> Markdown version of [/jobs/ext/616363-information-systems-security-officer-isso](https://www.wearedevelopers.com/jobs/ext/616363-information-systems-security-officer-isso). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Information Systems Security Officer (ISSO) - **Company:** BERRYVILLE HOLDINGS, LLC - **Location:** Herndon, VA, United States - **Experience:** Experienced - **Salary:** $120,000.0 - $137,000.0 - **Contract:** Permanent contract - **Skills:** Antivirus Softwares, Software System Penetration Testing, Audit Trail, CompTIA Security+, Cyber Security, Information Systems, Monitoring of Systems, Intrusion Detection Systems, Software Vulnerability Management, Firewalls (Computer Science), Information Technology, CIS Benchmarks, Vulnerability Analysis - **Published:** June 24, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=44facb397a3bbf91 ## About the Role Do you have experience in Vulnerability management?, Do you have a Bachelor's degree?, · Active Top Secret (TS) clearance or the ability to obtain and maintain TS eligibility. · Bachelor's degree in Information Security, Computer Science, Information Technology, Cybersecurity, or a related discipline. Equivalent combinations of education and experience may be considered. · Minimum of 3-5 years of experience in information security, cybersecurity, information assurance, compliance, or a related field. · Demonstrated experience implementing and maintaining security frameworks and standards, including NIST, ISO 27001, CIS Controls, and other applicable regulatory requirements. · Strong understanding of risk management, security controls, vulnerability management, incident response, and compliance processes. · Relevant certifications are highly desirable, including CISSP, CISM, GSLC, CISM, CEH, CompTIA Security+, SecurityX (CASP+), or similar cybersecurity credentials. · Excellent written and verbal communication skills, with the ability to develop security documentation and communicate technical concepts to both technical and non-technical audiences. · Strong understanding of information security principles, best practices, and industry standards. · Proficiency with security technologies and tools, including vulnerability management, endpoint protection, security monitoring, access control, and compliance management solutions. · Demonstrated ability to identify, assess, and mitigate security risks across systems, networks, and applications. · Excellent analytical, troubleshooting, and problem-solving skills with the ability to evaluate complex security issues and develop effective solutions. · Strong written and verbal communication skills, including the ability to prepare technical documentation, policies, procedures, and executive-level reports. · Effective interpersonal skills with the ability to collaborate across technical and non-technical teams and build strong working relationships. · Ability to manage multiple priorities, work independently with minimal supervision, and meet deadlines in a fast-paced environment. · Strong organizational skills and attention to detail, particularly in maintaining compliance documentation and audit records. · Ability to function effectively as both an individual contributor and a collaborative member of a multidisciplinary team., * Are you familiar with RMF, ATO, NIST, and other security compliance documentation? * How many years of cybersecurity or information security experience do you have? * How familiar are you with CMMC, ISO, FEDRamp, and eMASS? * Do you have experience helping to prepare or maintain security documentation, such as System Security Plans, POA&Ms, or assessment evidence? ## Description Berryville Holdings LLC is seeking a highly motivated and detail-oriented Information Systems Security Officer (ISSO) to support the development, implementation, and maintenance of the organization's cybersecurity, risk management, and compliance programs. The ISSO serves as a key member of the security team and is responsible for ensuring information systems, networks, applications, and business operations remain compliant with applicable security requirements, industry standards, and regulatory frameworks. This role works closely with technical teams, leadership, auditors, and stakeholders to identify and mitigate cybersecurity risks, maintain security controls, support compliance initiatives, manage security incidents, and strengthen the organization's overall security posture. The ideal candidate possesses a strong understanding of information security principles, risk management methodologies, security governance, and compliance frameworks, including NIST SP 800-53, NIST SP 800-171, CMMC, FISMA, and ISO 27001. The successful candidate will serve as a trusted security advisor, helping ensure the confidentiality, integrity, and availability of organizational systems and data while supporting business objectives and operational excellence. Key Responsibilities Security Policy and Compliance: · Develop, implement, and maintain security policies, procedures, and protocols. · Ensure compliance with applicable federal, state, and local regulations, contractual requirements, and cybersecurity frameworks, including FISMA, NIST 800-53, NIST 800-171, CMMC, and ISO 27001. · Conduct regular audits and assessments to ensure adherence to security policies. Risk Management: · Identify, assess, document, and prioritize information security risks across systems, applications, and business processes. · Develop, implement, and monitor risk mitigation strategies, security controls, and corrective actions to reduce organizational risk and support compliance objectives. · Conduct and coordinate vulnerability assessments, security reviews, and penetration testing activities, tracking findings through remediation and closure. Incident Response: · Develop and maintain an incident response plan. · Coordinate and manage security incidents and breaches. · Conduct forensic investigations and root cause analysis. Security Training and Awareness: · Develop, coordinate, and deliver security awareness and training programs to educate employees on cybersecurity best practices, policies, and compliance requirements. · Promote a culture of security throughout the organization by increasing awareness of security risks, responsibilities, and emerging threats. · Evaluate the effectiveness of security awareness initiatives and recommend improvements to strengthen the organization's security posture. System Monitoring and Maintenance: · Monitor information systems for security incidents and vulnerabilities. · Implement and manage security tools and technologies (e.g., firewalls, intrusion detection systems, antivirus software). · Ensure systems are patched and updated regularly. Documentation and Reporting: · Collaborate with cross-functional teams to ensure security requirements and controls are integrated into systems, applications, and operational processes. · Serve as the primary point of contact for information security matters, providing guidance and support to internal stakeholders. · Prepare and deliver regular security status updates, risk assessments, and incident reports to executive leadership and other stakeholders. · Develop, maintain, and continuously improve security documentation, including policies, procedures, standards, plans, and incident records. · Coordinate the preparation and submission of required security documentation and reports to auditors and regulatory agencies. · Maintain comprehensive records of security assessments, audits, authorizations, findings, and remediation activities to support compliance and accreditation efforts. · Track and document corrective actions to ensure timely resolution of identified vulnerabilities and compliance deficiencies. · Support internal and external audits by providing requested evidence, documentation, and subject matter expertise. ## Related Videos - [One Pipeline, Three Regulator - SBOM Compliance for the Developer](https://www.wearedevelopers.com/videos/100169-one-pipeline-three-regulator-sbom-compliance-for-the-developer) - [A practical guide to writing secure Dockerfiles](https://www.wearedevelopers.com/videos/109-a-practical-guide-to-writing-secure-dockerfiles) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [Resilient by Design: Building Robust Architectures in High-Stakes Financial Systems](https://www.wearedevelopers.com/videos/2106-resilient-by-design-building-robust-architectures-in-high-stakes-financial-systems) - [What makes Cybersecurity different for critical infrastructure?](https://www.wearedevelopers.com/videos/571-what-makes-cybersecurity-different-for-critical-infrastructure) - [Cyber Security: Small, and Large!](https://www.wearedevelopers.com/videos/259-cyber-security-small-and-large) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [The Overflow: Security and Privacy](https://www.wearedevelopers.com/magazine/715-the-overflow-security-and-privacy) - [How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again](https://www.wearedevelopers.com/magazine/751-how-we-built-a-worry-free-system-that-runs-for-10-years-and-what-we-d-do-again) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities)