> Markdown version of [/jobs/ext/2282979-information-system-security-officer](https://www.wearedevelopers.com/jobs/ext/2282979-information-system-security-officer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Information System Security Officer - **Company:** Peraton Inc - **Location:** Washington, DC, United States - **Salary:** $135,000.0 - $216,000.0 - **Contract:** Permanent contract - **Skills:** CompTIA Security+, Cyber Security, Information Security Management, Information Technology Audit, Network Configuration and Change Management, Plan of Action and Milestones - **Published:** August 28, 2026 - **Apply:** https://www.clearancejobs.com/jobs/9124790/information-system-security-officer ## About the Role * Minimum of 12 years with BS/BA; Minimum of 10 years with MS/MA; Minimum of 7 years with Ph.D. and 16 years with a HS Diploma * Demonstrated experience as an Information System Security Officer (ISSO), Information System Security Manager (ISSM), Cybersecurity Analyst, Security Engineer, or comparable cybersecurity professional supporting federal or national security environments. * Strong working knowledge of the Risk Management Framework (RMF), security controls, security assessment activities, authorization processes, and continuous monitoring. * Experience supporting federal cybersecurity compliance, audit readiness, and Assessment & Authorization (A&A) activities. * Demonstrated ability to analyze cybersecurity requirements and translate them into standards, procedures, controls, and actionable recommendations. * Experience reviewing system changes, architectures, software, hardware, or network configurations from a cybersecurity and risk perspective. * Strong analytical, technical writing, documentation, and briefing skills. * Ability to work independently while coordinating effectively across multidisciplinary government and contractor teams. * Ability to operate effectively in a fast-paced environment where mission urgency and cybersecurity rigor must be balanced., * Experience supporting the Department of Energy. * Familiarity with DOE cybersecurity and Information Assurance policies and procedures. * Experience supporting classified or national security systems. * Familiarity with IC security policies, standards, and risk-management practices. * Relevant cybersecurity certifications such as CISSP, CISM, Security+, CAP, or equivalent credentials. ## Description The Information System Security Officer (ISSO) will provide cybersecurity, Information Assurance (IA), and Risk Management Framework (RMF) expertise across enterprise and mission-support environments. The ISSO will help strengthen security programs, maintain audit and Assessment & Authorization (A&A) readiness, manage cybersecurity risk, and ensure security decisions are technically sound, evidence-based, mission-aligned, and consistent with applicable requirements. The ideal candidate is a proactive security professional who can operate effectively in a mission-focused environment, translate complex cybersecurity requirements into actionable standards and controls, and collaborate with government stakeholders, system owners, engineers, vendors, and external partners., * Identify gaps across cybersecurity, intelligence, and mission-support requirements and proactively develop, refine, and document standards that strengthen Information Assurance and RMF programs. * Ensure new and revised standards are aligned with applicable DOE policy, IC direction, federal cybersecurity requirements, and organizational mission needs. * Support continuous improvement of security processes, controls, procedures, and governance mechanisms. * Translate policy and regulatory requirements into practical, implementable security guidance for technical and mission stakeholders. * Maintain strong traceability between security requirements, controls, assessments, findings, remediation activities, and authorization decisions. * Drive headquarters-level system audit readiness and RMF Assessment & Authorization (A&A) activities. * Coordinate the preparation, review, validation, and maintenance of security documentation and assessment evidence. * Support security control assessments, Plan of Action and Milestones (POA&M) management, risk determinations, remediation tracking, and authorization activities. * Identify deficiencies and provide actionable recommendations to system owners and leadership. * Support and coordinate incident response activities, ensuring appropriate escalation, documentation, containment, and follow-through. * Maintain awareness of emerging threats and vulnerabilities that could affect mission systems, personnel, data, or supporting infrastructure. * Support contingency planning, preparedness, testing, and continuous improvement activities. * Apply a proactive risk-reduction mindset to cybersecurity operations and recommend mitigations before issues become mission-impacting events. ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [Fireside Chat: AI and Sustainability - Thorsten Jonas](https://www.wearedevelopers.com/videos/1769-fireside-chat-ai-and-sustainability-thorsten-jonas) - [Organizational Change Through The Power Of Why - DevSecOps Enablement](https://www.wearedevelopers.com/videos/478-organizational-change-through-the-power-of-why-devsecops-enablement) - [Cyber Security: Small, and Large!](https://www.wearedevelopers.com/videos/259-cyber-security-small-and-large) - [Making Interactions Accessible to All Users](https://www.wearedevelopers.com/videos/649-making-interactions-accessible-to-all-users) ## Related Articles - [Best Paying Jobs in Technology](https://www.wearedevelopers.com/magazine/256-best-paying-jobs-in-technology) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again](https://www.wearedevelopers.com/magazine/751-how-we-built-a-worry-free-system-that-runs-for-10-years-and-what-we-d-do-again) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Software Engineer Career: Things You Should Know](https://www.wearedevelopers.com/magazine/143-software-engineer-career-things-you-should-know)