Information System Security Officers (ISSO - Mid Level)
Agile Defense›
📍Washington, DC, US
Posted 3w ago · via lever
Apply on lever→Job Description
Requisition #: 1502
Job Title for Careers Page: Information System Security Officers (ISSO)
Location: Hybrid, Washington, D.C. (3 days onsite, 2 remote days)
Clearance Level: Public Trust
Required Certification(s): CISSP or Security +
SUMMARY: The Information System Security Officers (ISSO) bring valuable technical, policy, and business knowledge and advice to inform system security and risk management required to maintain the security posture of each IT system within defined portfolios
JOB DUTIES AND RESPONSIBILITIES:
Serve as the primary liaison between the Cybersecurity Group, system owners, ECCP, and information owners on security and risk matters.
Ensure systems follow security policies, including vulnerability scanning, patching, and configuration management.
Verify compliance for commercial and open‑source software through OCIO governance processes.
Support incident reporting and coordination with the SOC.
Determine system categorization and control selection under the Risk Management Framework.
Coordinate with stakeholders on ECCP controls and expansion of standard control providers.
Manage IPAs and PIAs.
Review security reports and participate in briefings with system owners and leadership.
Monitor overall security posture and prepare updated Security Posture Reports.
QUALIFICATIONS: Required Certifications:
CISSP or Security +
Education, Background, and Years of Experience:
Bachelor of Science Degree
3 -5 years of experience as an ISSO/ISSM
ADDITIONAL SKILLS & QUALIFICATIONS: Required Skills:
3 - 5 years ISSO/ISSM support including
Maintain the security posture of assigned information systems and ensure compliance with federal security requirements (e.g., NIST, FISMA).
Support system authorization and accreditation activities, including preparing and maintaining A&A documentation.
Monitor system security controls and ensure they are implemented, operating, and effective.
Perform continuous monitoring activities and review security logs, scans, and reports.
Identify, track, and remediate vulnerabilities in coordination with engineering teams.
Conduct periodic security assessments and risk analysis.
Prepare and maintain system security plans, contingency plans, incident response plans, and related artifacts.
Ensure proper configuration management practices are followed for all system changes.
Support security incident response activities, including documenting and escalating events.
Work closely with system owners, developers, and administrators to ensure security is integrated throughout the system lifecycle.
Communicate security risks and recommendations to stakeholders and leadership.
Ensure users maintain proper security awareness and follow established policies and procedures.
Participate in audits and reviews, providing evidence, documentation, and responses as needed.
Track and report on Plan of Action & Milestones (POA&Ms).
Ensure compliance with policies related to access control, patch management, and security operations.
WORKING CONDITIONS: Environmental Conditions:
Hybrid position in Washington, D.C.
3 days onsite, 2 remote days
- Happy - Be Infectious. Happiness multiplies and creates a positive and connected environment where motivation and satisfaction have an outsized effect on everything we do.
- Helpful - Be Supportive. Being helpful is the foundation of teamwork, resulting in a supportive atmosphere where collaboration flourishes, and collective success is celebrated.
- Honest - Be Trustworthy. Honesty serves as our compass, ensuring transparent communication and ethical conduct, essential to who we are and the complex domains we support.
- Humble - Be Grounded. Success is not achieved alone, humility ensures a culture of mutual respect, encouraging open communication, and a willingness to learn from one another and take on any task.
- Hungry - Be Eager. Our hunger for excellence drives an insatiable appetite for innovation and continuous improvement, propelling us forward in the face of new and unprecedented challenges.
- Hustle - Be Driven. Hustle is reflected in our relentless work ethic, where we are each committed to going above and beyond to advance the mission and achieve success.
Details
- Department
- Cybersecurity
- Work Type
- hybrid
- Locations
- Washington, DC, US
- Posted
- March 31, 2026
- Source
- lever