> Markdown version of [/jobs/ext/3040462-information-systems-security-officer-isso-cyber-test-engineer-mid-lcat](https://www.wearedevelopers.com/jobs/ext/3040462-information-systems-security-officer-isso-cyber-test-engineer-mid-lcat). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Information Systems Security Officer (ISSO) (Cyber Test Engineer - Mid LCAT) - **Company:** Ennoble First - **Location:** Reston, VA, United States - **Experience:** Experienced - **Salary:** $110,000.0 - $140,000.0 - **Contract:** Permanent contract - **Skills:** Xacta, Amazon Web Services, Microsoft Azure, Cloud Computing, Cloud Computing Security, CompTIA Security+, Cyber Security, Information Systems, Decision Support Systems, Information Security Management, Systems Analysis, Internet Security, Network Security, Microsoft Security Essentials, Ansible, Zero Trust Network Access, Security Content Automation Protocol, Security Software, Information Technology, Operational Systems, Terraform, Splunk, Cisco, Vulnerability Analysis - **Published:** September 23, 2026 - **Apply:** https://www.careerbuilder.com/job-details/information-systems-security-officer-isso-cyber-test-engineer-mid-lcat-reston-va--d68e3152-aa22-498b-ae68-0b0bf4904869 ## About the Role * 3+ years of experience as an Information System Security Officer (ISSO) or Information System Security Analyst (ISSA) * Experience implementing and maintaining security controls for IT systems and cybersecurity tools * Experience conducting configuration assessments and risk analysis * Experience supporting RMF processes and security authorization activities * Experience with eMASS or Xacta IA Manager * Active TS/SCI clearance; willingness to take a polygraph exam Education * Associate's degree and 5+ years of experience supporting IT projects and activities, or * Bachelor's degree and 3+ years of experience supporting IT projects and activities, or * Master's degree and 1+ year of experience supporting IT projects and activities Certifications * Active DoD 8570 Information Assurance Technician (IAT) Level II certification (e.g., Security+ CE, CCNA-Security, CySA+, GICSP, GSEC, CND, or SSCP) * Must obtain a DoD 8570 Cybersecurity Service Provider (CSSP) - Infrastructure Support certification (e.g., CEH, CySA+, GICSP, SSCP, CHFI, CFR, Cloud+, or CND) prior to start date Desired Qualifications * Experience with DoD STIGs, SCAP, ACAS, and configuration assessment tools * Experience assessing security impacts of new COTS tools, upgrades, or configuration changes * Experience drafting or reviewing CONOPS, system topologies, and vulnerability scan results * Familiarity with tools such as Ansible, Terraform, Splunk, or STIG Viewer * Knowledge of cloud-native security tools and Zero Trust concepts * Strong written, verbal, and presentation skills * Ability to work effectively in a fast-paced, collaborative environment * AWS, Azure, or GCP certification, Access Authorization, Amazon Web Services (AWS), Ansible, Best Practices, CCNA - Cisco Certified Network Associate, Cloud Computing, Code of Federal Regulations, Commercial Off-the-Shelf (COTS), CompTIA Security+, Computer Network Defense (CND), Computer Security, Concept of Operations (CONOPS), Decision Support, Defense Intelligence, DoD Directive 8140, DoD Directive 8570, DoD Information Assurance - IA, Documentation, EEO Regulations, GCP (Good Clinical Practices), GSEC - GIAC Security Essentials Certification, Government, Government Requirements, Homeland Security, IAT - Information Assurance Technical, Information Technology & Information Systems, International Classification of Diseases (ICD), Internet Security, Microsoft Windows Azure, Operations Security (OPSEC), Presentation/Verbal Skills, Risk, Risk Analysis, SSCP - Systems Security Certified Practitioner, Security Analysis, Security Compliance, Sensitive Compartmented Information (SCI), Splunk, Systems Analysis, Team Player, Technical Support, Testing, Top Secret Clearance, Topology, Trademarks, U.S. National Institute of Standards and Technology (NIST), United States Department of Defense (DoD), Vendor/Supplier Evaluation, Vulnerability Scanners, Writing Skills ## Description Ennoble First is seeking an Information Systems Security Officer (ISSO) to support the assessment, implementation, and sustainment of security controls for developmental and operational cybersecurity tools in a mission-critical environment. The ISSO evaluates security configurations, identifies risks, and provides actionable recommendations to ensure systems comply with federal security requirements and achieve and maintain Authorization to Operate (ATO). This role works closely with engineers, vendors, and government stakeholders to translate cybersecurity policy and risk into secure, operational solutions. Primary Responsibilities * Assess and document security configurations for developmental and operational systems and tools * Conduct tools assessments and configuration analysis against vendor guidance, best practices, and government security requirements * Support implementation, oversight, and sustainment of security controls in accordance with RMF * Apply and evaluate controls from NIST 800-53, FedRAMP, ICD 503, RMF, and DoD Information Levels * Support system authorization activities including initial ATOs and ongoing continuous monitoring * Perform risk analysis and document findings, recommendations, and mitigation strategies * Coordinate with engineers, SMEs, subcontractors, and vendors to assess security impacts of system changes * Develop and deliver security documentation, briefings, and artifacts to support stakeholder decision-making ## Related Videos - [Our journey with Spring Boot in a microservice architecture](https://www.wearedevelopers.com/videos/511-our-journey-with-spring-boot-in-a-microservice-architecture) - [How Cisco embraced a DevOps culture within its network engineering team](https://www.wearedevelopers.com/videos/99-how-cisco-embraced-a-devops-culture-within-its-network-engineering-team) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Computer Vision from the Edge to the Cloud done easy](https://www.wearedevelopers.com/videos/263-computer-vision-from-the-edge-to-the-cloud-done-easy) - [DevSecOps culture](https://www.wearedevelopers.com/videos/783-devsecops-culture) - [Your Infrastructure Is Not a Playground: AI Agents for Infra Done Right](https://www.wearedevelopers.com/videos/2084-your-infrastructure-is-not-a-playground-ai-agents-for-infra-done-right) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again](https://www.wearedevelopers.com/magazine/751-how-we-built-a-worry-free-system-that-runs-for-10-years-and-what-we-d-do-again) - [Best Paying Jobs in Technology](https://www.wearedevelopers.com/magazine/256-best-paying-jobs-in-technology) - [The Overflow: Security and Privacy](https://www.wearedevelopers.com/magazine/715-the-overflow-security-and-privacy)