ISSO

Occam Solutions Inc
Arlington, VA, United States
5 days ago
Apply on www.clearancejobs.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Experienced
Experience required
2 years minimum
Working hours
Regular working hours

Tech stack

Cyber Security Information Systems Information Security Management Software Vulnerability Management Information Technology Plan of Action and Milestones Vulnerability Analysis

Job description

We are seeking an Information System Security Officer (ISSO) to support the day-to-day cybersecurity posture and compliance of Department of Defense information systems. The ISSO will work closely with system owners, engineers, administrators, cybersecurity leadership, and other technical stakeholders to maintain system authorization and ensure compliance with DoD and NIST cybersecurity requirements.

This is a hands-on cybersecurity role with significant responsibility for Risk Management Framework (RMF) activities, continuous monitoring, vulnerability management, security documentation, POA&M management, and eMASS administration., * Maintain and update System Security Plans (SSPs) and supporting RMF documentation.

  • Support the full RMF lifecycle, including categorization, control implementation, assessment, authorization, and continuous monitoring.
  • Create, maintain, and track Plans of Action and Milestones (POA&Ms).
  • Maintain system authorization and compliance records within eMASS.
  • Review and analyze vulnerability scan results using tools such as ACAS/Tenable.
  • Review and validate DISA STIG compliance findings.
  • Track vulnerabilities and coordinate remediation activities with system administrators, engineers, and other technical teams.
  • Support continuous monitoring activities, including security control validation, log review, documentation updates, and security status tracking.
  • Collect and maintain audit and authorization evidence.
  • Support incident-response activities affecting assigned systems.
  • Work with system owners, administrators, engineers, ISSMs, and other stakeholders to resolve cybersecurity and compliance issues.
  • Maintain accurate, audit-ready security documentation throughout the authorization lifecycle.

Requirements

  • Active Secret security clearance.
  • Typically 2-4 years of cybersecurity, information assurance, ISSO, or related experience.
  • Working knowledge of the Risk Management Framework (RMF) and NIST SP 800-53.
  • Experience developing or maintaining SSPs and POA&Ms.
  • Experience with vulnerability management and security compliance.
  • Familiarity with eMASS.
  • Familiarity with ACAS/Tenable, STIG Viewer, or comparable vulnerability/compliance tools.
  • Strong documentation, analytical, organizational, and issue-tracking skills.
  • Ability to communicate effectively with both technical and non-technical stakeholders., * Bachelor’s degree in Cybersecurity, Information Technology, Computer Science, or a related discipline.
  • Relevant DoD 8140 cybersecurity certification; CISSP or comparable certification is strongly preferred.
  • Experience supporting DoD information systems.
  • Experience with ATO packages and continuous monitoring.
  • Ability to operate effectively in a fast-paced, compliance-driven environment.
  • Strong judgment when evaluating cybersecurity risk and mission requirements.
  • Strong attention to detail in authorization, documentation, vulnerability remediation, and continuous monitoring.

Candidates must be able to support an onsite schedule of approximately 3-5 days per week.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.clearancejobs.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

59 sec

Proving regulatory compliance to auditors and chief officers

Mike Bursell Mike Bursell · World Congress 2026 Europe

5:03 min

Navigating new cybersecurity compliance frameworks and laws

Kurt Eder · LIVE

42 sec

Energy forecasts and resource demands of information technology

Marjolein Pordon · LIVE

4:11 min

Introduction to cloud-native application developer security

Micah Silverman · World Congress 2022

4:01 min

Finding personal fulfillment in the cybersecurity industry

LIVE

2:46 min

Missing equipment retrieval processes for departing employees

Jasmin Azemović Jasmin Azemović · World Congress 2026 Europe

Videos

See all

Related articles

See all