> Markdown version of [/jobs/ext/2502172-senior-information-system-security-officer-isso](https://www.wearedevelopers.com/jobs/ext/2502172-senior-information-system-security-officer-isso). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Senior Information System Security Officer (ISSO) - **Company:** ShorePoint, Inc - **Location:** Albuquerque, NM, United States - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** Databases, Information Security Management, Plan of Action and Milestones - **Published:** August 2, 2026 - **Apply:** https://www.clearancejobs.com/jobs/9074890/senior-information-system-security-officer-isso ## About the Role We are seeking an experienced Senior Information System Security Officer (ISSO) to drive Risk Management Framework (RMF) activities, security documentation, control validation, and ongoing compliance efforts across assigned enterprise systems. The ideal candidate will possess deep experience managing authorization packages, executing continuous monitoring strategies, and leading corrective action tracking in a federal environment. The Sr. ISSO role takes full ownership of maintaining system security plans, updating risk databases, and directing remediation actions with technical and operational stakeholders. This is a unique opportunity to shape the growth, development and culture of an exciting and fast-growing company in the cybersecurity market. Employment for this position is dependent on the successful award of the contract., * Strong experience as an ISSO or RMF lead in a federal cybersecurity environment. * Familiarity with ATO processes, continuous monitoring, POA&M lifecycle management, and security documentation requirements. * Strong organizational and documentation skills. * Ability to coordinate effectively with government stakeholders and technical staff. * Strong understanding of cybersecurity controls, risk management, and compliance practices. Must have's: * Bachelor's degree from an accredited university; a postgraduate degree from an accredited university may substitute for 6 years of experience. * 10+ years of relevant work experience. * Proven ability to analyze complex requirements and translate them into clear, actionable tasks and processes through critical thinking. * Applicants must currently be a U.S. citizen and eligible to obtain and maintain a security clearance, in compliance with federal contract requirements. Beneficial to have: * Active DOE Q or equivalent DoD Top Secret clearance. ## Description * Lead the development, review, and maintenance of system security plans, risk assessments, and related authorization artifacts. * Drive continuous monitoring activities and conduct rigorous validation of implemented security controls across complex environments. * Develop or support Plans of Action and Milestones (POA&Ms), directing remediation activities with technical and operational stakeholders to ensure timely deficiency resolution. * Execute system self-assessments and lead the systematic collection and verification of compliance evidence for authorization reviews. * Manage enterprise asset, vulnerability, and compliance information within designated governance and risk tools. * Ensure documentation quality, completeness, and alignment with federal and organizational requirements. ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Kubernetes and Microservices with Multi-Model Databases](https://www.wearedevelopers.com/videos/382-kubernetes-and-microservices-with-multi-model-databases) - [Beyond the Numbers: Engineering Recruiting Excellence Through Quality, Data, and Team Empowerment](https://www.wearedevelopers.com/videos/1491-beyond-the-numbers-engineering-recruiting-excellence-through-quality-data-and-team-empowerment) - [Don't Be A Naive Developer: How To Avoid Basic Cybersecurity Mistakes](https://www.wearedevelopers.com/videos/498-don-t-be-a-naive-developer-how-to-avoid-basic-cybersecurity-mistakes) - [You can’t hack what you can’t see](https://www.wearedevelopers.com/videos/41-you-can-t-hack-what-you-can-t-see) - [Organizational Change Through The Power Of Why - DevSecOps Enablement](https://www.wearedevelopers.com/videos/478-organizational-change-through-the-power-of-why-devsecops-enablement) ## Related Articles - [How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again](https://www.wearedevelopers.com/magazine/751-how-we-built-a-worry-free-system-that-runs-for-10-years-and-what-we-d-do-again) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [The Overflow: Security and Privacy](https://www.wearedevelopers.com/magazine/715-the-overflow-security-and-privacy) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks)