> Markdown version of [/jobs/ext/3037836-4535-isso](https://www.wearedevelopers.com/jobs/ext/3037836-4535-isso). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # 4535 ISSO - **Company:** Procession Systems - **Location:** Fort Meade, MD, United States - **Contract:** Permanent contract - **Skills:** Configuration Management, Cyber Security, Information Systems, Firmware, Information Security Management, Software Requirements Analysis, Software Vulnerability Management, Network Routers, Firewalls (Computer Science), Network Server, User Identification - **Published:** September 23, 2026 - **Apply:** https://www.clearancejobs.com/jobs/9182530/4535-isso ## About the Role * Bachelor's degree in a technical, cybersecurity, information assurance, or related discipline from an accredited college or university is required. Five (5) years of additional information assurance, cybersecurity, or security engineering experience may be substituted for a bachelor's degree. * Experience supporting ISSO, information assurance, cybersecurity compliance, security authorization, or RMF activities on programs and contracts of similar scope, type, and complexity is required. * Must meet applicable DoW 8140/8570 requirements for the position. Preferred certifications may include Security+, CySA+, CASP+, CISSP, CAP, or equivalent cybersecurity, information assurance, or RMF-related credentials., * Experience with SSPs, A&A packages, SRTMs, vulnerability management, continuous monitoring, classified information systems, DoW/IC security policies, and NIST RMF processes is preferred. ## Description * Support senior ISSOs and the ISSM in implementing, enforcing, and maintaining information systems security policies, standards, procedures, and methodologies. * Plan, coordinate, and support IT security programs and policies, including development and maintenance of system security policies that support compliance with customer, IC, DoW, and NIST RMF requirements. * Maintain and update required security documentation, including System Security Plans (SSPs), Risk Assessment Reports, Assessment and Authorization (A&A) packages, System Requirements * Traceability Matrices (SRTMs), and other information assurance documentation. * Support security authorization and A&A activities in accordance with applicable IC, DoW, customer, and NIST RMF policies, including preparation and coordination of authorization artifacts. * Perform vulnerability, compliance, and risk-assessment analysis to support certification, accreditation, continuous monitoring, and remediation activities. * Evaluate security solutions, system changes, and configuration updates to determine security impact and suitability for systems processing classified information. * Provide security-relevant Configuration Management (CM) support for information system software, hardware, firmware, and system components, including maintaining records for workstations, servers, routers, firewalls, hubs, switches, upgrades, and related assets. * Support day-to-day security operations, including user identification and authentication processes, security control monitoring, incident coordination, compliance tracking, and transition activities associated with ConMon activities. ## Related Videos - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [Playing Pong on a shoulder press machine](https://www.wearedevelopers.com/videos/100140-playing-pong-on-a-shoulder-press-machine) - [Kubernetes Security - Challenge and Opportunity](https://www.wearedevelopers.com/videos/412-kubernetes-security-challenge-and-opportunity) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [One Pipeline, Three Regulator - SBOM Compliance for the Developer](https://www.wearedevelopers.com/videos/100169-one-pipeline-three-regulator-sbom-compliance-for-the-developer) - [tRPC: API schemas are pure overhead](https://www.wearedevelopers.com/videos/796-trpc-api-schemas-are-pure-overhead) ## Related Articles - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again](https://www.wearedevelopers.com/magazine/751-how-we-built-a-worry-free-system-that-runs-for-10-years-and-what-we-d-do-again) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [What Makes WeAreDevelopers World Congress Different From Every Other Tech Event?](https://www.wearedevelopers.com/magazine/701-what-makes-wearedevelopers-world-congress-different-from-every-other-tech-event) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities)