> Markdown version of [/jobs/ext/3111242-information-system-security-officer](https://www.wearedevelopers.com/jobs/ext/3111242-information-system-security-officer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Information System Security Officer - **Company:** Booz Allen Hamilton Inc. - **Location:** Bethesda, MD, United States - **Experience:** Expert - **Salary:** $62,000.0 - $141,000.0 - **Contract:** Permanent contract - **Skills:** Information Security Management, Cyber Threat Analysis, Cybercrime - **Published:** September 27, 2026 - **Apply:** https://jobs.localjobnetwork.com/apply/add/88464683/1 ## About the Role * 5+ years of experience within cyber risk management or security compliance functions * 3+ years of experience supporting A&A activities at health or research-focused government entities * Experience applying NIST RMF across categorization, control selection or implementation, assessment, authorization, and continuous monitoring * Experience supporting A&A efforts and coordinating ATO decisions with authorizing officials * Experience performing security control assessments, producing artifacts such as Security Assessment Reports (SAR) and Plans of Action and Milestones (POA&Ms), and developing and maintaining security documentation, including System Security Plans (SSP) and control implementation statements * Knowledge of NIST SP 80053 Rev.5 control families and tailoring controls to impact levels * Knowledge of FISMA processes supporting RMF and authorization decisions * Ability to translate technical findings into risk statements and remediation recommendations aligned to mission and business priorities, plan and execute continuous monitoring (ConMon), track residual risk, and drive closure of POA&Ms * Public Trust * Bachelor's degree Nice If You Have: * Experience supporting the NIH and NCI * Experience communicating complex security concepts clearly to nontechnical stakeholders and senior leaders * Experience producing concise A&A documentation and executiveready summaries * Knowledge of structured writing and plainlanguage techniques for technical documentation * Knowledge of stakeholder analysis and change management to drive adoption of security recommendations * Ability to write crisply, edit meticulously, and proofread to ensure consistency across artifacts * Ability to facilitate working sessions, build consensus, and present recommendations confidently * Master's degree Vetting: Applicants selected will be subject to a government investigation and may need to meet eligibility requirements of the U.S. government client; Public Trust determination is required. ## Description Cyber threats evolve constantly. In this role, you'll turn complex risk into clear action by supporting Risk Management Framework (RMF) activities and driving Assessment and Authorization (A&A) packages through an Authorization to Operate (ATO). You'll partner with engineering and mission teams to scope controls, assess risk, remediate gaps, and sustain continuous monitoring so systems remain secure and compliant. ## Related Videos - [Cyber Sleuth: Finding Hidden Connections in Cyber Data](https://www.wearedevelopers.com/videos/893-cyber-sleuth-finding-hidden-connections-in-cyber-data) - [Don't Be A Naive Developer: How To Avoid Basic Cybersecurity Mistakes](https://www.wearedevelopers.com/videos/498-don-t-be-a-naive-developer-how-to-avoid-basic-cybersecurity-mistakes) - [Fighting the Next Wave of Cybercrime](https://www.wearedevelopers.com/videos/100331-fighting-the-next-wave-of-cybercrime) - [One Pipeline, Three Regulator - SBOM Compliance for the Developer](https://www.wearedevelopers.com/videos/100169-one-pipeline-three-regulator-sbom-compliance-for-the-developer) - [Forecasting Cyber Attacks with Glassdoor Reviews - Lianne Potter](https://www.wearedevelopers.com/videos/2143-forecasting-cyber-attacks-with-glassdoor-reviews-lianne-potter) - [You can’t hack what you can’t see](https://www.wearedevelopers.com/videos/41-you-can-t-hack-what-you-can-t-see) ## Related Articles - [How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again](https://www.wearedevelopers.com/magazine/751-how-we-built-a-worry-free-system-that-runs-for-10-years-and-what-we-d-do-again) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Trustworthy AI Starts at Deployment: 5 Checks Before You Ship](https://www.wearedevelopers.com/magazine/753-trustworthy-ai-starts-at-deployment-5-checks-before-you-ship) - [The Overflow: Security and Privacy](https://www.wearedevelopers.com/magazine/715-the-overflow-security-and-privacy)