> Markdown version of [/jobs/ext/3022849-information-system-security-officer](https://www.wearedevelopers.com/jobs/ext/3022849-information-system-security-officer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Information System Security Officer - **Company:** CACI International Inc. - **Location:** Hanover, MD, United States - **Experience:** Experienced - **Salary:** $103,800.0 - $218,100.0 - **Contract:** Permanent contract - **Skills:** Systems Engineering, JIRA, Audit Trail, Cloud Computing, CompTIA Security+, Cyber Security, Data Security, Identity and Access Management, Information Systems Security Architecture Professional, Network Security, Network Monitoring, Public Key Infrastructure, Redmine, Release Management, Server Administration, Service Pack, Software Engineering, Product Software Implementation Methods, Data Streaming, Systems Architecture, Computer Networking Systems, Information Security Management System, Nessus, Servicenow, Vulnerability Analysis - **Published:** September 21, 2026 - **Apply:** https://www.careerbuilder.com/job-details/information-system-security-officer-isso-chantilly-va--8df9db2f-be88-4312-8805-d8a00866fd54 ## About the Role Required: * TS/SCI clearance with polygraph * This position has been designated as requiring IAM Level 1 CWIP certification and requires one of the following baseline certifications to qualify * CAP, CND, Cloud+, GSLC, Security+CE, HCISPP, CASP+CE, CISM, CISSP (or Associate), CCISO * Bachelor''s degree in a technical discipline from an accredited college or university * Ten (10) years relevant work experience. Four (4) years of additional experience may be substituted for a bachelor''s degree. * At least four (4) years of this experience must be as an ISSO on programs and contracts of similar scope, type, and complexity. Desired: Experience with: * The ICD 503/NIST 800-53 certification and accreditation process * The Risk Management Framework * Developing and maintaining SSPs * IAVA review and handling * Interpreting Security Scan results * Interfacing with System Administrators and Software Engineers * Task tracking systems (e.g. Jira, Redmine, ServiceNow) Understands: * Public Key Infrastructure-based authentication * A variety of security policies, especially within the IC * Fundamentals of technical security risk assessment * Understands how to perform analysis of alternatives * Able to clearly communicate ideas and status updates to management and other stakeholders * What You Can Expect: A culture of integrity., Analysis Skills, CISM - Certified Information Security Manager, CISSP - Certified Information Systems Security Professional, Certification & Accreditation Process (C&A), Change Control, Cloud Computing, Communication Skills, CompTIA Security+, Computer Network Defense (CND), Computer Security, Data Access Objects (DAO), Documentation, Federal Contracts, Federal Government, GSLC - GIAC Security Leadership Certificate, Government Contracts, Integrated Circuits (ICs), International Classification of Diseases (ICD), Maintain Compliance, Nessus, Network Monitoring, Network Systems, People Management, Project/Program Management, Release Management/Engineering, Risk Analysis, Risk Management Framework (RMF), Safety/Work Safety, Security Analysis, Security Architecture, Sensitive Compartmented Information (SCI), Software Administration, Software Development, Software Engineering, Software Patches, System Architecture, System Migration, Systems Administration/Management, Systems Engineering, Test Plan/Schedule, Top Secret Clearance, U.S. National Institute of Standards and Technology (NIST), Vulnerability Scanners, Willing to Travel ## Description The candidate will be responsible for security architecture and systems engineering supporting ICAM projects. The ISSO will provide guidance to the team to support system accreditation (IATT and ATO). ISSO tasks include: * Prepare system security plan (SSP) and provide recommendations to assist in obtaining ATOs. * Identify, develop (either directly, or in coordination with applicable experts), review and incorporate common artifacts found in an RMF accreditation package such as: system architecture and boundaries, hardware and software lists, risk assessment reports, POA&Ms, data flows, and other necessary system, network, and application documentation. * Work with ISSM and DAOs to ensure systems obtain and maintain accreditation. * Verify package submissions have met the threshold for approval such as: C&A Package for System Reauthorization, SAR Findings, CTO's, POA&Ms, and System Security Plans (SSPs). * Apply continuous monitoring techniques to evaluate the systems security posture. * Create tasking for developers and system administrators as changes and patching are required. * Oversee the implementation of software patches to maintain the security posture of the organization. * Responsible for implementing and enforcing information systems security policies, standards, and methodologies. * Familiarity with the use of vulnerability scanning and assessment tools (e.g., ACAS/Nessus) necessary to identify and document compliance. * Review Audit Logs on a weekly basis. * Perform Data transfers on a weekly basis driving from CACI Hanover Office to Ft. Meade. * Maintain and report assessment and authorization statuses and issues in accordance with organizational guidance. * Understand the PRIVAC process. Support personnel with new PRIVAC requests and extensions. ## Related Videos - [Improving quality with Agentic AI with Rovo Dev and Xray](https://www.wearedevelopers.com/videos/2005-improving-quality-with-agentic-ai-with-rovo-dev-and-xray) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Collaboration Quantified: Lessons from Open Source Developer Networks](https://www.wearedevelopers.com/videos/1422-collaboration-quantified-lessons-from-open-source-developer-networks) - [One Pipeline, Three Regulator - SBOM Compliance for the Developer](https://www.wearedevelopers.com/videos/100169-one-pipeline-three-regulator-sbom-compliance-for-the-developer) - [DevSecOps culture](https://www.wearedevelopers.com/videos/783-devsecops-culture) - [Integrate your Cognitive Assistant with 3rd-party DBs and software](https://www.wearedevelopers.com/videos/249-integrate-your-cognitive-assistant-with-3rd-party-dbs-and-software) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again](https://www.wearedevelopers.com/magazine/751-how-we-built-a-worry-free-system-that-runs-for-10-years-and-what-we-d-do-again) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks)