> Markdown version of [/jobs/ext/3036610-information-system-security-officer](https://www.wearedevelopers.com/jobs/ext/3036610-information-system-security-officer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Information System Security Officer - **Company:** Caci Inc - **Location:** Florham Park, NJ, United States - **Experience:** Experienced - **Salary:** $86,600.0 - $181,800.0 - **Contract:** Contract - **Skills:** Xacta, Configuration Management, Cyber Security, Identity and Access Management, Information Security Management, SAP (Applications), SAP Security, Security Information and Event Management, Systems Architecture, Software Vulnerability Management, Information Technology, Nessus, Plan of Action and Milestones - **Published:** September 23, 2026 - **Apply:** https://www.clearancejobs.com/jobs/9184095/information-system-security-officer ## About the Role Required: * Must have an active TS and willing to sit for the POLY * 3 - 5 years of cybersecurity experience supporting DoD classified systems (SCI, SAP). * Knowledge of JSIG, RMF, DoDI 8510.01, NIST SP 800-53, ICD 503. * Experience coordinating directly with AOs, AO reps, SCAs, and government cyber stakeholders. * Demonstrated ability to manage cybersecurity across multi-system classified environments. * Strong technical risk assessment and communication skills. * Ability to operate independently in complex classified environments. * DoD 8140 IAM Level II/III or IAT III certification; CISSP preferred. Experience with cybersecurity and RMF toolsets, including: * eMASS and/or Xacta for RMF, authorization, and security control management. * SIEM platforms for security monitoring, event analysis, and incident response. * Vulnerability management tools, including Nessus/ACAS or equivalent platforms. * Tools used for STIG compliance, configuration management, continuous monitoring, and POA&M tracking. * Bachelor's degree in Cybersecurity, IT, Computer Science, Engineering, or related field; or equivalent experience. * Current or recent SAP access * Must maintain eligibility for all required program-specific accesses. ## Description CACI is seeking an experienced Information Systems Security Officer (ISSO) to assest the Facility ISSM and oversee Risk Management Framework (RMF) lifecycle activities for a portfolio of classified DoD systems supporting SAP, SCI, and NSA missions. You will manage system authorizations, direct cybersecurity compliance, and serve as the senior cybersecurity authority for multiple high-visibility programs-ensuring systems remain secure, compliant, and fully authorized to operate., * Support RMF lifecycle activities from system categorization through Authorization to Operate (ATO), Interim Authorization to Test (IATT), and continuous authorization. * Develop and manage SSPs, POA&Ms, Risk Assessments, Implementation Plans, and other RMF artifacts. * Coordinate with SCAs, AOs, Cyber Leads, and program stakeholders to resolve findings and adjudicate risk. * Prepare systems for ATO, IATT, reauthorization, and continuous monitoring. * Ensure compliant implementation of security controls per JSIG, NIST SP 800-53, DoDI 8510.01, ICD 503, and SAP/NSA requirements. * Track, remediate, and validate POA&Ms to ensure timely closure of vulnerabilities. * Conduct internal cybersecurity compliance assessments and inspection-ready reviews. * Support DCSA, SAP, NSA, and customer cybersecurity inspections. * Evaluate system architecture changes for compliance and cybersecurity impact. * Provide cybersecurity guidance and oversight to ISSOs, admins, engineers, and program staff. * Develop and present cybersecurity briefings and risk recommendations to leadership and government customers. * Maintain strong working relationships with AOs, SCAs, FSOs, SAP Security, program management, and system owners. * Support cybersecurity incident response, vulnerability management, continuous monitoring, and reporting. * Ensure all authorization and cybersecurity documentation remains current and inspection-ready. * Manage cybersecurity across a multi-system classified portfolio. ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [AI Pair Programming with GitHub Copilot at SAP: Looking Back, Looking Forward!](https://www.wearedevelopers.com/videos/1546-ai-pair-programming-with-github-copilot-at-sap-looking-back-looking-forward) - [What makes Cybersecurity different for critical infrastructure?](https://www.wearedevelopers.com/videos/571-what-makes-cybersecurity-different-for-critical-infrastructure) - [Beyond GPT: Building Unified GenAI Platforms for the Enterprise of Tomorrow](https://www.wearedevelopers.com/videos/1525-beyond-gpt-building-unified-genai-platforms-for-the-enterprise-of-tomorrow) - [One Pipeline, Three Regulator - SBOM Compliance for the Developer](https://www.wearedevelopers.com/videos/100169-one-pipeline-three-regulator-sbom-compliance-for-the-developer) - [Remote Driving on Plant Grounds with State-of-the-Art Cloud Technologies](https://www.wearedevelopers.com/videos/251-remote-driving-on-plant-grounds-with-state-of-the-art-cloud-technologies) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [The Overflow: Security and Privacy](https://www.wearedevelopers.com/magazine/715-the-overflow-security-and-privacy)