> Markdown version of [/jobs/ext/2966240-isso](https://www.wearedevelopers.com/jobs/ext/2966240-isso). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # ISSO - **Company:** Humanit Solutions, LLC - **Location:** Linthicum Heights, MD, United States - **Experience:** Experienced - **Contract:** Permanent contract - **Skills:** CompTIA Security+, Cyber Security, Information Systems, Information Security Management, SAP (Applications), Security Content Automation Protocol, Software Vulnerability Management, SARS Software Products, Information Technology, Nessus - **Published:** September 17, 2026 - **Apply:** https://www.clearancejobs.com/jobs/9170645/isso ## About the Role * Clearance Level: Top Secret & Active Security+ Certificate * Education: Bachelor's degree in Cybersecurity, Computer Science, Information Technology, or a related field. A combination of equivalent experience and relevant cybersecurity certifications may be considered. * Experience: Minimum of 3+ years of cybersecurity experience in a Department of Defense (DoD) or Federal environment. * Frameworks & Standards: Strong knowledge of DoD 8510 Risk Management Framework (RMF), NIST SP 800-37, NIST SP 800-53, and experience using eMASS. * Tools & Technologies: Familiarity with DISA STIGs, ACAS, Nessus, or Tenable.sc. * Security Operations: Understanding of continuous monitoring processes and the vulnerability management lifecycle. * Compliance & Authorization: Experience supporting Assessment & Authorization (A&A) packages and working with Authorizing Officials (AOs). * Regulatory Knowledge: Knowledge of SCAP compliance, FISMA metrics, and federal cybersecurity reporting requirements Certifications (DoD 8570/8140 Baseline Requirements Level I / II): * Security+ CE (CompTIA) * CGRC (ISC2 Certified Governance, Risk And Compliance) * GSLC (GIAC Security Leadership Certification) * CISM (Certified Information Security Manager) * CISSP (Associate or Full) * CASP+ (CompTIA) Note: Must maintain certification to remain compliant with DoD 8570.01-M / DoD 8140. Must satisfy one or more certification requirements ## Description We are seeking a highly motivated Information System Security Officer (ISSO) to support and enhance the cybersecurity posture of Department of Defense (DoD) information systems. The ISSO will ensure compliance with the DoD Risk Management Framework (RMF) and NIST 800-37 security requirements. This role involves close collaboration with system owners, engineers, and cybersecurity professionals to implement, document, and maintain security controls in accordance with federal standards. Work Environment & Clearance Requirements: * May require access to classified information and familiarity with secure facility operations. * Must hold a current DoD security clearance at the required level. * Must be eligible for access to Special Access Programs (SAP), if needed. WHAT YOU WILL DO: * Serve as the ISSO for one or more Department of Defense (DoD) information systems. * Develop, implement, and maintain RMF documentation, including System Security Plans (SSPs), Security Assessment Reports (SARs), and Plans of Action and Milestones (POA&Ms). * Ensure systems are operated, maintained, and decommissioned in compliance with DoD cybersecurity policies and procedures. * Conduct regular system security reviews and continuous monitoring activities. * Participate in security incident response, reporting, and remediation efforts. * Collaborate with Information System Owners (ISOs), Information System Security Managers (ISSMs), and Authorizing Officials (AOs) to achieve and maintain Authorization to Operate (ATO). * Support internal and external audits, inspections, and cybersecurity assessments. * Apply security updates and patches in accordance with Security Technical Implementation Guides (STIGs) and Information Assurance Vulnerability Management (IAVM) requirements. * Utilize tools such as eMASS, ACAS, Nessus, and HBSS to support compliance, vulnerability management, and reporting ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [What makes Cybersecurity different for critical infrastructure?](https://www.wearedevelopers.com/videos/571-what-makes-cybersecurity-different-for-critical-infrastructure) - [One Pipeline, Three Regulator - SBOM Compliance for the Developer](https://www.wearedevelopers.com/videos/100169-one-pipeline-three-regulator-sbom-compliance-for-the-developer) - [Cyber Security: Small, and Large!](https://www.wearedevelopers.com/videos/259-cyber-security-small-and-large) - [Less Is More: How Lagom and Agile Can Create Harmonious Workflows](https://www.wearedevelopers.com/videos/1993-less-is-more-how-lagom-and-agile-can-create-harmonious-workflows) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [The Overflow: Security and Privacy](https://www.wearedevelopers.com/magazine/715-the-overflow-security-and-privacy) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks)