> Markdown version of [/jobs/ext/2296335-senior-isso](https://www.wearedevelopers.com/jobs/ext/2296335-senior-isso). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Senior ISSO - **Company:** Bart & Associates - **Location:** Washington, DC, United States - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** Cyber Security, Information Systems, Monitoring of Systems, Identity and Access Management, Information Security Management, Information Systems Security Architecture Professional, Nmap, Software Vulnerability Management, SC Clearance, Information Technology, Tenable Nessus, Splunk - **Published:** August 29, 2026 - **Apply:** https://www.clearancejobs.com/jobs/9036847/senior-isso ## About the Role * Minimum of 9 years of experience in computer science, cybersecurity, information assurance, or related IT fields. * At least 7 years of experience serving as an ISSO or ISSE within a cleared facility or classified environment. * Bachelor's degree in Computer Science, Information Technology, Cybersecurity, Business Management, or related discipline preferred. * Advanced degree in a related field preferred. * Experience supporting RMF, federal cybersecurity compliance, and continuous monitoring activities. * Experience working in classified government or DoD/Federal environments preferred., * Strong understanding of RMF, NIST standards, and federal cybersecurity compliance frameworks. * Experience using enterprise cybersecurity and vulnerability management tools including Tenable Nessus/Security Center, Splunk, IBM Guardium, NMAP and similar security assessment and monitoring tools. * Strong analytical and troubleshooting skills for identifying and mitigating cybersecurity risks. * Experience supporting system authorization and security assessment activities. * Ability to manage multiple systems and priorities in a fast-paced operational environment. * Excellent written and verbal communication skills. * Strong leadership, organizational, and task management abilities. * Ability to work collaboratively across technical and non-technical teams. Certifications * CISSP (Certified Information Systems Security Professional) * GISP (Global Information Security Professional) * CASP+ (CompTIA Advanced Security Practitioner) * Or equivalent certification meeting DoD 8570 IAM Level III requirements Security Clearance * Active Top-Secret clearance required * SCI eligibility may be required depending on assignment ## Description B&A is seeking a Senior ISSO who will be responsible for leading cybersecurity compliance and security operations activities supporting cleared federal information systems. This role serves as the primary Task Lead for assigned efforts while also providing ISSO support across additional systems as needed. The position requires strong expertise in RMF, vulnerability management, security assessment tools, and enterprise cybersecurity operations within classified environments. The ideal candidate possesses advanced knowledge of federal cybersecurity standards, hands-on experience supporting secure system operations, and the ability to lead cybersecurity initiatives in high-security mission environments. Responsibilities * Serve as Task Lead for assigned cybersecurity and information assurance activities. * Provide ISSO support for multiple classified systems and environments as required. * Support implementation and maintenance of RMF cybersecurity processes and documentation. * Conduct security analysis, vulnerability management, and compliance activities. * Utilize enterprise security tools to identify, assess, and remediate cybersecurity risks. * Monitor systems for security vulnerabilities and coordinate remediation efforts with technical teams. * Support system authorization activities, continuous monitoring, and audit readiness efforts. * Maintain and update cybersecurity documentation, policies, procedures, and security artifacts. * Coordinate with government stakeholders, system owners, and technical personnel to ensure compliance with federal cybersecurity requirements. * Provide technical guidance and mentorship to cybersecurity team members as needed. * Assist with incident response, security investigations, and risk mitigation activities. * Track and report cybersecurity status, risks, and remediation efforts to leadership., B&A has launched several programs to focus on employee engagement, wellness, and assistance. These include: * The B&A Cares program: 30/60/90-day wellness check ins, personal development, financial management, and stress management seminars, and more * A formal mentorship program * Job shadowing and cross training opportunities * Brand Ambassador program * Employee Assistance Program (EAP) - Access to various support resources to include counseling, legal guidance, financial planning, and more * Monthly teambuilding events * B&A Annual Wellness Challenges: #StepWithB&A, #WalkDuringLunchWithB&A, #VolunteeringWithB&A, #ExerciseDuringLunchWithB&A, and more At B&A, we place significant importance on improving the communities and lives of citizens across the nation through our involvement, technology expertise, and employees. B&A puts an emphasis on charitable efforts in the Northern Virginia area, including Capital Area Food Bank pantry drives, book donations, Hope for Henry Foundation events, and many more. In recognition of all these efforts, B&A has been named a Companies as Responsive Employers (CARE) award recipient by Northern Virginia Family Services and nominated by the Northern Virginia Chamber of Commerce for Outstanding Corporate Citizenship Award. ## Related Videos - [Our journey with Spring Boot in a microservice architecture](https://www.wearedevelopers.com/videos/511-our-journey-with-spring-boot-in-a-microservice-architecture) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [One Pipeline, Three Regulator - SBOM Compliance for the Developer](https://www.wearedevelopers.com/videos/100169-one-pipeline-three-regulator-sbom-compliance-for-the-developer) - [DevSecOps culture](https://www.wearedevelopers.com/videos/783-devsecops-culture) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again](https://www.wearedevelopers.com/magazine/751-how-we-built-a-worry-free-system-that-runs-for-10-years-and-what-we-d-do-again) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Best Paying Jobs in Technology](https://www.wearedevelopers.com/magazine/256-best-paying-jobs-in-technology) - [The Overflow: Security and Privacy](https://www.wearedevelopers.com/magazine/715-the-overflow-security-and-privacy)