> Markdown version of [/jobs/ext/2569675-information-systems-security-officer](https://www.wearedevelopers.com/jobs/ext/2569675-information-systems-security-officer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Information Systems Security Officer - **Company:** System One - **Location:** Anne Arundel County, MD, United States - **Salary:** $200,000.0 - **Contract:** Permanent contract - **Skills:** Xacta, Cyber Security, Information Systems, Software Vulnerability Management, Plan of Action and Milestones - **Published:** August 25, 2026 - **Apply:** https://dejobs.org/x/x/495B052D5F9D4661886F92A22BC6D6A8/job/ ## About the Role * Active TS/SCI with Polygraph * Experience in ISSO / Information Assurance / cybersecurity compliance in classified environments * Strong knowledge of RMF and the security authorization process (ATO) * Familiarity with: * NIST SP 800-53 (Rev 3 and/or Rev 5) * NIST SP 800-37 * Experience with compliance/configuration scanning and assessment workflows * Strong communication skills (written + verbal) and comfort working cross-functionally Tools/Platforms (Experience With) Experience with RMF/cyber compliance tools such as: * XACTA * LATTE / ART * BISCOTTI * WATCHCAT * STE (Experience with similar tools is also valuable.) Documentation You Should Be Comfortable With Hands-on experience developing/reviewing security documentation such as: * SSP, POA&M, SAR, RAR * CMP, CP, BIA * SPFs / exceptions and related artifacts * AARs and audit support documentation Preferred / Nice-to-Have * Prior support of classified government systems * Experience partnering with ISSMs, System Owners, Security Control Assessors, and Authorizing Officials * Familiarity with vulnerability remediation and system administration security concepts * Certifications like Security+, CISSP, CAP, CASP+, or CISM ## Description We're hiring an Information Systems Security Officer (ISSO) to support mission-critical, classified environments. In this role, you'll help ensure information systems stay compliant throughout the Risk Management Framework (RMF) lifecycle-supporting ATO packages, continuous monitoring, assessments, and audit readiness. You'll partner closely with technical teams and security stakeholders to drive secure, compliant system operations. What You'll Do (Key Responsibilities) * Support the full RMF lifecycle for classified information systems * Build and maintain security authorization packages and RMF documentation * Coordinate and support Authority to Operate (ATO) efforts * Perform/control security assessments, compliance reviews, and control validation * Track vulnerabilities, findings, and remediation activities (POA&Ms, etc.) * Support Continuous Monitoring (ConMon) and ongoing security activities * Review scan results/configurations to ensure alignment with security requirements * Work with system teams to implement/maintain required security controls * Participate in audits, inspections, and cybersecurity compliance reviews * Provide risk-based recommendations to improve security posture ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Microservices? Monoliths? An Annoying Discussion!](https://www.wearedevelopers.com/videos/970-microservices-monoliths-an-annoying-discussion) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [One Pipeline, Three Regulator - SBOM Compliance for the Developer](https://www.wearedevelopers.com/videos/100169-one-pipeline-three-regulator-sbom-compliance-for-the-developer) - [Giving AI eyes: How to build a dashboard you can't see](https://www.wearedevelopers.com/videos/100193-giving-ai-eyes-how-to-build-a-dashboard-you-can-t-see) - [Cyber Security: Small, and Large!](https://www.wearedevelopers.com/videos/259-cyber-security-small-and-large) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again](https://www.wearedevelopers.com/magazine/751-how-we-built-a-worry-free-system-that-runs-for-10-years-and-what-we-d-do-again) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [The Overflow: Security and Privacy](https://www.wearedevelopers.com/magazine/715-the-overflow-security-and-privacy) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks)