> Markdown version of [/jobs/ext/2294224-sr-isso](https://www.wearedevelopers.com/jobs/ext/2294224-sr-isso). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Sr ISSO - **Company:** BlueWater Federal Solutions - **Location:** Colorado Springs, CO, United States - **Experience:** Expert - **Salary:** $145,000.0 - $155,000.0 - **Contract:** Permanent contract - **Skills:** Cyber Security, Information Systems, Identity and Access Management, SC Clearance - **Published:** August 29, 2026 - **Apply:** https://jobs.localjobnetwork.com/apply/add/88186379/1 ## About the Role * Master's degree in a cyber-related field. * 10+ years of cybersecurity/information assurance experience. * Must have an active Secret Clearance * DoD 8570 IAM Level III Certification (e.g. CISSP, CISM, or GSLC) * Understanding of RMF and ATO processes. * Experience evaluating threats, vulnerabilities, and risks. ## Description * Prepare, deliver, and maintain comprehensive Authority to Operate (ATO) and RMF packages, ensuring successful lifecycle management of SEWS systems. * Develop, maintain, and manage Plans of Action and Milestones (POA&Ms) within the Enterprise Mission Assurance Support Service (eMASS) to track, mitigate, and remediate system vulnerabilities and non-compliant controls in accordance with National Institute of Standards and Technology Special Publication 800-53 Revision 5 (NIST SP 800-53r5). * Lead the Continuous Monitoring (ConMon) program to ensure security controls are regularly assessed, documented, and maintained in accordance with the Information System Continuous Monitoring (ISCM) strategy. * Support and coordinate internal and external security assessments, including the Cyber Operational Readiness Assessment (CORA), Security Control Assessor-Representative (SCA-R) audits, and Program Protection reviews. * Create, implement, and validate automated and manual Secure Technical Implementation Guide (STIG) and Security Requirements Guide (SRG) compliance workflows. * Analyze, triage, and ensure implementation compliance for Information Assurance Vulnerability Alerts (IAVAs), Cyber Tasking Orders (CTOs), Air Force Time Compliance Network Orders (TCNOs), Notice to Airmen (NOTAMs), and USCYBERCOM directives, ensuring proper tracking and mitigation reporting. * Lead cybersecurity incident response efforts, including investigating, reporting, and documenting cyber events. * Collaborate closely with the Cybersecurity Lead and Government stakeholders to implement robust mitigation activities and risk-reduction strategies. ## Related Videos - [Microservices? Monoliths? An Annoying Discussion!](https://www.wearedevelopers.com/videos/970-microservices-monoliths-an-annoying-discussion) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [What makes Cybersecurity different for critical infrastructure?](https://www.wearedevelopers.com/videos/571-what-makes-cybersecurity-different-for-critical-infrastructure) - [One Pipeline, Three Regulator - SBOM Compliance for the Developer](https://www.wearedevelopers.com/videos/100169-one-pipeline-three-regulator-sbom-compliance-for-the-developer) - [Giving AI eyes: How to build a dashboard you can't see](https://www.wearedevelopers.com/videos/100193-giving-ai-eyes-how-to-build-a-dashboard-you-can-t-see) ## Related Articles - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again](https://www.wearedevelopers.com/magazine/751-how-we-built-a-worry-free-system-that-runs-for-10-years-and-what-we-d-do-again) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking)