> Markdown version of [/jobs/ext/2863060-information-system-security-officer-isso](https://www.wearedevelopers.com/jobs/ext/2863060-information-system-security-officer-isso). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Information System Security Officer (ISSO) - **Company:** Andy Frain Services, Inc. - **Location:** Washington, DC, United States - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** Microsoft Windows, Microsoft Antivirus, Systems Engineering, Microsoft Azure, Cloud Computing, CompTIA Security+, Cyber Security, Information Systems, Information Security Management, Microsoft Security Essentials, Cloud Services, Zero Trust Network Access, Security Software, Software Vulnerability Management, Cloud Platform System, Okta, Software Security, Microsoft InTune, Palo Alto Networks, Tenable Nessus, Splunk, Qualys, Servicenow, Plan of Action and Milestones - **Published:** September 12, 2026 - **Apply:** https://www.careerjet.com/jobad/us3d6d50a7f234314bd6979681da2bbfb0 ## About the Role * Experience supporting cybersecurity, information assurance, or ISSO activities in a federal environment * Hands-on experience with FISMA, NIST RMF, NIST SP 800-53, FedRAMP, ATO packages, SSPs, continuous monitoring, vulnerability management, and POA&M management * Experience supporting FISMA Moderate systems, major applications, general support systems, or FedRAMP-authorized cloud services * Working familiarity with cybersecurity tools and platforms such as CSAM, ServiceNow, Splunk, Tenable Nessus or Qualys, Microsoft Defender, Azure, Microsoft 365, Entra ID, Intune, Okta, Palo Alto, and Zscaler * Strong technical writing, documentation, risk analysis, and stakeholder communication skills * Must be a U.S. Citizen * Must be eligible to successfully complete and maintain a Tier 4 background investigation Microsoft Certifications One or more Microsoft security certifications is required * SC-500 - Microsoft Certified: Cloud and AI Security Engineer Associate * SC-300 - Microsoft Certified: Identity and Access Administrator Associate * SC-200 - Microsoft Certified: Security Operations Analyst Associate * SC-100 - Microsoft Certified: Cybersecurity Architect Expert * Other relevant Microsoft Azure, Microsoft 365, security, identity, or compliance certifications Cybersecurity Certifications One or more of the following is highly desirable: * CISSP * CompTIA Security+ * CISM * CGRC / CAP * CCSP * Similar recognized cybersecurity or information assurance certification Corporate Resources Unlike traditional ISSO positions that are primarily compliance and documentation focused, this role is backed by a broader cybersecurity and engineering organization. You will have access to a large cybersecurity laboratory environment, engineering resources, and reach-back subject matter experts across cloud, networking, identity, systems engineering, application security, vulnerability management, security operations, and federal cybersecurity compliance. ## Description The ISSO will provide senior-level, hands-on cybersecurity support for assigned federal information systems and will be qualified to assume Lead ISSO responsibilities during scheduled or unscheduled absences. The position will support Risk Management Framework (RMF), authorization, continuous monitoring, vulnerability management, POA&M management, audit readiness, and cybersecurity compliance activities across enterprise and cloud environments. The Senior ISSO will work closely with the Lead ISSO, Government ISSM, System Owners, technical teams, assessors, and other cybersecurity stakeholders to maintain system security posture, develop and maintain authorization artifacts, track remediation activities, review security controls and evidence, and support Government cybersecurity reviews and audits. Candidates with a combination of federal RMF/ISSO experience, a recognized cybersecurity certification, and Microsoft security certifications will be strongly preferred., You will be able to use these resources to investigate technical issues, validate security approaches, reproduce and assess configurations, evaluate emerging technologies, and develop practical solutions to security and compliance challenges. The position offers an opportunity to lead not only the execution of RMF activities, but also to help shape the technical approaches, processes, tools, and practices used by the cybersecurity team. Technical Environment and Professional Resources You will be supported by capabilities beyond those normally available to an embedded ISSO team, including: * Access to a dedicated cybersecurity and engineering laboratory for testing, validation, prototyping, and technical investigation * Reach-back access to experienced cybersecurity, cloud, network, systems, identity, application, and infrastructure SMEs * Opportunities to work directly with engineers to translate security findings and control requirements into implementable technical solutions * Ability to evaluate and test security tools, configurations, architectures, and remediation approaches outside of the production environment * Access to organizational lessons learned, technical expertise, reusable engineering approaches, and cybersecurity research developed across other federal programs * Opportunity to help mature the team's RMF, continuous monitoring, vulnerability management, security engineering, and automation practices * Ability to influence the technical direction and operating model of a growing federal cybersecurity team, Job Summary: Provide security detail as outlined in the post orders and establish working relationships with customers, local law enforcement and fire departments. Security person… + 2 days ago, Job Summary: Provide security detail as outlined in the post orders and establish working relationships with customers, local law enforcement and fire departments. Security person… + 2 days ago + ## Related Videos - [Our journey with Spring Boot in a microservice architecture](https://www.wearedevelopers.com/videos/511-our-journey-with-spring-boot-in-a-microservice-architecture) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [DevSecOps culture](https://www.wearedevelopers.com/videos/783-devsecops-culture) - [What makes Cybersecurity different for critical infrastructure?](https://www.wearedevelopers.com/videos/571-what-makes-cybersecurity-different-for-critical-infrastructure) ## Related Articles - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again](https://www.wearedevelopers.com/magazine/751-how-we-built-a-worry-free-system-that-runs-for-10-years-and-what-we-d-do-again) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Best Paying Jobs in Technology](https://www.wearedevelopers.com/magazine/256-best-paying-jobs-in-technology) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing)