> Markdown version of [/jobs/ext/2696994-intermediate-information-system-security-officer](https://www.wearedevelopers.com/jobs/ext/2696994-intermediate-information-system-security-officer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Intermediate Information System Security Officer - **Company:** Everforth Apex - **Location:** Washington, DC, United States (Remote available) - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** Amazon Web Services, Microsoft Azure, Cloud Computing Security, Configuration Management, Cyber Security, Information Systems, Information Security Management, Software Vulnerability Management, Plan of Action and Milestones, Vulnerability Analysis - **Published:** September 3, 2026 - **Apply:** https://www.dice.com/job-detail/e0ae05aa-432e-4065-a12a-db6a43e7c1e0 ## About the Role * Bachelor's Degree and 10+ years of relevant experience; or an Associate's Degree and 12+ years of experience; or 16+ years of experience with no degree. * A minimum of 7 years of experience in Information Security or as an ISSO supporting federal systems. Citizenship and Work Location: * U.S. Citizenship is required. * Candidates must reside within a local radius of Washington, D.C., and be available for occasional onsite work if requested. Technical Skills and Knowledge: * Hands-on experience with the RMF lifecycle and ATO activities. * Strong knowledge of FISMA, NIST 800-37, NIST 800-53, and DHS 4300 Series. * Experience developing and maintaining SSPs, POA&Ms, Contingency Plans, and other security artifacts. * Background in conducting security control assessments and Security Impact Analyses. * Proficiency in continuous monitoring, vulnerability management, and POA&M remediation. * Strong technical writing skills for producing compliance and assessment documentation. Certifications: * Must hold a CISSP, CISM, or CASP+ certification., * Experience supporting the Department of Homeland Security (DHS) or its components. * Understanding of cloud security concepts, with experience in AWS or Azure. * Experience with Governance, Risk, and Compliance (GRC) tools such as CSAM, eMASS, or RegScale. ## Description We are seeking an Intermediate Information System Security Officer (ISSO) to support a federal government customer. The primary objective is to restore the security program, which has been neglected, by cleaning up existing compliance issues and stabilizing the environment. This role is central to remediation efforts and will involve enhancing automation to improve efficiency across approximately 90 systems. The position requires working with system owners and cybersecurity teams to manage security controls enterprise-wide, focusing on specific control families rather than individual systems., * Execute Risk Management Framework (RMF) activities to support Authorization to Operate (ATO) decisions. * Develop, maintain, and update security documentation, including System Security Plans (SSPs), Plan of Action and Milestones (POA&Ms), and Contingency Plans. * Conduct security control assessments, vulnerability assessments, and Security Impact Analyses for system changes. * Support continuous monitoring, vulnerability management, and POA&M tracking and remediation. * Implement security controls to ensure the confidentiality, integrity, and availability of information systems in compliance with federal standards. * Support change management processes, including participating in Change Advisory Board (CAB) reviews. * Prepare for and support security audits, testing, and compliance reviews by providing necessary documentation. * Respond to cybersecurity data calls with timely information for leadership. * Organize responsibilities by security control areas (e.g., Access Control, Configuration Management) across all systems. ## Related Videos - [Containers in the cloud - State of the Art in 2022](https://www.wearedevelopers.com/videos/410-containers-in-the-cloud-state-of-the-art-in-2022) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Developer Tools for Microsoft Azure](https://www.wearedevelopers.com/videos/450-developer-tools-for-microsoft-azure) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [One Pipeline, Three Regulator - SBOM Compliance for the Developer](https://www.wearedevelopers.com/videos/100169-one-pipeline-three-regulator-sbom-compliance-for-the-developer) - [Develop enterprise-ready applications for Microsoft Teams with Azure resources on modern web technologies](https://www.wearedevelopers.com/videos/187-develop-enterprise-ready-applications-for-microsoft-teams-with-azure-resources-on-modern-web-technologies) ## Related Articles - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [Best Paying Jobs in Technology](https://www.wearedevelopers.com/magazine/256-best-paying-jobs-in-technology) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again](https://www.wearedevelopers.com/magazine/751-how-we-built-a-worry-free-system-that-runs-for-10-years-and-what-we-d-do-again) - [The Overflow: Security and Privacy](https://www.wearedevelopers.com/magazine/715-the-overflow-security-and-privacy)