> Markdown version of [/jobs/ext/2617408-information-system-security-officer](https://www.wearedevelopers.com/jobs/ext/2617408-information-system-security-officer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Information System Security Officer - **Company:** INADEV Corporation - **Location:** Reston, VA, United States - **Experience:** Expert - **Salary:** $200,000.0 - $220,000.0 - **Contract:** Permanent contract - **Skills:** Amazon Web Services, Cloud Computing, Information Security Management, CIS Benchmarks, Devsecops, Security Orchestration, Automation & Response, Plan of Action and Milestones - **Published:** August 3, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=bb3336e85420ff22 ## About the Role * Must be a U.S. Citizen. * Must be willing to work a HYRBID Schedule (2 Days) in Reston, VA & client locations in the Washington D.C. area as required. * Ability to pass a 7-year background check and obtain/maintain a U.S. Government Clearance * Strong communication and presentation skills. * Must be able to prioritize and self-start. * Must be adaptable/flexible as priorities shift. * Must be enthusiastic and have passion for learning and constant improvement. * Must be open to collaboration, feedback and client asks. * Must enjoy working with a vibrant team of outgoing personalities., * CISSP, CAP, or equivalent security certification * 5+ years of information system security / ISSO experience * Strong knowledge of RMF, NIST 800-53, and federal ATO processes * Experience with continuous monitoring and POA&M management Preferred Qualifications: * FedRAMP and cloud (AWS) security experience * Financial-regulatory security experience * Experience with security automation and GRC tooling ## Description The Information System Security Officer (ISSO) is responsible for maintaining the security posture and authorization of the system. You will manage the Risk Management Framework (RMF) lifecycle, maintain ATO documentation and continuous-monitoring artifacts, and ensure the system remains compliant with NIST 800-53 and federal security requirements., * Maintain the system's Risk Management Framework (RMF) documentation and ATO package * Manage security control implementation evidence against NIST 800-53 / FedRAMP * Track and remediate findings via POA&Ms and coordinate continuous monitoring * Support security assessments, audits, and authorization activities * Coordinate with the client ISSM, security teams, and DevSecOps on compliance * Review changes for security impact and maintain security baselines * Report security posture, risks, and incidents to program and client stakeholders PHYSICAL DEMANDS: * Reasonable accommodations may be made to enable individuals with disabilities to perform the essential functions Inadev Corporation does not discriminate against qualified individuals based on their status as protected veterans or individuals with disabilities and prohibits discrimination against all individuals based on their race, color, religion, sex, sexual orientation/gender identity, or national origin INTEGRITY AND COMPLIANCE NOTICE: All information provided by applicants must be complete, truthful, and accurate. Any intentional misrepresentation of skills, experience, credentials, or identity may result in removal from consideration for this and future employment opportunities. For positions supporting U.S. federal government contracts, applicants may be subject to background investigations and employment eligibility verification in accordance with federal regulations. Providing false information during this process may be subject to review and action as required under applicable federal laws and security regulations. Inadev is proud to be an Equal Opportunity Employer and a federal contractor committed to compliance with all applicable EEO, OFCCP, and federal hiring standards. ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [DevSecOps: Injecting Security into Mobile CI/CD Pipelines](https://www.wearedevelopers.com/videos/273-devsecops-injecting-security-into-mobile-ci-cd-pipelines) - [Green Cloud Computing](https://www.wearedevelopers.com/videos/592-green-cloud-computing) - [A practical guide to writing secure Dockerfiles](https://www.wearedevelopers.com/videos/109-a-practical-guide-to-writing-secure-dockerfiles) - [DevSecOps culture](https://www.wearedevelopers.com/videos/783-devsecops-culture) - [DevSecOps: Security in DevOps](https://www.wearedevelopers.com/videos/36-devsecops-security-in-devops) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Now is the time for industrialized software development](https://www.wearedevelopers.com/magazine/601-now-is-the-time-for-industrialized-software-development) - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing)