Information System Security Officer (ISSO)

CACIChantilly, VA
Onsite

About The Position

The Information System Security Officer (ISSO) will be responsible for security architecture and systems engineering supporting Identity, Credential and Access Management (ICAM) projects. The ISSO will provide guidance to the team to support system accreditation (IATT and ATO). This role is a prime contractor position on MWIII Bridge, focusing on developing and supporting ICAM capabilities for the enterprise and stand-alone deployment throughout the Intelligence Community (IC). Tasks include program management, mission support, software integration, software development, system engineering, migration, testing, documentation development, network and system monitoring, configuration control, and release management.

Requirements

  • TS/SCI clearance with polygraph
  • IAM Level 1 CWIP certification
  • One of the following baseline certifications: CAP, CND, Cloud+, GSLC, Security+CE, HCISPP, CASP+CE, CISM, CISSP (or Associate), CCISO
  • Bachelor's degree in a technical discipline from an accredited college or university
  • Ten (10) years relevant work experience.
  • Four (4) years of additional experience may be substituted for a bachelor's degree.
  • At least four (4) years of this experience must be as an ISSO on programs and contracts of similar scope, type, and complexity.

Nice To Haves

  • Experience with the ICD 503/NIST 800-53 certification and accreditation process
  • Experience with the Risk Management Framework
  • Experience developing and maintaining SSPs
  • Experience with IAVA review and handling
  • Experience interpreting Security Scan results
  • Experience interfacing with System Administrators and Software Engineers
  • Experience with task tracking systems (e.g. Jira, Redmine, ServiceNow)
  • Understands Public Key Infrastructure-based authentication
  • Understands a variety of security policies, especially within the IC
  • Understands fundamentals of technical security risk assessment
  • Understands how to perform analysis of alternatives
  • Able to clearly communicate ideas and status updates to management and other stakeholders

Responsibilities

  • Prepare system security plan (SSP) and provide recommendations to assist in obtaining ATOs.
  • Identify, develop, review and incorporate common artifacts found in an RMF accreditation package such as: system architecture and boundaries, hardware and software lists, risk assessment reports, POA&Ms, data flows, and other necessary system, network, and application documentation.
  • Work with ISSM and DAOs to ensure systems obtain and maintain accreditation.
  • Verify package submissions have met the threshold for approval such as: C&A Package for System Reauthorization, SAR Findings, CTO’s, POA&Ms, and System Security Plans (SSPs).
  • Apply continuous monitoring techniques to evaluate the systems security posture.
  • Create tasking for developers and system administrators as changes and patching are required.
  • Oversee the implementation of software patches to maintain the security posture of the organization.
  • Implement and enforce information systems security policies, standards, and methodologies.
  • Identify and document compliance using vulnerability scanning and assessment tools (e.g., ACAS/Nessus).
  • Review Audit Logs on a weekly basis.
  • Perform Data transfers on a weekly basis driving from CACI Hanover Office to Ft. Meade.
  • Maintain and report assessment and authorization statuses and issues in accordance with organizational guidance.
  • Support personnel with new PRIVAC requests and extensions.

Benefits

  • Flexible time off
  • Robust learning resources
  • Competitive compensation
  • Comprehensive benefits
  • Healthcare
  • Wellness
  • Financial
  • Retirement
  • Family support
  • Continuing education
  • Time off benefits
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service