> Markdown version of [/jobs/ext/3049882-information-systems-security-analyst-issa](https://www.wearedevelopers.com/jobs/ext/3049882-information-systems-security-analyst-issa). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Information Systems Security Analyst (ISSA) - **Company:** ZANTECH INC. - **Location:** Reston, VA, United States - **Contract:** Permanent contract - **Skills:** Apple IOS, Configuration Management, Cyber Security, Information Systems, Firmware, Identity and Access Management, Software Vulnerability Management, Information Technology, Plan of Action and Milestones, Vulnerability Analysis - **Published:** September 24, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=bb6281bd1e9e8109 ## About the Role * 1+ Years of experience working on ATOs for government systems * Ability to manage the Plan of Actions & Milestones (POA&M) documents associated with Information Systems. * Demonstrated on-the-job knowledge and experience of the Risk Management Framework (RMF) process and the National Institute of Standards and Technology (NIST) publications (specifically NIST 800-53 and NIST 800-37), including development and maintenance of associated certification and accreditation documentation. * Excellent writing, verbal communication, and time-management skills., + Bachelor's Degree in Information Systems, Information Assurance Management, Computer Science, or related field. + (May be substituted for relevant work experience) * Certifications Required: * + IAT Level II or IAM Level II DoD approved cybersecurity baseline certification, or higher. Required Security Clearance: * US Citizenship and the ability to obtain and maintain an active Secret or higher clearance, per contract requirements. ## Description * Conduct information system security inspections, tests, and reviews of the Risk Management Framework (RMF) Information Assurance Package to ensure ANG DSS maintains an Authority to Operate (ATO). Update artifacts and information within the Enterprise Mission Assurance Support Service (eMASS) to validate Security Controls and Assessments. Develop Plan of Actions and Milestones (POAMs) for non-compliant items. * Maintain a formal information system security program, including systems security plans, cyber security policies, security control assessments, contingency plans, configuration management plans, incident response plans, plan of actions and milestones, risk management plans, vulnerability scanning, and/or vulnerability management plans. * Ensures software, hardware, and firmware comply with appropriate security configuration guidelines (e.g., security technical implementation guides /security requirement guides). * Ensures cybersecurity-related events or configuration changes that impact AF IT authorization or adversely impact the security posture are formally reported to the Authorizing Official (AO) and other affected parties, such as Information Owners (IOs) and stewards and AOs of interconnected IT. * Coordinates with the Air National Guard Readiness Center's Risk Management Framework lead on eMASS related tasks. ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Xcode development redefAIned](https://www.wearedevelopers.com/videos/100195-xcode-development-redefained) - [Playing Pong on a shoulder press machine](https://www.wearedevelopers.com/videos/100140-playing-pong-on-a-shoulder-press-machine) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [Agent Smith Gets Hardware: Autonomous IoT Hacking From Debug Port to Cloud API](https://www.wearedevelopers.com/videos/100258-agent-smith-gets-hardware-autonomous-iot-hacking-from-debug-port-to-cloud-api) - [Maturity assessment for technicians or how I learned to love OWASP SAMM](https://www.wearedevelopers.com/videos/351-maturity-assessment-for-technicians-or-how-i-learned-to-love-owasp-samm) ## Related Articles - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [The Overflow: Security and Privacy](https://www.wearedevelopers.com/magazine/715-the-overflow-security-and-privacy) - [Building Security Champions](https://www.wearedevelopers.com/magazine/87-building-security-champions)