> Markdown version of [/jobs/ext/2413403-information-system-security-officer-isso](https://www.wearedevelopers.com/jobs/ext/2413403-information-system-security-officer-isso). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Information System Security Officer (ISSO) - **Company:** IBM - **Location:** Bethesda, MD, United States - **Experience:** Experienced - **Contract:** Permanent contract - **Skills:** Amazon Web Services, Microsoft Azure, Cloud Computing Security, Information Security Management, Software Vulnerability Management, Cloud Platform System, Plan of Action and Milestones, Vulnerability Analysis - **Published:** August 19, 2026 - **Apply:** https://dejobs.org/x/x/0A5C26CD02F046B4B7CB754ED0709C28/job/ ## About the Role Required technical and professional expertise * Demonstrated experience leading one or more systems through the entire Risk Management Framework (RMF) Authorization to Operate (ATO) process. * Must be a self-starter comfortable with leading and executing a high-priority, high-visibiilty task * Requires the ability to work independently, possess strong technical writing, communication, project management and problem-solving skills to successfully deliver authorization objectives * Must possess strong knowledge of NIST RMF, NIST SP 800-53 Rev. 5, DoD & IC authorization processes * Must possess Security+ certification * Must have experience with risk management, security control implementation, vulnerability management, continuous monitoring, and POA&M management * Must possess a TS/SCI CI Poly security clearance on day 1 Preferred technical and professional experience * Experience with National Reconnaissance Office (NRO) accreditation and authorization processes and procedures * 2+ years of experience supporting DoD IL4/IL5/IL6/IL7, or IC (ICD 503) authorization efforts. * 2+ years of experience supporting cloud environments (e.g., AWS GovCloud, Azure Government) and cloud security principles. * 2+ years of experience supporting independent security assessments (e.g., 3PAO, FedRAMP, DoD, or internal assessments). * 2+ years of experience leading cross-functional security initiatives, with CISSP and/or PMP certifications highly desirable ## Description As the ISSO, you will complete the planning, execution, and maintenance of system accreditation and authorization activities to achieve and sustain an Authority to Operate (ATO) in accordance with NIST RMF, DoD, IC and agency specific requirements. Serve as the primary security lead, responsible for activities for the security posture of the system to include working with the software and system architects to ensure the design meets security controls. Responsible for coordinating across cross-functional teams to develop and manage security documentation and perform assessment activities. Oversee risk management and continuous monitoring and ensuring implemented security controls meet compliance requirements. ## Related Videos - [Containers in the cloud - State of the Art in 2022](https://www.wearedevelopers.com/videos/410-containers-in-the-cloud-state-of-the-art-in-2022) - [One Pipeline, Three Regulator - SBOM Compliance for the Developer](https://www.wearedevelopers.com/videos/100169-one-pipeline-three-regulator-sbom-compliance-for-the-developer) - [Cloud Vendor Lock-In - Is it just a new version of the Database Abstraction Layers?](https://www.wearedevelopers.com/videos/1185-cloud-vendor-lock-in-is-it-just-a-new-version-of-the-database-abstraction-layers) - [Developer Tools for Microsoft Azure](https://www.wearedevelopers.com/videos/450-developer-tools-for-microsoft-azure) - [Hosting a modern justice system](https://www.wearedevelopers.com/videos/332-hosting-a-modern-justice-system) - [Reliable scalability: How Amazon.com scales on AWS](https://www.wearedevelopers.com/videos/983-reliable-scalability-how-amazon-com-scales-on-aws) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again](https://www.wearedevelopers.com/magazine/751-how-we-built-a-worry-free-system-that-runs-for-10-years-and-what-we-d-do-again) - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [Now is the time for industrialized software development](https://www.wearedevelopers.com/magazine/601-now-is-the-time-for-industrialized-software-development) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks)