> Markdown version of [/jobs/ext/2689172-information-systems-security-officer-isso](https://www.wearedevelopers.com/jobs/ext/2689172-information-systems-security-officer-isso). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Information Systems Security Officer (ISSO) - **Company:** Caci Inc - **Location:** United States - **Experience:** Experienced - **Salary:** $75,200.0 - $158,100.0 - **Contract:** Contract - **Skills:** Cyber Security, Information Systems, Comptia Pentest+ CE, Software Engineering, Information Technology - **Published:** September 3, 2026 - **Apply:** https://www.clearancejobs.com/jobs/9136879/information-systems-security-officer-isso ## About the Role Required: * Active Secret or TS clearance * 3-5 years of RMF/ATO experience in DoD or federal environments * Hands-on experience with eMASS * Working knowledge of NIST SP 800-53 Rev. 5 and DoD RMF processes * Demonstrated ability to independently author SSPs and manage POA&Ms * DoD 8140.03M DCWF Basic Tier - CEH * DoD 8140 Interim Education Options Required to travel to Scott Airforce base on a quarterly basis Desired: * DoD 8140.03M DCWF Intermediate Tier - CEH(P), RCCE Level 1, Cloud+, CPTE, FITSP-A, GCED, GCIH, GCSA, GICSP, GSEC, PenTest+, or Security+ * Bachelor's degree in Computer Science, Cybersecurity, Data Science, Information Systems, IT, or Software Engineering * Experience with eMASSer or other RMF automation tooling * Exposure to cloud-hosted or hybrid system authorization boundaries * Familiarity with the DoD RMF Knowledge Service ## Description Step into a core mission-support role where you'll own the daily security authorization posture for DoD information systems. You'll work within a well-resourced cybersecurity organization equipped with dedicated engineering, operations, and architecture teams, giving you the support needed to drive meaningful impact. You will: * Own and manage the security authorization posture of assigned DoD systems * Partner closely with engineering, operations, and architecture professionals to ensure secure system performance * Build advanced expertise with modern RMF tools, including eMASS and eMASSer automation * Maintain mission continuity by developing and managing ATO packages and continuous monitoring programs * Advance into a senior GRC career pathway with structured opportunities for professional growth Responsibilities: * Develop, update, and maintain System Security Plans (SSPs) for assigned systems * Manage POA&Ms from identification through remediation and closure * Compile and submit complete Authorization to Operate (ATO) packages * Conduct continuous monitoring aligned with program strategy and RMF standards * Use eMASS to track RMF workflows, manage artifacts, and support GRC governance processes * Coordinate with ISSEs and SecOps teams to validate security control implementations * Create Security Assessment Plans (SAPs) and support SAR development and coordination * Draft supply chain risk management plans to support system-level authorization needs * Partner with the Cybersecurity Architect on RMF strategic planning and lifecycle improvements ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Microservices? Monoliths? An Annoying Discussion!](https://www.wearedevelopers.com/videos/970-microservices-monoliths-an-annoying-discussion) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [One Pipeline, Three Regulator - SBOM Compliance for the Developer](https://www.wearedevelopers.com/videos/100169-one-pipeline-three-regulator-sbom-compliance-for-the-developer) - [Giving AI eyes: How to build a dashboard you can't see](https://www.wearedevelopers.com/videos/100193-giving-ai-eyes-how-to-build-a-dashboard-you-can-t-see) - [Cyber Security: Small, and Large!](https://www.wearedevelopers.com/videos/259-cyber-security-small-and-large) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [The Overflow: Security and Privacy](https://www.wearedevelopers.com/magazine/715-the-overflow-security-and-privacy) - [Best Paying Jobs in Technology](https://www.wearedevelopers.com/magazine/256-best-paying-jobs-in-technology) - [How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again](https://www.wearedevelopers.com/magazine/751-how-we-built-a-worry-free-system-that-runs-for-10-years-and-what-we-d-do-again)