> Markdown version of [/jobs/ext/2266939-information-system-security-officer-isso-senior](https://www.wearedevelopers.com/jobs/ext/2266939-information-system-security-officer-isso-senior). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Information System Security Officer (ISSO) - Senior - **Company:** NEUMA CONSULTING, LLC - **Location:** Washington, DC, United States - **Experience:** Expert - **Contract:** Temporary contract - **Skills:** Xacta, Agile Methodology, Audit Trail, Configuration Management, Extract Transform Load (ETL), DevOps, Elasticsearch, Identity and Access Management, Information Security Management, PostgreSQL, MongoDB, OpenShift, Role-Based Access Control, Redis, Virtual Machines, Software Vulnerability Management, Containerization, Gitlab-ci, Nessus, Splunk, Devsecops, Docker, Plan of Action and Milestones, Vulnerability Analysis - **Published:** August 27, 2026 - **Apply:** https://www.clearancejobs.com/jobs/9120773/information-system-security-officer-isso-senior ## About the Role * Education: Master's degree from an accredited college or university; or a Bachelor's degree from an accredited college or university plus an additional 2 years of related experience * Experience: Minimum 8 years of experience related to the specific labor category (minimum 10 years with a Bachelor's degree) * Active TS/SCI clearance (recent CI Polygraph strongly preferred) * Mandatory: RMF and NIST SP 800-53 expertise; hands-on experience developing and maintaining SSPs, POA&Ms, and full authorization packages; experience with vulnerability management tools and interpreting scan results * DoD 8140/8570 IAM Level II compliant certification (e.g., Security+, CGRC/CAP, CISSP, CISM) * Experience supporting assessment and authorization in DoD or Intelligence Community environments (ICD 503 experience strongly preferred) * Experience with continuous monitoring, STIG compliance, and audit log review * Experience working within collaborative, cross-functional Agile teams * Strong technical writing, leadership, and communication skills * Comprehensive knowledge across key tasks and high-impact assignments, with the ability to plan and lead major technology assignments, evaluate performance results, recommend changes affecting project growth and success, and function as a technical expert across multiple project assignments * Highly Desired: CISSP or CGRC, XACTA or eMASS experience, JWICS experience, container/OpenShift security, cross-domain solution (CDS) experience, Splunk, experience supporting DevSecOps pipelines and automating compliance evidence collection * 100% onsite Reston, VA or JB Anacostia-Bolling, Washington, DC ## Description Neuma Consulting is hiring a Senior Information System Security Officer (ISSO) to support the Defense Intelligence Agency (DIA) on a recently awarded 5-year contract, offering long-term stability and a central role in keeping the EPD application ecosystem authorized, monitored, and mission-ready. The EPD environment spans shared enterprise services, cross-domain data movement, and a flagship application used across the Intelligence Community-all while the platform migrates from virtual machines to a fully containerized architecture. As the systems evolve, you will own the security authorization and continuous monitoring that keep them operating, serving as the day-to-day security lead and the primary interface between our engineering teams and the government security stakeholders. What You'll Do * Serve as ISSO for assigned EPD systems, executing assessment and authorization activities under the Risk Management Framework (RMF) in accordance with ICD 503 and NIST SP 800-53 * Develop and maintain the full security authorization package: System Security Plans (SSPs), security assessment support, contingency plans, incident response plans, configuration management plans, and POA&Ms * Manage the POA&M lifecycle-track findings, coordinate remediation with developers and DevOps, validate closure, and report status to the ISSM and government stakeholders * Run continuous monitoring: review vulnerability scans, audit logs, and STIG/configuration compliance across VM and containerized environments; report deviations and drive fixes * Maintain system records and artifacts in the customer's governance tool of record (e.g., XACTA/eMASS) * Perform security impact analyses for system changes-including the VM-to-container migration and cross-domain (high-to-low) transfer processes-and participate in change control boards * Support security assessments and audits; prepare evidence and coordinate assessor engagement * Lead incident response coordination for assigned systems, including reporting per DIA requirements * Advise engineering teams on classification handling, need-to-know (NTK) enforcement, least privilege, and secure configuration * Review server logs and consoles onsite to support security triage of production issues Environment: JWICS, RMF/ICD 503, NIST SP 800-53, XACTA/eMASS, ACAS/Nessus, STIGs, Splunk, GitLab CI Pipelines, Docker, OpenShift, MongoDB, PostgreSQL, Redis, Elasticsearch A Great Fit If You: are equally comfortable writing an SSP the government will scrutinize and sitting with engineers to walk through a scan finding, want your compliance work tied to systems the IC actually uses every day, and have experience securing systems through major architecture transitions. Because the EPD systems exist on JWICS and the work is hands-on in the SCIF, a recent CI Poly is strongly preferred to enable onsite work from day one. ## Related Videos - [Reducing LLM Calls with Vector Search Patterns - Raphael De Lio (Redis)](https://www.wearedevelopers.com/videos/1714-reducing-llm-calls-with-vector-search-patterns-raphael-de-lio-redis) - [Organizational Change Through The Power Of Why - DevSecOps Enablement](https://www.wearedevelopers.com/videos/478-organizational-change-through-the-power-of-why-devsecops-enablement) - [Accelerating Authentication Architecture: Taking Passwordless to the Next Level](https://www.wearedevelopers.com/videos/733-accelerating-authentication-architecture-taking-passwordless-to-the-next-level) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [DevSecOps culture](https://www.wearedevelopers.com/videos/783-devsecops-culture) - [Event based cache invalidation in GraphQL](https://www.wearedevelopers.com/videos/433-event-based-cache-invalidation-in-graphql) ## Related Articles - [How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again](https://www.wearedevelopers.com/magazine/751-how-we-built-a-worry-free-system-that-runs-for-10-years-and-what-we-d-do-again) - [Best Paying Jobs in Technology](https://www.wearedevelopers.com/magazine/256-best-paying-jobs-in-technology) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [The Overflow: Security and Privacy](https://www.wearedevelopers.com/magazine/715-the-overflow-security-and-privacy) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [What’s the Difference between a Junior, Mid, and Senior Developer?](https://www.wearedevelopers.com/magazine/238-what-s-the-difference-between-a-junior-mid-and-senior-developer)