> Markdown version of [/jobs/ext/3080693-isso](https://www.wearedevelopers.com/jobs/ext/3080693-isso). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # ISSO - **Company:** Halvik Corp. - **Location:** Washington, DC, United States - **Contract:** Permanent contract - **Skills:** Cyber Security, System Configuration, Log Analysis, SARS Software Products, Cloud Platform System, SC Clearance, Information Technology, Cybercrime, Vulnerability Analysis - **Published:** September 25, 2026 - **Apply:** https://www.clearancejobs.com/jobs/9193546/isso ## About the Role * Education: Bachelor's degree in Information Technology or Business -OR- Associate's Degree and one (1) year relevant experience with professional certification * Experience: One+ years of information technology experience; minimum one year of ISSO experience preferred * Technical Proficiency: Proficient in planning for and performing audits to ensure compliance with agency and federal security requirements. Knowledge of and/or capability to review and develop system security plans and other required security documentation; perform vulnerability assessment scans or interpret results of scans and track mitigation actions and progress of system engineers and administrators; and perform certification and accreditation activities as required to ensure assigned systems remain accredited and risk is managed to an acceptable level. * Compliance: Ensure compliance with Federal cybersecurity regulations, including NIST, FISMA, and associated guidance. Ensure artifacts, assessments, and system configurations remain aligned with NIST SP 800-53 controls, FedRAMP baselines, Federal agency policy and directives. * Certifications: + Per education requirements above. * Must possess an active Secret clearance. Preferred Expertise * CISSP or equivalent Cybersecurity certification (e.g., Security+) preferred. * Demonstrated success supporting Federal contracts. * Strong background coordinating with stakeholders (e.g., system owners, ISSOs, architecture teams, and cybersecurity leadership) to validate cybersecurity requirements, address information assurance concerns, and resolve compliance or security issues. * Strong analytical, written, and verbal communication skills, with the ability to translate technical risks and content into terms suitable for executive and government stakeholders. * Ability to work collaboratively with others and contribute to a team environment. ## Description Halvik is seeking a candidate to support a Federal customer in implementing and maintaining security measures to protect the customer's systems, data, and networks from cyber threats. The position includes performing Information Assurance (IA) engineering activities that support cybersecurity posture and ensure compliance with applicable Federal requirements, and performing assessments and monitoring activities, and maintaining compliance with Federal security requirements. Core Responsibilities * Performing regular security assessments of networks, systems, applications, and cloud environments * Developing or supporting the development of incident response plans and conducting security training sessions * Monitoring compliance with applicable security standards, regulations, and NTIA security policies * Supporting continuous monitoring activities, including vulnerability scanning, log analysis, and remediation tracking * Preparing security assessment documentation such as SAPs, SARs, and POA&Ms in accordance with NIST RMF * Validating remediation effectiveness through retesting, evidence review, and compliance verification ## Related Videos - [Fighting the Next Wave of Cybercrime](https://www.wearedevelopers.com/videos/100331-fighting-the-next-wave-of-cybercrime) - [Progressive Delivery in Kubernetes](https://www.wearedevelopers.com/videos/949-progressive-delivery-in-kubernetes) - [One Pipeline, Three Regulator - SBOM Compliance for the Developer](https://www.wearedevelopers.com/videos/100169-one-pipeline-three-regulator-sbom-compliance-for-the-developer) - [Deep Fakes: The Lies We Can’t See](https://www.wearedevelopers.com/videos/1187-deep-fakes-the-lies-we-can-t-see) - [What makes Cybersecurity different for critical infrastructure?](https://www.wearedevelopers.com/videos/571-what-makes-cybersecurity-different-for-critical-infrastructure) - [Leveraging Large Language Models for Legacy Code Translation: Challenges and Solutions](https://www.wearedevelopers.com/videos/1157-leveraging-large-language-models-for-legacy-code-translation-challenges-and-solutions) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again](https://www.wearedevelopers.com/magazine/751-how-we-built-a-worry-free-system-that-runs-for-10-years-and-what-we-d-do-again) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities)