> Markdown version of [/jobs/ext/2987515-isso-security-analyst](https://www.wearedevelopers.com/jobs/ext/2987515-isso-security-analyst). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # ISSO Security Analyst - **Company:** Booz Allen Hamilton Inc. - **Location:** Stafford, VA, United States - **Experience:** Expert - **Salary:** $99,000.0 - $225,000.0 - **Contract:** Permanent contract - **Skills:** Cyber Security, Information Systems, Information Security Management, SC Clearance, Information Technology, Plan of Action and Milestones - **Published:** September 18, 2026 - **Apply:** https://www.clearancejobs.com/jobs/9176021/isso-security-analyst ## About the Role * 6+ years of experience with both Information Technology (IT) and Information Assurance (IA) * Experience with National Institute of Standards and Technology (NIST) SP 800-53 security controls, RMF, system authorizations, and security compliance standards and processes, including IATTs, ATOs, ATCs, and reciprocity agreements * Experience supporting all RMF steps, security categorizations, creating and updating security artifacts and FISMA security documents, control implementation details, and Plan of Action and Milestones (POA&M) for the IT system or application being accredited * Experience creating plans and approaches for executing product installation securely in accordance with agency authorization policy requirements for system major changes and development lifecycles while identifying potential risks and working with system stakeholders to create mitigation strategies to reduce or eliminate risks * Experience analyzing authorization documents and associated artifacts against authorization requirements to identify gaps, establish a schedule to address outstanding authorization requirements, and coordinate directly with system stakeholders to address identified gaps in accordance with required deadlines * Experience with Enterprise Mission Assurance Support Service (eMASS) and tools such as the Assured Compliance Assessment Solution (ACAS), Security Technical Implementation Guides (STIG), or Evaluate-STIG * Ability to organize, manage, and maintain large amounts of discrete data with various expiration dates across multiple systems simultaneously * Secret clearance * HS diploma or GED * CAP, CISSP, CASP, CISM, or GSLC Certification Nice If You Have: * Experience working with MOUs, MOAs and ISAs * Experience with RMF DoW and USMC Cybersecurity and Acquisition policies * Ability to work as part of a team * Possession of excellent verbal and written communication skills ## Description As a ISSO on our team, you'll use your experience to work with United States Marine Corps (USMC) Information System Owners (ISO), Information System Security Officers (ISSO), site managers, and other system stakeholders to coordinate and drive the completion of Risk Management Framework (RMF) steps 0-6 ATO activities and requirements, identify and mitigate risks, escalate project risks to leadership, understand and apply USMC authorization policies and processes, and provide information system security expertise. You'll ensure the appropriate operational security posture is maintained for information systems throughout the system's lifecycle from product acquisition and installation through decommission. You will complete and maintain very detailed security documentation and coordinate to execute ATO support duties that documents security details related to a variety of IT systems, networks, hardware, and software in a variety of complex and simple installation sites. You'll work with your client to translate security concepts into actionable implementable solution recommendations to help the client make informed security decisions from all aspects of IT deployments ensuring full commissioning is completed through deployment, into production and decommissioning. ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Microservices? Monoliths? An Annoying Discussion!](https://www.wearedevelopers.com/videos/970-microservices-monoliths-an-annoying-discussion) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [One Pipeline, Three Regulator - SBOM Compliance for the Developer](https://www.wearedevelopers.com/videos/100169-one-pipeline-three-regulator-sbom-compliance-for-the-developer) - [Cyber Security: Small, and Large!](https://www.wearedevelopers.com/videos/259-cyber-security-small-and-large) - [Giving AI eyes: How to build a dashboard you can't see](https://www.wearedevelopers.com/videos/100193-giving-ai-eyes-how-to-build-a-dashboard-you-can-t-see) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again](https://www.wearedevelopers.com/magazine/751-how-we-built-a-worry-free-system-that-runs-for-10-years-and-what-we-d-do-again) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks)