> Markdown version of [/jobs/ext/2237763-information-system-security-officer-isso](https://www.wearedevelopers.com/jobs/ext/2237763-information-system-security-officer-isso). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Information System Security Officer (ISSO) - **Company:** CCS, LLC - **Location:** Vienna, VA, United States - **Experience:** Experienced - **Salary:** $110,000.0 - $125,000.0 - **Contract:** Permanent contract - **Skills:** Cyber Security, Information Security Management, Software Vulnerability Management, Information Security Management System, Information Technology - **Published:** August 26, 2026 - **Apply:** https://www.clearancejobs.com/jobs/9117814/information-system-security-officer-isso ## About the Role * 3-5 years Cybersecurity experience * Working knowledge and experience with CSAM and the NIST RMF * Solid knowledge of the process to obtain a system ATO and requirements to maintain the ATO * Experience working with system stakeholders to assess and manage system cybersecurity risk * Ability to synthesize complex IT system information and communicate system status and requirements in written products and verbal presentations * Ability to write clear, concise and effective security control implementation statements * Familiarity with configuration settings and vulnerability management analysis of infrastructure devices * Ability to draft a complete ATO package, to include the SSP * Ability to work independently, and efficiently, with minimal direct supervision, and within given timelines Required - Professional Certification(s): Security+ Formal Education: HS Diploma Years of Professional Experience: Minimum 3-5 Desired Skills & Experience * BS in Computer Science, Information Technology, or related field * CISSP, Security+, CGRC (formerly CAP), CISM Required Technical/Business Tools Experience * CSAM GRC Tool * DHS experience Physical Requirements * Ability to work onsite at customer HQ 1-2 times per week ## Description * Role Overview: The Information Systems Security Officer (ISSO) conducts research, develops, implements, tests, and reviews an organization's information security to protect information and prevent unauthorized access. Emphasis on general knowledge of infrastructure devices (i.e. firewalls, routers, switches)., o Conduct initial Security Assessment and obtain system Authorization to Operate (ATO), in line with NIST SP 800-37 Rev. 2. o Maintain the Security Authorization or ATO of assigned system(s) o Continuously update all Security Authorization documentation to maintain assigned system's ATO or system go-live dates. o Select the baseline security controls for the IT system, using the CSAM Governance, Risk, and Compliance (GRC) Tool, and tailor controls where appropriate. o Document all relevant NIST 800-53 Security Controls for assigned IT systems in the System Security Plan (SSP). o Perform and document initial and annual risk self-assessments of all systems assigned o Develop and document all supporting Security A&A artifacts (i.e., PTA, SSP, ITCP, BIA, CMP, MOU, ISA). o Produce Security Authorization package for Authorizing Official (AO) signature including ATO o Track the deployment of software to the environment that is not part of the base image. o Conduct security impact analyses of proposed changes, provide recommendations. o Ability to analyze configuration settings, implementation of STIGs, and conducting manual checklists. o Generate and manage Plan of Action & Milestones (POA&Ms), with meaningful milestones, and clear/concise implementation statements for each non-compliant control for assigned IT Systems. ## Related Videos - [Don't Be A Naive Developer: How To Avoid Basic Cybersecurity Mistakes](https://www.wearedevelopers.com/videos/498-don-t-be-a-naive-developer-how-to-avoid-basic-cybersecurity-mistakes) - [One Pipeline, Three Regulator - SBOM Compliance for the Developer](https://www.wearedevelopers.com/videos/100169-one-pipeline-three-regulator-sbom-compliance-for-the-developer) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [Enabling intelligent logistics automation: home-grown Industrial IoT platform at Austrian Post](https://www.wearedevelopers.com/videos/2018-enabling-intelligent-logistics-automation-home-grown-industrial-iot-platform-at-austrian-post) - [You can’t hack what you can’t see](https://www.wearedevelopers.com/videos/41-you-can-t-hack-what-you-can-t-see) - [Better Together: Leveraging Your Observability Tools as a SIEM](https://www.wearedevelopers.com/videos/2118-better-together-leveraging-your-observability-tools-as-a-siem) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again](https://www.wearedevelopers.com/magazine/751-how-we-built-a-worry-free-system-that-runs-for-10-years-and-what-we-d-do-again) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Best Paying Jobs in Technology](https://www.wearedevelopers.com/magazine/256-best-paying-jobs-in-technology) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities)