> Markdown version of [/jobs/ext/2563551-senior-information-system-security-officer-isso](https://www.wearedevelopers.com/jobs/ext/2563551-senior-information-system-security-officer-isso). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Senior Information System Security Officer (ISSO) - **Company:** ASRC Federal Holding Company - **Location:** Reston, VA, United States - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** Cloud Computing Security, Configuration Management, Cyber Security, Federal Information Processing Standards (FIPS), Information Security Management, Information Systems Security Architecture Professional, Networx, Software Vulnerability Management, Information Technology, Devsecops, Security Orchestration, Automation & Response - **Published:** August 1, 2026 - **Apply:** https://dejobs.org/x/x/83B5915F04624FACA6F6CE88160FEF75/job/ ## About the Role * Bachelor's degree in Cybersecurity, Information Assurance, Computer Science, Information Technology, or a related field. * Minimum 5-7 years of experience supporting information assurance, cybersecurity, RMF, or information system security, or an equivalent combination of education and experience. * Experience supporting federal cybersecurity programs and the NIST Risk Management Framework (RMF). * Experience developing and maintaining RMF documentation, authorization packages, and Governance, Risk, and Compliance (GRC) tools. * Strong knowledge of NIST SP 800-37, NIST SP 800-53, FISMA, FIPS 199, and federal privacy requirements. * Experience supporting Authorization to Operate (ATO), Continuous ATO (cATO), or Continuous Authorization efforts. * Strong analytical, communication, documentation, and stakeholder engagement skills. Required Certifications * Certified Information Systems Security Professional (CISSP) * Certified in Governance, Risk and Compliance (CGRC) or Certified Cloud Security Professional (CCSP) Preferred Qualifications * Experience supporting U.S. federal civilian agencies, preferably the USPTO. * Experience with continuous monitoring, vulnerability management, and security automation. * Familiarity with cloud security, DevSecOps, and continuous authorization initiatives. * Knowledge of privacy compliance activities, including Privacy Threshold Assessments (PTAs), Privacy Impact Assessments (PIAs), and System of Records Notices (SORNs). ## Description ASRC Federal Data Networx is seeking a Senior Information System Security Officer (ISSO) to support federal cybersecurity and Risk Management Framework (RMF) activities for enterprise information systems. The ISSO serves as the primary cybersecurity and privacy advisor to System Owners (SOs), ensuring security and privacy requirements are integrated throughout the system lifecycle while maintaining compliance with federal regulations and Authorization to Operate (ATO) requirements., * Serve as the primary cybersecurity and privacy advisor to System Owners for assigned systems. * Lead RMF activities, including development and maintenance of System Security and Privacy Plans (SSPPs), authorization packages, risk documentation, and supporting artifacts. * Ensure systems maintain Authorization to Operate (ATO) through assessment support, continuous monitoring, and compliance with NIST RMF, FISMA, and federal security requirements. * Assess security risks, validate security controls, and coordinate remediation of vulnerabilities and Plans of Action and Milestones (POA&Ms). * Maintain system inventories, security documentation, contingency plans, configuration management plans, and privacy documentation. * Collaborate with ISSMs, System Owners, Security Control Assessors, and technical teams to integrate security throughout the system lifecycle. * Monitor system security posture, review vulnerability and compliance scan results, and support continuous authorization initiatives. * Provide cybersecurity guidance, develop security policies and procedures, and deliver security awareness training. * Support security engineering, certification and accreditation activities, and implementation of security controls across systems. * Recommend process improvements and automation opportunities to enhance RMF and cybersecurity operations. ## Related Videos - [One Pipeline, Three Regulator - SBOM Compliance for the Developer](https://www.wearedevelopers.com/videos/100169-one-pipeline-three-regulator-sbom-compliance-for-the-developer) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [DevSecOps: Injecting Security into Mobile CI/CD Pipelines](https://www.wearedevelopers.com/videos/273-devsecops-injecting-security-into-mobile-ci-cd-pipelines) - [DevSecOps culture](https://www.wearedevelopers.com/videos/783-devsecops-culture) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [DevSecOps: Security in DevOps](https://www.wearedevelopers.com/videos/36-devsecops-security-in-devops) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [The Overflow: Security and Privacy](https://www.wearedevelopers.com/magazine/715-the-overflow-security-and-privacy) - [How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again](https://www.wearedevelopers.com/magazine/751-how-we-built-a-worry-free-system-that-runs-for-10-years-and-what-we-d-do-again) - [Best Paying Jobs in Technology](https://www.wearedevelopers.com/magazine/256-best-paying-jobs-in-technology) - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers)