Information Systems Security Officer (ISSO)

BERRYVILLE HOLDINGS, LLC
Herndon, VA, United States
2 months ago
Apply on indeed.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Experienced
Experience required
3 years minimum
Compensation
$120,000.0 - $137,000.0
Working hours
Regular working hours
Job source

Tech stack

Antivirus Softwares Software System Penetration Testing Audit Trail CompTIA Security+ Cyber Security Information Systems Monitoring of Systems Intrusion Detection Systems Software Vulnerability Management Firewalls (Computer Science) Information Technology CIS Benchmarks
+1 more
Vulnerability Analysis

Job description

Berryville Holdings LLC is seeking a highly motivated and detail-oriented Information Systems Security Officer (ISSO) to support the development, implementation, and maintenance of the organization’s cybersecurity, risk management, and compliance programs. The ISSO serves as a key member of the security team and is responsible for ensuring information systems, networks, applications, and business operations remain compliant with applicable security requirements, industry standards, and regulatory frameworks.

This role works closely with technical teams, leadership, auditors, and stakeholders to identify and mitigate cybersecurity risks, maintain security controls, support compliance initiatives, manage security incidents, and strengthen the organization’s overall security posture. The ideal candidate possesses a strong understanding of information security principles, risk management methodologies, security governance, and compliance frameworks, including NIST SP 800-53, NIST SP 800-171, CMMC, FISMA, and ISO 27001.

The successful candidate will serve as a trusted security advisor, helping ensure the confidentiality, integrity, and availability of organizational systems and data while supporting business objectives and operational excellence.

Key Responsibilities

Security Policy and Compliance:

· Develop, implement, and maintain security policies, procedures, and protocols.

· Ensure compliance with applicable federal, state, and local regulations, contractual requirements, and cybersecurity frameworks, including FISMA, NIST 800-53, NIST 800-171, CMMC, and ISO 27001.

· Conduct regular audits and assessments to ensure adherence to security policies.

Risk Management:

· Identify, assess, document, and prioritize information security risks across systems, applications, and business processes.

· Develop, implement, and monitor risk mitigation strategies, security controls, and corrective actions to reduce organizational risk and support compliance objectives.

· Conduct and coordinate vulnerability assessments, security reviews, and penetration testing activities, tracking findings through remediation and closure.

Incident Response:

· Develop and maintain an incident response plan.

· Coordinate and manage security incidents and breaches.

· Conduct forensic investigations and root cause analysis.

Security Training and Awareness:

· Develop, coordinate, and deliver security awareness and training programs to educate employees on cybersecurity best practices, policies, and compliance requirements.

· Promote a culture of security throughout the organization by increasing awareness of security risks, responsibilities, and emerging threats.

· Evaluate the effectiveness of security awareness initiatives and recommend improvements to strengthen the organization’s security posture.

System Monitoring and Maintenance:

· Monitor information systems for security incidents and vulnerabilities.

· Implement and manage security tools and technologies (e.g., firewalls, intrusion detection systems, antivirus software).

· Ensure systems are patched and updated regularly.

Documentation and Reporting:

· Collaborate with cross-functional teams to ensure security requirements and controls are integrated into systems, applications, and operational processes.

· Serve as the primary point of contact for information security matters, providing guidance and support to internal stakeholders.

· Prepare and deliver regular security status updates, risk assessments, and incident reports to executive leadership and other stakeholders.

· Develop, maintain, and continuously improve security documentation, including policies, procedures, standards, plans, and incident records.

· Coordinate the preparation and submission of required security documentation and reports to auditors and regulatory agencies.

· Maintain comprehensive records of security assessments, audits, authorizations, findings, and remediation activities to support compliance and accreditation efforts.

· Track and document corrective actions to ensure timely resolution of identified vulnerabilities and compliance deficiencies.

· Support internal and external audits by providing requested evidence, documentation, and subject matter expertise.

Requirements

Do you have experience in Vulnerability management?, Do you have a Bachelor’s degree?, · Active Top Secret (TS) clearance or the ability to obtain and maintain TS eligibility.

· Bachelor’s degree in Information Security, Computer Science, Information Technology, Cybersecurity, or a related discipline. Equivalent combinations of education and experience may be considered.

· Minimum of 3-5 years of experience in information security, cybersecurity, information assurance, compliance, or a related field.

· Demonstrated experience implementing and maintaining security frameworks and standards, including NIST, ISO 27001, CIS Controls, and other applicable regulatory requirements.

· Strong understanding of risk management, security controls, vulnerability management, incident response, and compliance processes.

· Relevant certifications are highly desirable, including CISSP, CISM, GSLC, CISM, CEH, CompTIA Security+, SecurityX (CASP+), or similar cybersecurity credentials.

· Excellent written and verbal communication skills, with the ability to develop security documentation and communicate technical concepts to both technical and non-technical audiences.

· Strong understanding of information security principles, best practices, and industry standards.

· Proficiency with security technologies and tools, including vulnerability management, endpoint protection, security monitoring, access control, and compliance management solutions.

· Demonstrated ability to identify, assess, and mitigate security risks across systems, networks, and applications.

· Excellent analytical, troubleshooting, and problem-solving skills with the ability to evaluate complex security issues and develop effective solutions.

· Strong written and verbal communication skills, including the ability to prepare technical documentation, policies, procedures, and executive-level reports.

· Effective interpersonal skills with the ability to collaborate across technical and non-technical teams and build strong working relationships.

· Ability to manage multiple priorities, work independently with minimal supervision, and meet deadlines in a fast-paced environment.

· Strong organizational skills and attention to detail, particularly in maintaining compliance documentation and audit records.

· Ability to function effectively as both an individual contributor and a collaborative member of a multidisciplinary team., * Are you familiar with RMF, ATO, NIST, and other security compliance documentation?

  • How many years of cybersecurity or information security experience do you have?
  • How familiar are you with CMMC, ISO, FEDRamp, and eMASS?
  • Do you have experience helping to prepare or maintain security documentation, such as System Security Plans, POA&Ms, or assessment evidence?

Benefits & conditions

Pulled from the full job description

  • Tuition reimbursement
  • Prescription drug insurance
  • 401(k)
  • Health insurance
  • 401(k) matching
  • Paid time off
  • Vision insurance, The estimated salary for this position is $120K-$137K. This salary is not guaranteed and will depend on experience and qualifications.

Benefits & Perks

At Berryville Holdings, we believe top talent deserves top-tier support-that’s why we offer a benefits package that truly stands out. We cover 100% of your medical, dental, and vision premiums, along with company-paid life insurance and short- and long-term disability, so you can focus on your work and personal life-not your healthcare costs.

You’ll be enrolled in a Platinum-level medical plan with comprehensive prescription coverage, giving you and your family access to high-quality care with minimal out-of-pocket expenses.

We also invest in your future with a 401(k) Safe Harbor plan and a company match of up to 4%, plus educational assistance to support your continued growth and career advancement.

To support your lifestyle, we offer flexible work schedules, 11 paid federal holidays, and generous PTO starting at 15 days per year, with additional increases as you grow with the company.

Equal Opportunity Employer

Berryville Holdings is an Equal Opportunity Employer and considers all qualified applicants for employment regardless of race, color, religion, national origin, gender, sexual orientation, gender identity, age, physical or mental disabilities, genetic factors, veteran status, or other protected status as required by law.

Pay: $120,000.00 - $137,000.00 per year

About the company

Berryville Holdings LLC is a software development company dedicated to delivering innovative solutions for clients with advanced security and operational requirements that demand proactive security and strategic approaches. Based in Herndon, Virginia, near Washington, D.C., we have a network of highly skilled developers across the U.S. who create and support our unique software offerings. Join us to unlock your potential, apply your talents to meaningful and rewarding projects, and go beyond the limits of traditional software firms.

At Berryville Holdings, we aren’t content with just adding new skins to existing technologies - our software holds multiple patents and leads in cyber protection. We use all our own software in daily operations because we believe you can’t expect other companies to adopt your solutions if you’re not proud to use them yourself.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on indeed.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

5:03 min

Navigating new cybersecurity compliance frameworks and laws

Kurt Eder · LIVE

2:15 min

Auditing container configurations against CIS benchmark security standards

Madhu Akula · LIVE

4:11 min

Introduction to cloud-native application developer security

Micah Silverman · World Congress 2022

3:56 min

Leveraging GitOps for AI auditing and instant rollbacks

Jaroslaw Gajewski Jaroslaw Gajewski · World Congress 2026 Europe

3:39 min

Validating data queries and infrastructure security configurations

Philipp Krenn · World Congress 2023

3:44 min

Current industry adoption and future security initiatives

Alexander Allmendinger · LIVE

Videos

See all

Related articles

See all