> Markdown version of [/jobs/ext/2488128-senior-information-system-security-officer-isso](https://www.wearedevelopers.com/jobs/ext/2488128-senior-information-system-security-officer-isso). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Senior Information System Security Officer (ISSO) - **Company:** ERP International - **Location:** Laurel, MD, United States - **Experience:** Expert - **Salary:** $145,000.0 - $185,000.0 - **Contract:** Permanent contract - **Skills:** Cloud Computing Security, Cyber Security, Information Systems, Information Security Management, Zero Trust Network Access, Software Vulnerability Management, Enterprise Software Applications, SARS Software Products, HybridCloud, Information Technology, Security Orchestration, Automation & Response, Plan of Action and Milestones - **Published:** August 11, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=880a035629aaa6ec ## About the Role * Bachelor's degree in Cybersecurity, Information Systems, Computer Science, Engineering, or related field. * 5+ years of cybersecurity experience supporting federal, healthcare, defense, or highly regulated environments. * 3+ years serving as an ISSO, Information Security Specialist, Security Analyst, Security Engineer, or similar role. * Experience supporting NIST Risk Management Framework (RMF) activities. * Experience with: * + NIST SP 800-53 + NIST SP 800-37 + FISMA compliance + Continuous Monitoring + Security Control Assessments + POA&M Management * Experience developing security documentation and compliance artifacts. * Strong written and verbal communication skills., * Experience supporting enterprise cybersecurity programs. * Experience working in cloud or hybrid-cloud environments. * Experience supporting audit readiness activities. * Experience working with security automation and vulnerability management platforms. * Experience supporting Zero Trust initiatives. * Experience supporting large-scale digital modernization efforts. Preferred Certifications One or more of the following: * CISSP * CGRC (formerly CAP) * CISM * CRISC * Security+ * CEH * GSEC * GSLC Desired Skills * Cybersecurity Governance * Risk Management * Continuous Monitoring * Vulnerability Management * Security Assessments * Compliance Monitoring * Security Documentation * Executive Reporting * Audit Readiness * Incident Response * Cloud Security * Security Architecture * Privacy Compliance Clearance Requirements: * Must be able to obtain a government publc trust Clearance/background check ## Description ERP International, LLC (www.erpinternational.com) is currently seeking a Full Time Information System Security Officer (ISSO) to support cybersecurity, privacy, risk management, and compliance initiatives for large-scale federal information systems and enterprise technology environments. Qualified candidates are urged to apply to learn more about this great opportunity! The selected candidate will serve as a trusted cybersecurity advisor responsible for supporting the security authorization lifecycle, ensuring compliance with federal security requirements, conducting risk assessments, supporting continuous monitoring activities, and collaborating with technical and business stakeholders to strengthen organizational security posture. This position is ideal for professionals with experience supporting federal civilian agencies, healthcare organizations, or other highly regulated environments that require rigorous security, privacy, and compliance oversight., Security Authorization & Compliance * Support the implementation and execution of the NIST Risk Management Framework (RMF). * Develop, review, and maintain security authorization documentation including: * + System Security Plans (SSPs) + Security Assessment Reports (SARs) + Plans of Action and Milestones (POA&Ms) + Contingency Plans + Security and privacy supporting artifacts * Support system authorization, reauthorization, and continuous authorization activities. * Ensure compliance with applicable federal cybersecurity and privacy requirements. Risk Management & Continuous Monitoring * Perform cybersecurity risk assessments and control analyses. * Monitor security posture through continuous monitoring activities. * Track vulnerabilities, remediation activities, and corrective action plans. * Support security reporting and risk communication activities. * Identify control deficiencies and recommend mitigation strategies. Governance & Stakeholder Engagement * Participate in security governance forums and technical reviews. * Coordinate with system owners, engineers, developers, operations teams, and security personnel. * Provide cybersecurity guidance to government and contractor stakeholders. * Support audit readiness, compliance reviews, and independent assessments. * Develop executive briefings, status reports, and cybersecurity metrics. Security Operations Support * Assist with incident response coordination and post-incident reviews. * Support security control testing and validation efforts. * Evaluate proposed system changes for cybersecurity impacts. * Participate in contingency planning and continuity activities. ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Microservices? Monoliths? An Annoying Discussion!](https://www.wearedevelopers.com/videos/970-microservices-monoliths-an-annoying-discussion) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [One Pipeline, Three Regulator - SBOM Compliance for the Developer](https://www.wearedevelopers.com/videos/100169-one-pipeline-three-regulator-sbom-compliance-for-the-developer) - [Giving AI eyes: How to build a dashboard you can't see](https://www.wearedevelopers.com/videos/100193-giving-ai-eyes-how-to-build-a-dashboard-you-can-t-see) - [Cyber Security: Small, and Large!](https://www.wearedevelopers.com/videos/259-cyber-security-small-and-large) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again](https://www.wearedevelopers.com/magazine/751-how-we-built-a-worry-free-system-that-runs-for-10-years-and-what-we-d-do-again) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [The Overflow: Security and Privacy](https://www.wearedevelopers.com/magazine/715-the-overflow-security-and-privacy) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Now is the time for industrialized software development](https://www.wearedevelopers.com/magazine/601-now-is-the-time-for-industrialized-software-development)