Information System Security Officer
- Discuss this with your agent
- Open in Claude
- Open in ChatGPT
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Role details
Tech stack
Job description
The ISSO will support cybersecurity, Risk Management Framework (RMF), and Authorization to Operate (ATO) activities while also providing hands-on support for vulnerability assessment and remediation using DISA STIGs and ACAS/Nessus. The position will work closely with systems, network, and cybersecurity personnel to maintain system security and authorization throughout the system lifecycle. This aligns with the DMZ PWS requirements for RMF/A&A, vulnerability remediation, eMASS, STIGs, Nessus, and cybersecurity support., Support RMF and A&A activities, including development and maintenance of ATO artifacts, security controls, POA&Ms, and eMASS records.
Review ACAS/Nessus and DISA STIG findings, assess compliance impact, and coordinate remediation activities with Network and Systems Engineers.
Track vulnerabilities and security findings through remediation and closure, validating supporting evidence and maintaining accurate authorization documentation.
Support continuous monitoring, security assessments, configuration changes, and customer cybersecurity reviews.
Prepare cybersecurity documentation, reports, and briefings for Government and program stakeholders.
Requirements
5+ years of experience in cybersecurity, information assurance, ISSO, or RMF roles supporting DoD or federal systems.
Hands-on experience supporting RMF/ATO packages and working in eMASS.
Strong experience reviewing and managing DISA STIG and ACAS/Nessus findings, including POA&M development and remediation tracking.
Working knowledge of NIST SP 800-53, DoDI 8510.01, and DoD cybersecurity requirements.
Active Top Secret clearance and DoD 8570 IAM Level 1 or higher cybersecurity certification.
Preferred Skills:
Prior experience supporting DISA programs.
Experience working closely with Network and Systems Engineers to coordinate vulnerability remediation.
Experience supporting classified NIPRNet/SIPRNet or DMZ environments.
Apply for this position
This job is hosted externally. Click below to view the full posting and apply.
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Good distractions
Talks and stories from around this role — technically off-topic, practically not.
Moments
Explore playlistsVideos
See allRelated articles
See all
Dev Digest 134 - Where pixels sing?
The Overflow: Security and Privacy
Understanding and Mitigating Common Web Vulnerabilities
Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.