https://www.wearedevelopers.com/videos/1146-fault-tolerance-and-consistency-at-scale-harnessing-the-power-of-distributed-sql-databases) - [DevSecOps culture](https://www.wearedevelopers.com/videos/783-devsecops-culture) ## Related Articles - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Best Paying Jobs in Technology](https://www.wearedevelopers.com/magazine/256-best-paying-jobs-in-technology) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again](https://www.wearedevelopers.com/magazine/751-how-we-built-a-worry-free-system-that-runs-for-10-years-and-what-we-d-do-again) - [The Overflow: Security and Privacy](https://www.wearedevelopers.com/magazine/715-the-overflow-security-and-privacy) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed)