Information Systems Security Officer

System One
Anne Arundel County, MD, United States
11 days ago
Apply on dejobs.org
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Compensation
$200,000.0
Working hours
Regular working hours
Job source

Tech stack

Xacta Cyber Security Information Systems Software Vulnerability Management Plan of Action and Milestones

Job description

We’re hiring an Information Systems Security Officer (ISSO) to support mission-critical, classified environments. In this role, you’ll help ensure information systems stay compliant throughout the Risk Management Framework (RMF) lifecycle-supporting ATO packages, continuous monitoring, assessments, and audit readiness. You’ll partner closely with technical teams and security stakeholders to drive secure, compliant system operations.

What You’ll Do (Key Responsibilities)

  • Support the full RMF lifecycle for classified information systems
  • Build and maintain security authorization packages and RMF documentation
  • Coordinate and support Authority to Operate (ATO) efforts
  • Perform/control security assessments, compliance reviews, and control validation
  • Track vulnerabilities, findings, and remediation activities (POA&Ms, etc.)
  • Support Continuous Monitoring (ConMon) and ongoing security activities
  • Review scan results/configurations to ensure alignment with security requirements
  • Work with system teams to implement/maintain required security controls
  • Participate in audits, inspections, and cybersecurity compliance reviews
  • Provide risk-based recommendations to improve security posture

Requirements

  • Active TS/SCI with Polygraph
  • Experience in ISSO / Information Assurance / cybersecurity compliance in classified environments
  • Strong knowledge of RMF and the security authorization process (ATO)
  • Familiarity with:
  • NIST SP 800-53 (Rev 3 and/or Rev 5)
  • NIST SP 800-37
  • Experience with compliance/configuration scanning and assessment workflows
  • Strong communication skills (written + verbal) and comfort working cross-functionally Tools/Platforms (Experience With)

Experience with RMF/cyber compliance tools such as:

  • XACTA
  • LATTE / ART
  • BISCOTTI
  • WATCHCAT
  • STE (Experience with similar tools is also valuable.) Documentation You Should Be Comfortable With

Hands-on experience developing/reviewing security documentation such as:

  • SSP, POA&M, SAR, RAR
  • CMP, CP, BIA
  • SPFs / exceptions and related artifacts
  • AARs and audit support documentation Preferred / Nice-to-Have

  • Prior support of classified government systems
  • Experience partnering with ISSMs, System Owners, Security Control Assessors, and Authorizing Officials
  • Familiarity with vulnerability remediation and system administration security concepts
  • Certifications like Security+, CISSP, CAP, CASP+, or CISM

Benefits & conditions

System One, and its subsidiaries including Joulé, ALTA IT Services, CM Access, TPGS, and MOUNTAIN, LTD., are leaders in delivering workforce solutions and integrated services across North America. We help clients get work done more efficiently and economically, without compromising quality. System One not only serves as a valued partner for our clients, but we offer eligible full-time employees health and welfare benefits coverage options including medical, dental, vision, spending accounts, life insurance, voluntary plans, as well as participation in a 401(k) plan.

About the company

System One, and its subsidiaries including Joulé and Mountain Ltd., are leaders in delivering outsourced services and workforce solutions across North America. We help clients get work done more efficiently and economically, without compromising quality. System One not only serves as a valued partner for our clients, but we offer eligible employees health and welfare benefits coverage options including medical, dental, vision, spending accounts, life insurance, voluntary plans, as well as participation in a 401(k) plan.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on dejobs.org
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

59 sec

Proving regulatory compliance to auditors and chief officers

Mike Bursell Mike Bursell · World Congress 2026 Europe

4:11 min

Introduction to cloud-native application developer security

Micah Silverman · World Congress 2022

5:51 min

Transitioning to continuous security operations and automated system hardening

Thomas Fuchs +3 · LIVE

2:28 min

Preventing sensitive information disclosure in RAG systems

Deepu Deepu · World Congress 2025

3:44 min

Current industry adoption and future security initiatives

Alexander Allmendinger · LIVE

1:13 min

Structuring a comprehensive corporate security organization

Eileen Uchitelle Eileen Uchitelle +1 · Coffee With Developers

Videos

See all

Related articles

See all