> Markdown version of [/jobs/ext/2634682-information-system-security-officer-isso-rmf-stig-support](https://www.wearedevelopers.com/jobs/ext/2634682-information-system-security-officer-isso-rmf-stig-support). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Information System Security Officer (ISSO) - RMF/STIG Support - **Company:** OBJECT CTALK INC - **Location:** Arlington, VA, United States - **Experience:** Expert - **Salary:** $120,000.0 - $160,000.0 - **Contract:** Permanent contract - **Skills:** Cyber Security, Information Systems, Information Security Management, Software Vulnerability Management, Nessus, Plan of Action and Milestones, Vulnerability Analysis - **Published:** August 6, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=821b11c9b22b909b ## About the Role The ideal candidate will have hands-on experience working in DoD environments with RMF, DISA STIGs, eMASS, ACAS/Nessus, NIST SP 800-53 security controls, vulnerability remediation, and POA&M management., Current, active TS/SCI U.S. Government security clearance Bachelor's degree; relevant experience may be substituted for education where permitted by customer/contract requirements 6+ years of relevant cybersecurity, information assurance, or information systems security experience Hands-on experience supporting DoD Risk Management Framework (RMF) Experience implementing, reviewing, and/or validating DISA STIGs Experience with ACAS and/or Nessus vulnerability scanning and remediation Experience with eMASS Experience developing and managing POA&Ms Experience supporting continuous monitoring Knowledge of NIST SP 800-53 security controls Experience developing and maintaining cybersecurity/security authorization documentation Experience coordinating vulnerability remediation with System Owners and technical teams Strong written and verbal communication skills Certification Requirement Candidate must currently possess at least one applicable cybersecurity certification required for the position, such as ## Description Object CTalk Inc. is seeking an experienced Information System Security Officer (ISSO) to support a mission-critical Department of Defense (DoD) customer in Arlington, Virginia. IMPORTANT SECURITY REQUIREMENT: This position requires a current, active TS/SCI U.S. Government security clearance. Candidates who do not currently possess the required active clearance cannot be considered for this position. The successful candidate will provide cybersecurity and information assurance support throughout the DoD Risk Management Framework (RMF) lifecycle. Responsibilities include continuous monitoring, Security Impact Assessments (SIA), vulnerability management, DISA STIG compliance, POA&M management, security documentation, and authorization activities., Support the DoD Risk Management Framework (RMF) lifecycle for assigned information systems. Perform Security Impact Assessments (SIA) and support continuous monitoring activities. Execute, review, and validate DISA STIG scan results and manually validate applicable STIG/SRG checklists. Analyze ACAS/Nessus vulnerability scan results and identify security findings requiring remediation or mitigation. Coordinate with System Owners, system administrators, engineers, and technical teams to remediate cybersecurity vulnerabilities. Develop, maintain, and track Plans of Action & Milestones (POA&Ms). Track remediation activities through Remedy tickets and provide regular status updates. Complete monthly STIG compliance reporting and quarterly STIG/SRG checklist validations. Support Authority to Operate (ATO) activities. Maintain security documentation and authorization artifacts within eMASS. Apply NIST SP 800-53 security controls and applicable DoD cybersecurity policies and guidance. Maintain accurate hardware and software inventories. Develop and maintain cybersecurity Standard Operating Procedures (SOPs) and Work Instructions (WIs). Provide cybersecurity recommendations to System Owners and technical stakeholders. Prepare management reports and communicate system security posture, vulnerabilities, remediation status, and cybersecurity risks to stakeholders. ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Microservices? Monoliths? An Annoying Discussion!](https://www.wearedevelopers.com/videos/970-microservices-monoliths-an-annoying-discussion) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [One Pipeline, Three Regulator - SBOM Compliance for the Developer](https://www.wearedevelopers.com/videos/100169-one-pipeline-three-regulator-sbom-compliance-for-the-developer) - [Giving AI eyes: How to build a dashboard you can't see](https://www.wearedevelopers.com/videos/100193-giving-ai-eyes-how-to-build-a-dashboard-you-can-t-see) - [Cyber Security: Small, and Large!](https://www.wearedevelopers.com/videos/259-cyber-security-small-and-large) ## Related Articles - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Dev Digest 138 - Are you secure about this?](https://www.wearedevelopers.com/magazine/486-dev-digest-138-are-you-secure-about-this) - [Dev Digest 216: CyberSec + Mythos, Stack Overflow for Agents & DOOM in TTF](https://www.wearedevelopers.com/magazine/728-dev-digest-216-cybersec-mythos-stack-overflow-for-agents-doom-in-ttf) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities)