> Markdown version of [/jobs/ext/2732893-information-system-security-officer-isso](https://www.wearedevelopers.com/jobs/ext/2732893-information-system-security-officer-isso). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Information System Security Officer (ISSO) - **Company:** Omniscius Consulting - **Location:** Oakton, VA, United States - **Experience:** Expert - **Salary:** $110,240.0 - **Contract:** Permanent contract - **Skills:** Xacta, Audit Trail, Cyber Security, Information Systems, System Configuration, Data Security, Identity and Access Management, Information Security Management, SAP (Applications), Software Vulnerability Management, Information Technology, Nessus, Splunk, Plan of Action and Milestones - **Published:** September 5, 2026 - **Apply:** https://www.careerjet.com/jobad/usc9ea1b6fce3c2595cfe57a5ed44dd66e ## About the Role * Education/Experience: Bachelor's degree in Cybersecurity, Information Technology, or related field (or equivalent experience) with 5-7+ years of experience acting as an ISSO or in a senior DoD RMF compliance role. * DoD Directive: DoD 8570.01-M / 8140.03 compliant for IAM Level II or III (e.g., CAP, CISM, CASP+ CE, CISSP). * Framework Knowledge: Expert-level understanding of DoD RMF (DoDI 8510.01), NIST SP 800-53/800-37/800-171, and DISA STIG implementation. * Tooling: Proven experience managing ATO artifacts in eMASS or Xacta. Proficient with SCC, STIG Viewer, and interpreting IAVA/IAVM notices. * Communication: Exceptional written and verbal communication skills. Ability to act as a security liaison, balancing strict DoD compliance requirements with our flexible, fast-paced R&D mission needs., Description Do you have experience leading people and an interest in shaping U.S. National Leadership Command Capability (NLCC) communications technology solutions? Are you pas… ## Description The Information Systems Security Officer (ISSO) ensures the secure operation of complex, multi-enclave IT and Research & Development (R&D) systems. The ISSO serves as the principal advisor to Information System Owners regarding security posture. This role requires a "hands-on" governance approach, heavily utilizing the Assured Compliance Assessment Solution (ACAS) and standard DoD tooling to drive Continuous Monitoring (ConMon), validate compliance, and maintain active Authority to Operate (ATO) statuses without disrupting critical experimental research., ISSO responsibilities include, but are not limited to: RMF Lifecycle Management: Develop, maintain, and oversee RMF authorization packages (SSP, SAR, RAR, SAP, and POA&M) within systems of record (e.g., eMASS, Xacta) for standard enterprise and non-standard research environments. ACAS Operations & Vulnerability Management: Execute credentialed and non-credentialed ACAS (Tenable.sc / Nessus) scans across connected and air-gapped networks. Analyze scan results to identify vulnerabilities, assess risk, and validate compliance against DoD baselines. POA&M & Remediation Advisory: Translate complex ACAS scan results and DISA STIG findings into actionable mitigation strategies. Work directly with systems administrators and researchers to remediate vulnerabilities, track progress, and close POA&M items. Continuous Monitoring (ConMon): Implement and oversee ConMon strategies. Review ACAS dashboards, audit logs (e.g., Splunk, Elastic), and system configurations to ensure ongoing compliance with NIST SP 800-53 controls. Air-Gapped & Multi-Enclave Support: Facilitate secure data transfers, manual ACAS plugin/feed updates, and compliance validation for isolated, disconnected, and highly classified enclaves. Security Assessments: Conduct routine compliance checks using SCC, STIG Viewer, and Evaluate-STIG. Support independent third-party assessments (e.g., CCRI) and ATO control validations. Incident Handling: Coordinate with the Information Systems Security Manager (ISSM) and incident response teams to investigate security anomalies, audit anomalies, or classified data spillages. Requirements ## Related Videos - [Our journey with Spring Boot in a microservice architecture](https://www.wearedevelopers.com/videos/511-our-journey-with-spring-boot-in-a-microservice-architecture) - [One Pipeline, Three Regulator - SBOM Compliance for the Developer](https://www.wearedevelopers.com/videos/100169-one-pipeline-three-regulator-sbom-compliance-for-the-developer) - [DevSecOps culture](https://www.wearedevelopers.com/videos/783-devsecops-culture) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again](https://www.wearedevelopers.com/magazine/751-how-we-built-a-worry-free-system-that-runs-for-10-years-and-what-we-d-do-again) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [The Overflow: Security and Privacy](https://www.wearedevelopers.com/magazine/715-the-overflow-security-and-privacy) - [Now is the time for industrialized software development](https://www.wearedevelopers.com/magazine/601-now-is-the-time-for-industrialized-software-development)