> Markdown version of [/jobs/ext/600815-information-systems-security-officer-lvl-2-rmf-compliance](https://www.wearedevelopers.com/jobs/ext/600815-information-systems-security-officer-lvl-2-rmf-compliance). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Information Systems Security Officer Lvl 2 - RMF & Compliance - **Company:** NineFX, Inc. - **Location:** Fort Meade, MD, United States - **Experience:** Experienced - **Contract:** Permanent contract - **Skills:** Xacta, Audit Trail, Configuration Management, Communications Protocols, Cyber Security, Information Systems, Firmware, Identity and Access Management, Information Security Management, Software Asset Management, Software Security, Information Technology, Legacy Systems, Vulnerability Analysis - **Published:** June 22, 2026 - **Apply:** https://www.clearancejobs.com/jobs/8989195/information-systems-security-officer-lvl-2-rmf-compliance ## About the Role * Top Secret/SCI with Full Scope Polygraph - No Exceptions * 10 years of ISSO experience with similar scope and complexity * Bachelor's degree in Computer Science or related discipline * Four (4) additional years of ISSO experience may substitute for a degree * Must have one IAM Level I certification (CAP, CND, Cloud+, GSLC, Security+ CE, HCISPP) ## Description The Information Systems Security Officer Level 2 supports the security posture, authorization activities, and daily IA operations of assigned systems, enclaves, and programs. This role implements and enforces information systems security policies, performs system security documentation updates, supports RMF (NIST) compliance, and conducts vulnerability assessments, POA&M remediation, and configuration management of security relevant components. Core Responsibilities * Support implementation and enforcement of information system security policies and standards * Assist with developing and maintaining IA documentation to include SSPs, SRTMs, Risk Assessments, and C&A packages * Evaluate security solutions to ensure compliance with classified processing requirements * Maintain system security posture and support day to day IA operations * Provide Configuration Management (CM) for security relevant software, hardware, and firmware * Manage and track system changes and assess associated security impacts * Support senior ISSOs and ISSMs in IA posture management for systems and enclaves * Administer identification and authentication mechanisms for Information Systems * Perform vulnerability and risk assessments and support remediation efforts * Support security authorization packages in alignment with NIST RMF * Maintain records of workstations, servers, routers, switches, firewalls, and other components * Assist in obtaining and maintaining C&A/ATO status for assigned systems * Plan, coordinate, and enforce IT security programs and policies * Serve as approval authority for systems under assigned purview (as designated) Technical Requirements * Experience with security tools, hardware/software security implementation, encryption methods, and communication protocols * Experience performing: - Hardware & software inventory updates and change log maintenance - STE/STN security processes - LatteArt and Gatekeeper workflows - Reviewing XACTA notices - Completing SEAR audit log records - Reviewing and addressing POA&Ms for IAVA vulnerabilities - Reviewing scans and coordinating remediation with system owners/admins - Security incident response reporting - Authorization activities for new and legacy systems ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Playing Pong on a shoulder press machine](https://www.wearedevelopers.com/videos/100140-playing-pong-on-a-shoulder-press-machine) - [Resilient by Design: Building Robust Architectures in High-Stakes Financial Systems](https://www.wearedevelopers.com/videos/2106-resilient-by-design-building-robust-architectures-in-high-stakes-financial-systems) - [One Pipeline, Three Regulator - SBOM Compliance for the Developer](https://www.wearedevelopers.com/videos/100169-one-pipeline-three-regulator-sbom-compliance-for-the-developer) - [Agent Smith Gets Hardware: Autonomous IoT Hacking From Debug Port to Cloud API](https://www.wearedevelopers.com/videos/100258-agent-smith-gets-hardware-autonomous-iot-hacking-from-debug-port-to-cloud-api) - [No Keys for the Robot: GitOps as the Control Plane for Autonomous Agents](https://www.wearedevelopers.com/videos/100095-no-keys-for-the-robot-gitops-as-the-control-plane-for-autonomous-agents) ## Related Articles - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [The Overflow: Security and Privacy](https://www.wearedevelopers.com/magazine/715-the-overflow-security-and-privacy) - [Best Paying Jobs in Technology](https://www.wearedevelopers.com/magazine/256-best-paying-jobs-in-technology) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Is Software Engineering Over-Saturated?](https://www.wearedevelopers.com/magazine/418-is-software-engineering-over-saturated)