Information Systems Security Officer (ISSO)
- Discuss this with your agent
- Open in Claude
- Open in ChatGPT
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Role details
Tech stack
+1 more
Job description
Berryville Holdings LLC is seeking a highly motivated and detail-oriented Information Systems Security Officer (ISSO) to support the development, implementation, and maintenance of the organization’s cybersecurity, risk management, and compliance programs. The ISSO serves as a key member of the security team and is responsible for ensuring information systems, networks, applications, and business operations remain compliant with applicable security requirements, industry standards, and regulatory frameworks.
This role works closely with technical teams, leadership, auditors, and stakeholders to identify and mitigate cybersecurity risks, maintain security controls, support compliance initiatives, manage security incidents, and strengthen the organization’s overall security posture. The ideal candidate possesses a strong understanding of information security principles, risk management methodologies, security governance, and compliance frameworks, including NIST SP 800-53, NIST SP 800-171, CMMC, FISMA, and ISO 27001.
The successful candidate will serve as a trusted security advisor, helping ensure the confidentiality, integrity, and availability of organizational systems and data while supporting business objectives and operational excellence.
Key Responsibilities
Security Policy and Compliance:
· Develop, implement, and maintain security policies, procedures, and protocols.
· Ensure compliance with applicable federal, state, and local regulations, contractual requirements, and cybersecurity frameworks, including FISMA, NIST 800-53, NIST 800-171, CMMC, and ISO 27001.
· Conduct regular audits and assessments to ensure adherence to security policies.
Risk Management:
· Identify, assess, document, and prioritize information security risks across systems, applications, and business processes.
· Develop, implement, and monitor risk mitigation strategies, security controls, and corrective actions to reduce organizational risk and support compliance objectives.
· Conduct and coordinate vulnerability assessments, security reviews, and penetration testing activities, tracking findings through remediation and closure.
Incident Response:
· Develop and maintain an incident response plan.
· Coordinate and manage security incidents and breaches.
· Conduct forensic investigations and root cause analysis.
Security Training and Awareness:
· Develop, coordinate, and deliver security awareness and training programs to educate employees on cybersecurity best practices, policies, and compliance requirements.
· Promote a culture of security throughout the organization by increasing awareness of security risks, responsibilities, and emerging threats.
· Evaluate the effectiveness of security awareness initiatives and recommend improvements to strengthen the organization’s security posture.
System Monitoring and Maintenance:
· Monitor information systems for security incidents and vulnerabilities.
· Implement and manage security tools and technologies (e.g., firewalls, intrusion detection systems, antivirus software).
· Ensure systems are patched and updated regularly.
Documentation and Reporting:
· Collaborate with cross-functional teams to ensure security requirements and controls are integrated into systems, applications, and operational processes.
· Serve as the primary point of contact for information security matters, providing guidance and support to internal stakeholders.
· Prepare and deliver regular security status updates, risk assessments, and incident reports to executive leadership and other stakeholders.
· Develop, maintain, and continuously improve security documentation, including policies, procedures, standards, plans, and incident records.
· Coordinate the preparation and submission of required security documentation and reports to auditors and regulatory agencies.
· Maintain comprehensive records of security assessments, audits, authorizations, findings, and remediation activities to support compliance and accreditation efforts.
· Track and document corrective actions to ensure timely resolution of identified vulnerabilities and compliance deficiencies.
· Support internal and external audits by providing requested evidence, documentation, and subject matter expertise.
Requirements
Do you have experience in Vulnerability management?, Do you have a Bachelor’s degree?, · Active Top Secret (TS) clearance or the ability to obtain and maintain TS eligibility.
· Bachelor’s degree in Information Security, Computer Science, Information Technology, Cybersecurity, or a related discipline. Equivalent combinations of education and experience may be considered.
· Minimum of 3-5 years of experience in information security, cybersecurity, information assurance, compliance, or a related field.
· Demonstrated experience implementing and maintaining security frameworks and standards, including NIST, ISO 27001, CIS Controls, and other applicable regulatory requirements.
· Strong understanding of risk management, security controls, vulnerability management, incident response, and compliance processes.
· Relevant certifications are highly desirable, including CISSP, CISM, GSLC, CISM, CEH, CompTIA Security+, SecurityX (CASP+), or similar cybersecurity credentials.
· Excellent written and verbal communication skills, with the ability to develop security documentation and communicate technical concepts to both technical and non-technical audiences.
· Strong understanding of information security principles, best practices, and industry standards.
· Proficiency with security technologies and tools, including vulnerability management, endpoint protection, security monitoring, access control, and compliance management solutions.
· Demonstrated ability to identify, assess, and mitigate security risks across systems, networks, and applications.
· Excellent analytical, troubleshooting, and problem-solving skills with the ability to evaluate complex security issues and develop effective solutions.
· Strong written and verbal communication skills, including the ability to prepare technical documentation, policies, procedures, and executive-level reports.
· Effective interpersonal skills with the ability to collaborate across technical and non-technical teams and build strong working relationships.
· Ability to manage multiple priorities, work independently with minimal supervision, and meet deadlines in a fast-paced environment.
· Strong organizational skills and attention to detail, particularly in maintaining compliance documentation and audit records.
· Ability to function effectively as both an individual contributor and a collaborative member of a multidisciplinary team., * Are you familiar with RMF, ATO, NIST, and other security compliance documentation?
- How many years of cybersecurity or information security experience do you have?
- How familiar are you with CMMC, ISO, FEDRamp, and eMASS?
- Do you have experience helping to prepare or maintain security documentation, such as System Security Plans, POA&Ms, or assessment evidence?
Benefits & conditions
Pulled from the full job description
- Tuition reimbursement
- Prescription drug insurance
- 401(k)
- Health insurance
- 401(k) matching
- Paid time off
- Vision insurance, The estimated salary for this position is $120K-$137K. This salary is not guaranteed and will depend on experience and qualifications.
Benefits & Perks
At Berryville Holdings, we believe top talent deserves top-tier support-that’s why we offer a benefits package that truly stands out. We cover 100% of your medical, dental, and vision premiums, along with company-paid life insurance and short- and long-term disability, so you can focus on your work and personal life-not your healthcare costs.
You’ll be enrolled in a Platinum-level medical plan with comprehensive prescription coverage, giving you and your family access to high-quality care with minimal out-of-pocket expenses.
We also invest in your future with a 401(k) Safe Harbor plan and a company match of up to 4%, plus educational assistance to support your continued growth and career advancement.
To support your lifestyle, we offer flexible work schedules, 11 paid federal holidays, and generous PTO starting at 15 days per year, with additional increases as you grow with the company.
Equal Opportunity Employer
Berryville Holdings is an Equal Opportunity Employer and considers all qualified applicants for employment regardless of race, color, religion, national origin, gender, sexual orientation, gender identity, age, physical or mental disabilities, genetic factors, veteran status, or other protected status as required by law.
Pay: $120,000.00 - $137,000.00 per year
About the company
Berryville Holdings LLC is a software development company dedicated to delivering innovative solutions for clients with advanced security and operational requirements that demand proactive security and strategic approaches. Based in Herndon, Virginia, near Washington, D.C., we have a network of highly skilled developers across the U.S. who create and support our unique software offerings. Join us to unlock your potential, apply your talents to meaningful and rewarding projects, and go beyond the limits of traditional software firms.
At Berryville Holdings, we aren’t content with just adding new skins to existing technologies - our software holds multiple patents and leads in cyber protection. We use all our own software in daily operations because we believe you can’t expect other companies to adopt your solutions if you’re not proud to use them yourself.
Apply for this position
This job is hosted externally. Click below to view the full posting and apply.
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Good distractions
Talks and stories from around this role — technically off-topic, practically not.
Moments
Explore playlistsVideos
See allRelated articles
See all
Dev Digest 134 - Where pixels sing?
Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.
The Overflow: Security and Privacy
How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again