> Markdown version of [/jobs/ext/3027655-isso](https://www.wearedevelopers.com/jobs/ext/3027655-isso). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # ISSO - **Company:** Occam Solutions Inc - **Location:** Arlington, VA, United States - **Experience:** Experienced - **Contract:** Permanent contract - **Skills:** Cyber Security, Information Systems, Information Security Management, Software Vulnerability Management, Information Technology, Plan of Action and Milestones, Vulnerability Analysis - **Published:** September 22, 2026 - **Apply:** https://www.clearancejobs.com/jobs/9183098/isso ## About the Role * Active Secret security clearance. * Typically 2-4 years of cybersecurity, information assurance, ISSO, or related experience. * Working knowledge of the Risk Management Framework (RMF) and NIST SP 800-53. * Experience developing or maintaining SSPs and POA&Ms. * Experience with vulnerability management and security compliance. * Familiarity with eMASS. * Familiarity with ACAS/Tenable, STIG Viewer, or comparable vulnerability/compliance tools. * Strong documentation, analytical, organizational, and issue-tracking skills. * Ability to communicate effectively with both technical and non-technical stakeholders., * Bachelor's degree in Cybersecurity, Information Technology, Computer Science, or a related discipline. * Relevant DoD 8140 cybersecurity certification; CISSP or comparable certification is strongly preferred. * Experience supporting DoD information systems. * Experience with ATO packages and continuous monitoring. * Ability to operate effectively in a fast-paced, compliance-driven environment. * Strong judgment when evaluating cybersecurity risk and mission requirements. * Strong attention to detail in authorization, documentation, vulnerability remediation, and continuous monitoring. Candidates must be able to support an onsite schedule of approximately 3-5 days per week. ## Description We are seeking an Information System Security Officer (ISSO) to support the day-to-day cybersecurity posture and compliance of Department of Defense information systems. The ISSO will work closely with system owners, engineers, administrators, cybersecurity leadership, and other technical stakeholders to maintain system authorization and ensure compliance with DoD and NIST cybersecurity requirements. This is a hands-on cybersecurity role with significant responsibility for Risk Management Framework (RMF) activities, continuous monitoring, vulnerability management, security documentation, POA&M management, and eMASS administration., * Maintain and update System Security Plans (SSPs) and supporting RMF documentation. * Support the full RMF lifecycle, including categorization, control implementation, assessment, authorization, and continuous monitoring. * Create, maintain, and track Plans of Action and Milestones (POA&Ms). * Maintain system authorization and compliance records within eMASS. * Review and analyze vulnerability scan results using tools such as ACAS/Tenable. * Review and validate DISA STIG compliance findings. * Track vulnerabilities and coordinate remediation activities with system administrators, engineers, and other technical teams. * Support continuous monitoring activities, including security control validation, log review, documentation updates, and security status tracking. * Collect and maintain audit and authorization evidence. * Support incident-response activities affecting assigned systems. * Work with system owners, administrators, engineers, ISSMs, and other stakeholders to resolve cybersecurity and compliance issues. * Maintain accurate, audit-ready security documentation throughout the authorization lifecycle. ## Related Videos - [One Pipeline, Three Regulator - SBOM Compliance for the Developer](https://www.wearedevelopers.com/videos/100169-one-pipeline-three-regulator-sbom-compliance-for-the-developer) - [Microservices? Monoliths? An Annoying Discussion!](https://www.wearedevelopers.com/videos/970-microservices-monoliths-an-annoying-discussion) - [Enabling intelligent logistics automation: home-grown Industrial IoT platform at Austrian Post](https://www.wearedevelopers.com/videos/2018-enabling-intelligent-logistics-automation-home-grown-industrial-iot-platform-at-austrian-post) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [Demystifying Crypto & Web3: A Technical Journey Through 15 Years of Innovation](https://www.wearedevelopers.com/videos/1516-demystifying-crypto-web3-a-technical-journey-through-15-years-of-innovation) - [Cyber Security: Small, and Large!](https://www.wearedevelopers.com/videos/259-cyber-security-small-and-large) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [The Overflow: Security and Privacy](https://www.wearedevelopers.com/magazine/715-the-overflow-security-and-privacy)