> Markdown version of [/jobs/ext/2110349-information-system-security-officer-isso](https://www.wearedevelopers.com/jobs/ext/2110349-information-system-security-officer-isso). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Information System Security Officer, (ISSO) - **Company:** Cinteot Inc. - **Location:** Fort Meade, MD, United States - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** Systems Engineering, Configuration Management, CompTIA Security+, Cyber Security, Information Systems, Information Security Management, Information Systems Security Architecture Professional, Software Vulnerability Management, SARS Software Products, Information Technology, Vulnerability Analysis - **Published:** August 19, 2026 - **Apply:** https://www.careerjet.com/job/us261aa84daf662e6441c6aeb3de754116/eaa ## About the Role * Bachelor's degree in Cybersecurity, Information Technology, or related field. * Must hold and maintain an appropriate DoD 8140.03 / 8570.01-M certification baseline for this labor category (e.g., Security+, CISSP, CISM, or equivalent as required). * At least 7 years of experience in cybersecurity engineering, RMF/DIACAP accreditation, and compliance documentation in DoD environments. * Expertise in the application of DISA STIGs/SRGs, ACAS/HBSS vulnerability analysis, and eMASS package preparation. * Strong written and verbal communication skills, with demonstrated experience producing accreditation documentation and presenting risk findings to senior stakeholders. Desired Qualifications: * Master's degree in Cybersecurity or related discipline. * Experience supporting DISA programs and preparing for CCRI inspections. * Advanced certifications such as CISSP-ISSAP or CISM. Clearance Requirement: Active Top Secret ## Description The Information System Security Officer (ISSO) provides senior-level cybersecurity engineering and compliance support to the Defense Information Systems Agency (DISA) Internet Enterprise (IE) under the CTAS Task Order. This role is responsible for ensuring mission systems achieve and sustain Authorization to Operate (ATO) through implementation of the Risk Management Framework (RMF) and transition from legacy DIACAP requirements. The ISSO - Level 3 acts as both a technical and compliance leader, bridging vulnerability management, STIG/SRG application, and documentation development to create complete and accurate accreditation packages. This position serves as a senior-level resource, providing mentorship to mid-level and junior ISSOs, while interfacing with Government stakeholders, Information System Security Managers (ISSMs), and Authorizing Officials (AOs)., The ISSO is expected to perform duties that span both hands-on technical tasks and high-level compliance oversight. Core responsibilities include: * Leading the development, maintenance, and validation of RMF and A&A artifacts, including System Security Plans (SSPs), Security Assessment Reports (SARs), Plans of Action and Milestones (POA&Ms), configuration management records, and testing documentation. * Implementing and validating compliance with DISA Security Technical Implementation Guides (STIGs) and Security Requirements Guides (SRGs) to maintain technical baselines across supported systems. * Managing and analyzing results from vulnerability scanning and compliance tools such as ACAS, HBSS, and CMRS, and ensuring timely remediation of findings in accordance with IAVM directives. * Preparing and submitting comprehensive accreditation packages in eMASS, ensuring accuracy, completeness, and timeliness of submissions to meet contract and PWS requirements. * Conducting and documenting Security Test and Evaluation (ST&E) activities, ensuring objective assessment of control implementation and risk posture. * Supporting and preparing for Command Cyber Readiness Inspections (CCRI), Security Assessment Visits (SAV), and Cooperative Vulnerability Penetration Assessments (CVPA) by creating corrective action plans, briefing results, and tracking closure of findings. * Providing mentorship and guidance to junior ISSOs, ensuring proper interpretation of DoD cybersecurity policy and consistent application of standards across the team. * Contributing to recurring deliverables such as Policy Compliance Reports, Risk Assessment Reports, and Directorate-level cybersecurity briefings, ensuring all outputs meet QASP Acceptable Quality Levels (AQLs)., Information Systems Security Officer The Opportunity: Join a team of communications and systems engineers supporting engineering, sustainment, and management of communications … + 7 days ago + ## Related Videos - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [Model Based Systems Engineering in an Agile Product Development Process](https://www.wearedevelopers.com/videos/68-model-based-systems-engineering-in-an-agile-product-development-process) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [One Pipeline, Three Regulator - SBOM Compliance for the Developer](https://www.wearedevelopers.com/videos/100169-one-pipeline-three-regulator-sbom-compliance-for-the-developer) - [Cyber Security: Small, and Large!](https://www.wearedevelopers.com/videos/259-cyber-security-small-and-large) - [Automated Driving - Why is it so hard to introduce](https://www.wearedevelopers.com/videos/628-automated-driving-why-is-it-so-hard-to-introduce) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again](https://www.wearedevelopers.com/magazine/751-how-we-built-a-worry-free-system-that-runs-for-10-years-and-what-we-d-do-again) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [The Overflow: Security and Privacy](https://www.wearedevelopers.com/magazine/715-the-overflow-security-and-privacy) - [Dev Digest 216: CyberSec + Mythos, Stack Overflow for Agents & DOOM in TTF](https://www.wearedevelopers.com/magazine/728-dev-digest-216-cybersec-mythos-stack-overflow-for-agents-doom-in-ttf)