> Markdown version of [/jobs/ext/2977985-information-systems-security-office-isso-sme](https://www.wearedevelopers.com/jobs/ext/2977985-information-systems-security-office-isso-sme). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Information Systems Security Office (ISSO) SME - **Company:** Gemini Industries - **Location:** Fort Washington, MD, United States - **Experience:** Experienced - **Contract:** Permanent contract - **Skills:** Artificial Intelligence, Configuration Management, CompTIA Network+, CompTIA Security+, Cyber Security, Information Systems, Computer Networks, Identity and Access Management, Information Security Management, Software Vulnerability Management, Enterprise Software Applications, Generative AI, Malware, Cybercrime, Vulnerability Analysis - **Published:** September 18, 2026 - **Apply:** https://www.clearancejobs.com/jobs/9177724/information-systems-security-office-isso-sme ## About the Role Education: MA/MS (or a BA/BS plus an additional 8 years of work experience, 4 of which must be work related), The candidate must have the following qualifications: * Minimum of fifteen (15) years of related work experience. * Minimum of ten (10) specific work-related experience in support of a DoW component. * Minimum of three (3) years as a staff action officer (e.g. DoW Staff. Service Staff, CCMD staff, Joint Staff, or equivalent) and may be included in years of technical experience above. * Experience supporting technical security of military systems with at least two of which include experience in coalition operations and at least multi-level security solutions supporting coalition environments or bilateral military information sharing efforts. * Experience with the following processes: Risk Management Framework (RMF) and system authorization, Cyber Incident Handling, System Life Cycle Management Processes (e.g. Engineering Change and Configuration Management), Vulnerability Management, Malware Protection, and Security Assessments/Evaluations/Reviews, Continuous Monitoring, DODIN Connection Approval Process, and Cybersecurity Service Provider (CSSP). * Good verbal and written communication. Certifications required: * IAM Level II certification (i.e. CAP, CASP+CE, CISM, CISSP, GSLC, or CCISO) (mandatory), CEH desirable. Shall comply with DoW established Directive 8140. The following qualifications are desired: * Knowledgeable and skilled in applying Generative AI. * CompTIA Network+ (desired). * CompTIA Security+ (desired). Travel: Local travel within the NCR and occasional long-distance travel outside the NCR, * Highly motivated self-starters * Resourceful individuals with extraordinary intellectual capability and the ability to rapidly learn and apply new concepts * Individuals who have a "let me try" attitude and are resilient, present an opinion/position, justify it, and then accept whatever decision is made and charge forward * Individuals who view criticism as an opportunity to improve ("let me try again") * Individuals who think and create, enhancing the company with a steady flow of fresh ideas, perspective, and energy. ## Description The successful candidate is expected to accomplish the following outcomes during the first year in the position: * Formally track all tasks, to include assigned by, suspense, status, and comments on all assigned tasks through completion and be prepared to brief upon request. * Develop digital continuity folders and files that include standard operating procedures, workflows and POC lists to accomplish all tasks. * Create 2-3 products beyond the client's requirements that positively impact the client to either increase efficiency, effectiveness, or innovation. * Establish foundation in AI/ML skills and contribute to AI/ML operationalization and modernization goals and objectives. * Master position tasks within 60 days and exceed requirements within 90 days. * Use government provided Generative AI tools on a day-to-day basis to accelerate tasks, research, documentation, analysis, planning, reporting, and problem solving. * Make recommendations on process improvements and practices that improve quality, speed and/or efficiency., The Information Systems Security Officer (ISSO) SME supports Secretary of the Air Force, Office of Competition (SAF/OCB) providing onsite ISSO process support in support of SAF/OCB Information Systems Security Managers (ISSMs) where Information Systems are located, which may include: the Pentagon, Joint Base Anacostia-Bolling, Fort Washington MD, and San Antonio TX. Primarily, the ISSO SME provides cybersecurity assessment support, STIG and ACAS vulnerability scan coordination, and Enterprise system security documentation development. Per PWS section 1.3.9.1 Information System Security Officer (ISSO), responsibilities include but are not limited to: * Provide onsite ISSO support to SAF/OCB Information System Security Managers (ISSMs) where Information Systems are located, which may include: the Pentagon, Joint Base Anacostia-Bolling, and Fort Washington MD. * Coordinate cybersecurity-related processes and activities for SAF/OCB Information Systems and related interfaces. The processes include, but are not limited to, Risk Management Framework (RMF) and system authorization, Cyber Incident Handling, System Life Cycle Management Processes (e.g., Engineering Change and Configuration Management), Vulnerability Management, Malware Protection, Security Assessments/Evaluations/Reviews, Continuous Monitoring, Department of Defense Information Network (DODIN) Connection Approval Process, and Cyber Security Service Provider (CSSP). * Work with the Cyberspace Capabilities Branch and other SAF/OCB Divisions to provide iterative innovation proposals to be implemented quarterly, by proposing best practices, innovative technology, and/or process improvements that would support the overarching objective of managing the Branch's daily operations more efficiently and effectively across the Enterprise. Proposals may include methods for increasing mission capability, enhancing customer experience and improving coordination across the geographically dispersed enterprise. The Contractor shall provide cost/benefit analysis proposals for Government review for any recommended efforts that require resources external to their organization. * Support, document and advise on cybersecurity assessments, security impact analysis and system authorization of SAF/OCB Information Systems. The format of the documentation will be determined based on the applicable DoW, Air Force and Multi-National directives and guidance. The documentation shall be submitted electronically to the appropriate repository per the DAF ISSM guidance. ## Related Videos - [Fighting the Next Wave of Cybercrime](https://www.wearedevelopers.com/videos/100331-fighting-the-next-wave-of-cybercrime) - [What makes Cybersecurity different for critical infrastructure?](https://www.wearedevelopers.com/videos/571-what-makes-cybersecurity-different-for-critical-infrastructure) - [Your imaginations is (no longer) the limit: how Generative AI empowers people to be creative](https://www.wearedevelopers.com/videos/741-your-imaginations-is-no-longer-the-limit-how-generative-ai-empowers-people-to-be-creative) - [Enhancing Workload Security in Kubernetes](https://www.wearedevelopers.com/videos/356-enhancing-workload-security-in-kubernetes) - [Deep Fakes: The Lies We Can’t See](https://www.wearedevelopers.com/videos/1187-deep-fakes-the-lies-we-can-t-see) - [The shadows that follow the AI generative models](https://www.wearedevelopers.com/videos/624-the-shadows-that-follow-the-ai-generative-models) ## Related Articles - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [System change: restart as developer?](https://www.wearedevelopers.com/magazine/39-system-change-restart-as-developer) - [Dev Digest 216: CyberSec + Mythos, Stack Overflow for Agents & DOOM in TTF](https://www.wearedevelopers.com/magazine/728-dev-digest-216-cybersec-mythos-stack-overflow-for-agents-doom-in-ttf) - [How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again](https://www.wearedevelopers.com/magazine/751-how-we-built-a-worry-free-system-that-runs-for-10-years-and-what-we-d-do-again)