> Markdown version of [/jobs/ext/3529219-information-system-security-officer-isso](https://www.wearedevelopers.com/jobs/ext/3529219-information-system-security-officer-isso). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Information System Security Officer (ISSO) - **Company:** CACI International Inc. - **Location:** Reston, VA, United States - **Experience:** Expert - **Salary:** $90,300.0 - $189,600.0 - **Contract:** Permanent contract - **Skills:** Cloud Computing Security, Configuration Management, Cyber Security, Information Systems, Information Security Management, Smartsuite, Software Asset Management, Information Technology, Plan of Action and Milestones, Vulnerability Analysis - **Published:** October 1, 2026 - **Apply:** https://www.businessworkforce.com/job.asp?id=3410955540&tx=TT434THZ&pt=1&aff=0B19D771-A501-4A5E-8338-2A822B784D54&utm_source=Job%20Feed&utm_medium=textkernel&utm_campaign=DE&utm_term=0B19D771-A501-4A5E-8338-2A822B784D54 ## About the Role Required: * U.S. Citizenship required * DHS EOD suitability or Current DHS EOD preferred * BS/BA + 8 years of applicable experience in information security * 7+ years of experience in information security * Demonstrated expertise in RMF, Information Security processes, audits, tools, implementation, FISMA, NIST, IT security * Experience developing System Security Plans, POA&Ms, and Configuration Management Plans * Knowledge of NIST SP 800-37, NIST SP 800-53, and DHS 4300 Series requirements, * Certified Information Security Manager (CISM) * CompTIA Advanced Security Practitioner (CASP+) * Previous DHS experience * Experience with CSAM, RegScale, eMASS, or similar GRC tools * Experience supporting emergency operations or disaster response missions * Knowledge of cloud security and FedRAMP authorization processes * Experience with continuous monitoring and ## Description CACI is searching for an Information System Security Officer (ISSO) to support the DHS Headquarters. As an Information System Security Officer, you will play a crucial role in ensuring the security and compliance of DHS HQ's information systems. You will work in a dynamic environment, collaborating with IT system owners, stakeholders, and cybersecurity professionals to implement and maintain robust security controls. Your efforts will directly contribute to safeguarding DHS's mission-critical systems and data. The ISSO will serve as the single point of contact on all systems security matters, leading cybersecurity engineering efforts for assigned Program Management Organizations with direct support to the Compliance Branch Lead. This includes spearheading systems' ATO efforts and maintaining a security posture in compliance with FISMA, DHS 4300 Series, NIST, and DHS and Component Directives. The ISSO will execute complete Risk Management Framework (RMF) activities for Authority to Operate (ATO) decisions and ensure all security documentation is kept up to date., The ISSO will execute complete Risk Management Framework (RMF) activities for Authority to Operate (ATO) decisions including system categorization, security control selection and implementation, self-assessments, POA&M development, and continuous monitoring. This position requires developing and maintaining System Security Plans (SSPs) including control baselines, inheritance, Business Impact Analyses, implementation statements, technical and system descriptions, and hardware and software inventories. The ISSO will create and maintain Configuration Management Plans, conduct Security Impact Analyses, approve Change Requests, and document the security impact of configuration changes. Responsibilities include developing and testing Contingency Plans and Incident Response Plans to ensure business continuity, as well as conducting annual risk assessments, supporting security assessments, and vulnerability assessments across assigned systems. The position involves advising system owners and senior executives on all cybersecurity matters and developing remediation work plans for assessment and/or audit findings. The ISSO will maintain Hardware and Software Inventory Lists and conduct FISMA Scorecard Analysis. The ISSO will ensure proper access controls are implemented for system access, track and suggest technologies, processes, and practices designed to protect networks, devices, programs, and data from malicious attack, damage, or unauthorized access, and research and maintain proficiency in tools, techniques, countermeasures, and trends in computer and network vulnerabilities, data hiding, and network and device security and encryption. ## Related Videos - [One Pipeline, Three Regulator - SBOM Compliance for the Developer](https://www.wearedevelopers.com/videos/100169-one-pipeline-three-regulator-sbom-compliance-for-the-developer) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [Microservices? Monoliths? An Annoying Discussion!](https://www.wearedevelopers.com/videos/970-microservices-monoliths-an-annoying-discussion) - [DevSecOps culture](https://www.wearedevelopers.com/videos/783-devsecops-culture) - [Cyber Security: Small, and Large!](https://www.wearedevelopers.com/videos/259-cyber-security-small-and-large) - [Demystifying Crypto & Web3: A Technical Journey Through 15 Years of Innovation](https://www.wearedevelopers.com/videos/1516-demystifying-crypto-web3-a-technical-journey-through-15-years-of-innovation) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again](https://www.wearedevelopers.com/magazine/751-how-we-built-a-worry-free-system-that-runs-for-10-years-and-what-we-d-do-again) - [Best Paying Jobs in Technology](https://www.wearedevelopers.com/magazine/256-best-paying-jobs-in-technology) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [The Overflow: Security and Privacy](https://www.wearedevelopers.com/magazine/715-the-overflow-security-and-privacy)