> Markdown version of [/jobs/ext/3632645-information-systems-security-officer-isso](https://www.wearedevelopers.com/jobs/ext/3632645-information-systems-security-officer-isso). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Information Systems Security Officer (ISSO) - **Company:** Caci Inc - **Location:** Fort Liberty, NC, United States - **Experience:** Expert - **Salary:** $71,500.0 - $150,200.0 - **Contract:** Permanent contract - **Skills:** Microsoft Windows, Audit Trail, Configuration Management, Cyber Security, Information Systems, Linux Security Modules, Security Content Automation Protocol, Nessus, Splunk, Vulnerability Analysis - **Published:** October 8, 2026 - **Apply:** https://www.clearancejobs.com/jobs/9226780/information-systems-security-officer-isso ## About the Role Required: * Current SECRET security clearance. * Bachelor's degree and 5+ years of relevant cybersecurity, information assurance, or RMF experience; associate degree and 7+ years of relevant experience; or equivalent directly relevant work experience. * DoD 8140/8570-aligned cybersecurity certification appropriate to the position; CISSP, Security+, CASP+, GCIH, GSLC, or other applicable certification. * Hands-on experience supporting the DoD Risk Management Framework (RMF) and maintaining cybersecurity authorization packages. * Experience using eMASS to document security controls, maintain artifacts, track findings, and support ATO activities. * Working knowledge of NIST SP 800-53 security controls, DoDI 8510.01, and applicable DoD cybersecurity requirements. * Experience reviewing security control implementation and supporting evidence. * Experience reviewing and analyzing audit logs using tools such as Splunk. * Experience with Nessus, SCAP, or comparable vulnerability/compliance tools. * Working knowledge of DISA Security Technical Implementation Guides (STIGs) and vulnerability scanning tools/processes. * Ability to develop and maintain cybersecurity documentation, including SSPs, POA&Ms, contingency plans, incident response plans, and configuration management documentation. * Excellent written and verbal communication skills and the ability to coordinate effectively with technical and non-technical stakeholders. Desired: * Experience supporting USASOC, Joint SOF, or other DoD organizations. * Experience with Windows and Linux security configuration and secure baselines. * Ability to work independently with limited Government oversight and function effectively as part of a joint working environment. ## Description As the CACI Information Systems Security Officer (ISSO) supporting the United States Army Special Operations Command (USASOC) G3 Risk Management Framework (RMF) project, you will provide day-to-day cybersecurity and RMF support to Special Operations Detachments (SODs) and other supported elements within the SOF Enterprise. You will help maintain the security posture of information systems supporting connectivity to the Special Operations Force Networks (SOFNET) and support systems throughout the RMF lifecycle, including initial authorization, continuous monitoring, and ATO sustainment., * Serve as an ISSO supporting assigned information systems in accordance with DoDI 8510.01, NIST SP 800-53, Rev 5 and applicable DoD cybersecurity requirements. * Develop, review, and maintain RMF authorization documentation, including System Security Plans, Configuration Management Plans, Contingency Plans, Disaster Recovery Plans, Incident Response Plans, and supporting security artifacts. * Maintain RMF security authorization packages in the Enterprise Mission Assurance Support Service (eMASS), including control implementation statements, evidence, artifacts, assessment results, and package updates. * Support continuous monitoring and ATO maintenance activities throughout the authorization lifecycle. * Review and validate security controls and support evidence to identify control gaps, deficiencies, and required remediation actions. * Coordinate with enterprise system administrators, ISSMs, and Government representatives to address cybersecurity requirements and maintain compliance. * Review vulnerability scans and compliance results and track remediation of identified vulnerabilities and findings. * Support DISA STIG compliance, security configuration validation, and documentation of applicable findings and exceptions. * Schedule and track vulnerability scans and reassessments of implemented security controls. * Perform periodic account and access reviews, including privileged, service, group, and inactive accounts, to support least privilege and access-control requirements.