> Markdown version of [/jobs/ext/2170021-senior-information-systems-security-officer](https://www.wearedevelopers.com/jobs/ext/2170021-senior-information-systems-security-officer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Senior Information Systems Security Officer - **Company:** ANALYGENCE, Inc. - **Location:** Washington, DC, United States - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** Xacta, Microsoft Windows, Agile Methodology, Amazon Web Services, Audit Trail, Microsoft Azure, Cloud Computing, Cloud Computing Security, Software Documentation, Cyber Security, Information Systems, Linux, Open Source Technology, Smartsuite, Security Content Automation Protocol, Security Software, HybridCloud, Gitlab, Splunk, Devsecops, Plan of Action and Milestones, Vulnerability Analysis - **Published:** August 21, 2026 - **Apply:** https://diversityjobs.com/main/sendform/8/8/28176/1/18002828?backUrl=%2Fcareer%2F18002828%2FSenior-Information-Systems-Security-Officer-D-C-Washington ## About the Role * 10+ years of related cybersecurity experience. * At least 2 years of recent experience in A&A, FISMA compliance, IC cybersecurity policy and standards, continuous monitoring, CDS, and secure cloud and hybrid engineering. * Experience applying NIST 800 series, CNSSI 1253, security controls, and RMF principles. * Experience with emerging security risk management practices, including automation of A&A and continuous monitoring activities. * CISM, CAP, or GRC certification, or comparable demonstrable experience. * Experience developing, reviewing, or maintaining SSPs, POA&Ms, risk exceptions, contingency plans, privileged user documentation, ATO packages, and continuous monitoring evidence. * Experience working with GRC tools and coordinating with technical teams to remediate vulnerabilities and maintain authorization readiness. * Strong written and verbal communication skills. * Ability to work onsite at a Government-approved location as required. Preferred Qualifications: * Prior DHS, Intelligence Community, DoD, CISO office, ISSM, AO, SCA, or national security ISSO experience. * Experience supporting large ISSO portfolios, classified systems, hybrid cloud environments, DevSecOps evidence collection, continuous monitoring, and audit readiness. * Experience with Archer, eMASS, Xacta, ACAS, Tenable.sc, Splunk, GitLab, Axonius, STIG/SCAP validation, or related Federal cybersecurity tools. * Experience with AWS, Microsoft Azure, Microsoft 365, or other cloud platforms. * Experience supporting TS/SCI, SCIF, cross-domain, or secure mission environments. ## Description Tharros is seeking a Senior Information Systems Security Officer to support a DHS Intelligence and Analysis cybersecurity program in the National Capital Region. This role will support ISSO operations across a complex Federal cybersecurity environment, including Assessment and Authorization, continuous monitoring, ATO package maintenance, POA&M management, security artifact quality, cloud and hybrid system support, and cybersecurity compliance. The ideal candidate is a hands-on ISSO who can maintain accurate authorization evidence, coordinate with technical teams, and help keep mission systems secure, compliant, and authorization-ready. Responsibilities: * Perform ISSO duties for assigned Federal information systems. * Support RMF activities, including system categorization, control implementation support, assessment readiness, authorization package maintenance, and ongoing monitoring. * Develop, review, validate, and maintain security artifacts such as SSPs, POA&Ms, risk exceptions, contingency plans, privileged user documentation, and privacy-related artifacts. * Create, maintain, and monitor ATO packages in GRC tools. * Support POA&M development, validation, remediation tracking, exception documentation, closure, and reporting. * Collaborate with system owners, ISSOs, ISSMs, developers, engineers, assessors, and other stakeholders to address vulnerabilities, security findings, and remediation actions. * Review vulnerability scan results and support recurring continuous monitoring activities. * Support audit log review, alert response, and documentation of follow-up actions. * Ensure assigned systems remain aligned with applicable cybersecurity policies, procedures, and decommissioning requirements. * Support quarterly cybersecurity performance and compliance reporting. * Provide ISSO support across hybrid environments, including classified and unclassified on-premise systems, cloud-based systems, DevSecOps environments, and agile development teams. * Support security for operating systems and technologies including Linux, Windows, open-source operating systems, and cloud platforms. * Support Cross Domain Solution security governance, assessment, and authorization activities. * Help improve ISSO workflows, evidence management, POA&M tracking, continuous monitoring, and risk reporting through automation and repeatable processes. * Translate compliance status, vulnerability data, and remediation progress into clear updates for technical and leadership stakeholders. ## Related Videos - [Our journey with Spring Boot in a microservice architecture](https://www.wearedevelopers.com/videos/511-our-journey-with-spring-boot-in-a-microservice-architecture) - [Docker network without Docker](https://www.wearedevelopers.com/videos/1418-docker-network-without-docker) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Docker exec without Docker](https://www.wearedevelopers.com/videos/1094-docker-exec-without-docker) - [DevSecOps culture](https://www.wearedevelopers.com/videos/783-devsecops-culture) - [Discover the open source trio you didn’t expect: .NET and PostgreSQL on Linux](https://www.wearedevelopers.com/videos/2042-discover-the-open-source-trio-you-didn-t-expect-net-and-postgresql-on-linux) ## Related Articles - [How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again](https://www.wearedevelopers.com/magazine/751-how-we-built-a-worry-free-system-that-runs-for-10-years-and-what-we-d-do-again) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [The Overflow: Security and Privacy](https://www.wearedevelopers.com/magazine/715-the-overflow-security-and-privacy) - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers)