> Markdown version of [/jobs/ext/3028478-information-systems-security-officer-isso-cyber-test-engineer](https://www.wearedevelopers.com/jobs/ext/3028478-information-systems-security-officer-isso-cyber-test-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Information Systems Security Officer (ISSO) (Cyber Test Engineer - **Company:** Ennoble First - **Location:** College Park, MD, United States - **Salary:** $26,000.0 - **Contract:** Permanent contract - **Skills:** Xacta, Amazon Web Services, Microsoft Azure, Cloud Computing Security, Cyber Security, Information Security Management, Ansible, Zero Trust Network Access, Security Content Automation Protocol, Security Software, Information Technology, Operational Systems, Terraform, Splunk, Vulnerability Analysis - **Published:** September 22, 2026 - **Apply:** https://www.clearancejobs.com/jobs/9182483/information-systems-security-officer-isso-cyber-test-engineer ## About the Role * 3+ years of experience as an Information System Security Officer (ISSO) or Information System Security Analyst (ISSA) * Experience implementing and maintaining security controls for IT systems and cybersecurity tools * Experience conducting configuration assessments and risk analysis * Experience supporting RMF processes and security authorization activities * Experience with eMASS or Xacta IA Manager * Active TS/SCI clearance; willingness to take a polygraph exam Education * Associate's degree and 5+ years of experience supporting IT projects and activities, or * Bachelor's degree and 3+ years of experience supporting IT projects and activities, or * Master's degree and 1+ year of experience supporting IT projects and activities Certifications * Active DoD 8570 Information Assurance Technician (IAT) Level II certification (e.g., Security+ CE, CCNA-Security, CySA+, GICSP, GSEC, CND, or SSCP) * Must obtain a DoD 8570 Cybersecurity Service Provider (CSSP) - Infrastructure Support certification (e.g., CEH, CySA+, GICSP, SSCP, CHFI, CFR, Cloud+, or CND) prior to start date Desired Qualifications * Experience with DoD STIGs, SCAP, ACAS, and configuration assessment tools * Experience assessing security impacts of new COTS tools, upgrades, or configuration changes * Experience drafting or reviewing CONOPS, system topologies, and vulnerability scan results * Familiarity with tools such as Ansible, Terraform, Splunk, or STIG Viewer * Knowledge of cloud-native security tools and Zero Trust concepts * Strong written, verbal, and presentation skills * Ability to work effectively in a fast-paced, collaborative environment * AWS, Azure, or GCP certification ## Description Ennoble First is seeking an Information Systems Security Officer (ISSO) to support the assessment, implementation, and sustainment of security controls for developmental and operational cybersecurity tools in a mission-critical environment. The ISSO evaluates security configurations, identifies risks, and provides actionable recommendations to ensure systems comply with federal security requirements and achieve and maintain Authorization to Operate (ATO). This role works closely with engineers, vendors, and government stakeholders to translate cybersecurity policy and risk into secure, operational solutions. Primary Responsibilities * Assess and document security configurations for developmental and operational systems and tools * Conduct tools assessments and configuration analysis against vendor guidance, best practices, and government security requirements * Support implementation, oversight, and sustainment of security controls in accordance with RMF * Apply and evaluate controls from NIST 800-53, FedRAMP, ICD 503, RMF, and DoD Information Levels * Support system authorization activities including initial ATOs and ongoing continuous monitoring * Perform risk analysis and document findings, recommendations, and mitigation strategies * Coordinate with engineers, SMEs, subcontractors, and vendors to assess security impacts of system changes * Develop and deliver security documentation, briefings, and artifacts to support stakeholder decision-making ## Related Videos - [DevSecOps culture](https://www.wearedevelopers.com/videos/783-devsecops-culture) - [Our journey with Spring Boot in a microservice architecture](https://www.wearedevelopers.com/videos/511-our-journey-with-spring-boot-in-a-microservice-architecture) - [Dev & Test in the Cloud? Deploy your cloud environments with Ansible & Terraform](https://www.wearedevelopers.com/videos/1607-dev-test-in-the-cloud-deploy-your-cloud-environments-with-ansible-terraform) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Eclipse Che for Infrastructure Automation](https://www.wearedevelopers.com/videos/1611-eclipse-che-for-infrastructure-automation) - [Organizational Change Through The Power Of Why - DevSecOps Enablement](https://www.wearedevelopers.com/videos/478-organizational-change-through-the-power-of-why-devsecops-enablement) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again](https://www.wearedevelopers.com/magazine/751-how-we-built-a-worry-free-system-that-runs-for-10-years-and-what-we-d-do-again) - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [Best Paying Jobs in Technology](https://www.wearedevelopers.com/magazine/256-best-paying-jobs-in-technology) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing)