All roles
Apply for this role →
Information Systems Security Officer (ISSO)
Posted 09/22/2026
As an Information Systems Security Officer (ISSO), you will lead the Risk Management Framework (RMF) lifecycle and manage the Authorization to Operate (ATO) process for assigned government systems. Key responsibilities include developing critical security artifacts (SSP, SAP, SAR, POA&M) in eMASS, conducting continuous security reviews, hardening software components, and ensuring strict NIST and FISMA compliance.An active DoD Secret or Top Secret clearance is required at the time of hire.
What you will do
- Serve as the primary cybersecurity point of contact for assigned information systems throughout the RMF lifecycle.
- Lead the RMF process for assigned programs, organizations, systems, or enclaves.
- Register and maintain the system in eMASS.
- Lead or support development of all RMF documentation including the System Security Plan, Security Assessment Plan, and Security Assessment Report.
- Assemble the Security Authorization Package and submit it for adjudication.
- Manage POA&M entries, ensuring vulnerabilities are properly tracked, mitigated, and resolved.
- Perform annual security reviews, annual testing of security controls, and annual contingency plan testing in line with FISMA requirements.
- Maintain and update existing ATO documentation — SSP, SLA, Incident Response Plan, Patch Management Plan.
- Harden newly introduced software components using DoD Security Requirements Guides and Security Technical Implementation Guides.
- Work closely with government cybersecurity leads and the ISSM to support Interim Authorization to Operate and Authorization to Operate.
What we are looking for
- Active DoD Secret or Top Secret clearance.
- Three to five years of direct experience supporting RMF and ATO processes within DoD or federal environments.
- Bachelor's degree in information systems, cybersecurity, computer science, or related field — or equivalent experience.
- Hands-on eMASS, or a comparable GRC platform such as Xacta.
- Working knowledge of NIST SP 800-53 Revision 5 and DoDI 8510.01.
- Continuous monitoring experience and the ability to interpret scan results.
Nice to have
- CISSP, CISM, CGRC, or CASP+/SecurityX.
- Cloud ISSO experience — the fastest-growing subtype. IL2, IL4, Secret and Top Secret impact levels; AWS GuardDuty, Security Hub, Config, and Organizations with SCPs.
- eMASSer or comparable automation tooling.
- Experience during the 800-53 Rev 4 to Rev 5 transition.
What we offer
- A skills-first hiring approach focused on demonstrated capability, not résumé keywords alone.
- EC-Council accredited training, with access to industry-recognized certification pathways.
- Support to learn, certify, and advance your career, with development aligned to real employer requirements.
- Exposure to commercial, government, and defense-aligned opportunities, where applicable.
- Support throughout the matching, interview, placement, and career progression process.
Skills and expertise
eMASS
Xacta 360
ACAS / Tenable Nessus
DISA STIGs and SRGs
SCAP Compliance Checker
STIG Viewer
Splunk
NIST SP 800-53 Rev 5
NIST 800-37
DoDI 8510.01
FISMA
AWS GuardDuty / Security Hub / Config