> Markdown version of [/jobs/ext/2603461-information-systems-security-officer-isso](https://www.wearedevelopers.com/jobs/ext/2603461-information-systems-security-officer-isso). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Information Systems Security Officer (ISSO) - **Company:** General Dynamics Information Technology - **Location:** Springfield, VA, United States - **Experience:** Expert - **Salary:** $111,155.0 - $150,385.0 - **Contract:** Permanent contract - **Skills:** Cyber Security, Information Systems, Monitoring of Systems, Data Logging, Information Technology, Splunk, Vulnerability Analysis - **Published:** August 13, 2026 - **Apply:** https://www.techcareers.com/job.asp?id=3351754115&tx=JJ9185FFQ&pt=1&aff=0B19D771-A501-4A5E-8338-2A822B784D54&utm_source=Job%20Feed&utm_medium=textkernel&utm_campaign=DE&utm_term=0B19D771-A501-4A5E-8338-2A822B784D54 ## About the Role Classified Networks,Cybersecurity Compliance,DISA STIG,ISSO,RMF, 8 + years of related experience, * Active TS/SCI clearance with CI Polygraph * Bachelor's degree in an IT-related field, or 10+ years of relevant IT experience in lieu of a degree * Meet DoD 8140 Information Assurance Workforce certification requirements (e.g. Security+ CE) * Hands-on experience performing ISSO functions under the Risk Management Framework (RMF) * Strong understanding of NIST SP 80037, 80053, CNSSI 1253, and FISMA-aligned security practices * Experience managing authorization package documentation, vulnerability assessments, and STIG compliance * Ability to evaluate system risks, track remediation, and coordinate security efforts across engineering and operations teams * Familiarity with enterprise security logging tools (e.g., Splunk) and vulnerability monitoring tools * Strong communication, documentation, and collaboration skills * LOCATION: Onsite ## Description As an Information Systems Security Officer (ISSO) supporting enterprise infrastructure services, you will safeguard critical information systems across multiple classified network domains. You will manage the full security lifecycle for assigned systems, ensure continuous compliance with cybersecurity standards, and help maintain resilient and secure mission enabling technologies. Your work strengthens system readiness, reduces risk, and ensures secure operations across globally distributed environments., * Serve as the primary cybersecurity advisor on system security posture, threats, vulnerabilities, and compliance requirements * Maintain and update security authorization packages, documentation, and baseline artifacts throughout the system lifecycle * Ensure systems retain active Authority to Operate (ATO) through continuous monitoring, updates, and alignment with security policies * Develop and manage POA&Ms, risk acceptance requests, waivers, and exceptions for identified vulnerabilities * Perform periodic system reviews, update security controls, and coordinate required security-driven configuration changes * Audit system logs and monitors outputs to identify compliance issues or abnormal activity and coordinate remediation * Oversee secure system recovery, validating restoration of approved security configurations * Manage system decommissioning activities, ensuring secure sanitization and proper documentation * Collaborate with engineers, system owners, and technical teams to validate controls and support accreditation updates ## Related Videos - [Our journey with Spring Boot in a microservice architecture](https://www.wearedevelopers.com/videos/511-our-journey-with-spring-boot-in-a-microservice-architecture) - [Crypto-secure Data Management with In-Database Blockchain](https://www.wearedevelopers.com/videos/632-crypto-secure-data-management-with-in-database-blockchain) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [One Pipeline, Three Regulator - SBOM Compliance for the Developer](https://www.wearedevelopers.com/videos/100169-one-pipeline-three-regulator-sbom-compliance-for-the-developer) - [Cyber Security: Small, and Large!](https://www.wearedevelopers.com/videos/259-cyber-security-small-and-large) ## Related Articles - [How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again](https://www.wearedevelopers.com/magazine/751-how-we-built-a-worry-free-system-that-runs-for-10-years-and-what-we-d-do-again) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Best Paying Jobs in Technology](https://www.wearedevelopers.com/magazine/256-best-paying-jobs-in-technology) - [Dev Digest 216: CyberSec + Mythos, Stack Overflow for Agents & DOOM in TTF](https://www.wearedevelopers.com/magazine/728-dev-digest-216-cybersec-mythos-stack-overflow-for-agents-doom-in-ttf) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing)