> Markdown version of [/jobs/ext/2661708-information-system-security-officer](https://www.wearedevelopers.com/jobs/ext/2661708-information-system-security-officer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Information System Security Officer - **Company:** Soliel LLC - **Location:** Fort Meade, MD, United States - **Experience:** Expert - **Salary:** $140,000.0 - $155,000.0 - **Contract:** Permanent contract - **Skills:** Systems Engineering, Cyber Security, Identity and Access Management, NIPRNet, Software Vulnerability Management, Nessus, Plan of Action and Milestones, Vulnerability Analysis - **Published:** August 31, 2026 - **Apply:** https://www.dice.com/job-detail/b8786a20-4a35-44af-b251-77eaa1fdef08 ## About the Role 5+ years of experience in cybersecurity, information assurance, ISSO, or RMF roles supporting DoD or federal systems. Hands-on experience supporting RMF/ATO packages and working in eMASS. Strong experience reviewing and managing DISA STIG and ACAS/Nessus findings, including POA&M development and remediation tracking. Working knowledge of NIST SP 800-53, DoDI 8510.01, and DoD cybersecurity requirements. Active Top Secret clearance and DoD 8570 IAM Level 1 or higher cybersecurity certification. Preferred Skills: Prior experience supporting DISA programs. Experience working closely with Network and Systems Engineers to coordinate vulnerability remediation. Experience supporting classified NIPRNet/SIPRNet or DMZ environments. ## Description The ISSO will support cybersecurity, Risk Management Framework (RMF), and Authorization to Operate (ATO) activities while also providing hands-on support for vulnerability assessment and remediation using DISA STIGs and ACAS/Nessus. The position will work closely with systems, network, and cybersecurity personnel to maintain system security and authorization throughout the system lifecycle. This aligns with the DMZ PWS requirements for RMF/A&A, vulnerability remediation, eMASS, STIGs, Nessus, and cybersecurity support., Support RMF and A&A activities, including development and maintenance of ATO artifacts, security controls, POA&Ms, and eMASS records. Review ACAS/Nessus and DISA STIG findings, assess compliance impact, and coordinate remediation activities with Network and Systems Engineers. Track vulnerabilities and security findings through remediation and closure, validating supporting evidence and maintaining accurate authorization documentation. Support continuous monitoring, security assessments, configuration changes, and customer cybersecurity reviews. Prepare cybersecurity documentation, reports, and briefings for Government and program stakeholders. ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [Organizational Change Through The Power Of Why - DevSecOps Enablement](https://www.wearedevelopers.com/videos/478-organizational-change-through-the-power-of-why-devsecops-enablement) - [Cyber Security: Small, and Large!](https://www.wearedevelopers.com/videos/259-cyber-security-small-and-large) - [Maturity assessment for technicians or how I learned to love OWASP SAMM](https://www.wearedevelopers.com/videos/351-maturity-assessment-for-technicians-or-how-i-learned-to-love-owasp-samm) - [Less Is More: How Lagom and Agile Can Create Harmonious Workflows](https://www.wearedevelopers.com/videos/1993-less-is-more-how-lagom-and-agile-can-create-harmonious-workflows) ## Related Articles - [How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again](https://www.wearedevelopers.com/magazine/751-how-we-built-a-worry-free-system-that-runs-for-10-years-and-what-we-d-do-again) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [The Overflow: Security and Privacy](https://www.wearedevelopers.com/magazine/715-the-overflow-security-and-privacy) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks)