Information System Security Officer (ISSO)

ASEC•Lexington Park, MD
•$125,000 - $140,000•Onsite

About The Position

As the Information Systems Security Officer (ISSO), you will support cybersecurity compliance, assessment and authorization, and continuous monitoring of information systems. The ISSO will coordinate with Government cybersecurity personnel, Information System Security Managers (ISSMs), system administrators, network administrators, and engineering teams to implement security requirements, maintain authorization documentation, and address vulnerabilities. This position requires on-site work at ASEC’s corporate office in Lexington Park, MD. Some travel to supported locations may be required.

Requirements

  • Bachelor’s degree in Cybersecurity, Information Technology, Computer Science, Information Systems, or a related technical field.
  • At least 5 years of related IA/Cybersecurity experience is preferred.
  • Demonstrated experience supporting cybersecurity compliance, vulnerability management, or assessment and authorization activities for DoD information systems.
  • Working knowledge of RMF, NIST SP 800-53 security controls, and DoD cybersecurity requirements.
  • Experience developing and maintaining authorization documentation, security control evidence, and POA&Ms.
  • Experience using ACAS, DISA STIGs, and SCAP tools to assess system security and support vulnerability remediation.
  • Familiarity with eMASS or comparable cybersecurity assessment and authorization repositories.
  • Working knowledge of Windows and Linux operating systems, networking fundamentals, access controls, and system hardening.
  • At a minimum, this position requires CompTIA Security+.
  • Candidates with a bachelor’s degree specifically in Cybersecurity, Data Science, Information Systems, Information Technology, or Software Engineering do not require an additional certification beyond the baseline (Security +) requirement.
  • Candidates without one of these degrees must hold one of the following additional certifications: SecurityX, GMON, CCISO, CCSP, CGRC/CAP, CISSO, Cloud+, GCSA, GSEC, SSCP. Note: your CISSP or CISM will satisfy the additional certification requirement.
  • Ability to build positive, collaborative relationships across teams and with external partners.
  • Effective communicator with strong verbal and written skills.
  • Proactive, self-directed work style with the ability to operate independently.
  • Analytical thinker with proven problem-solving capabilities.
  • Highly organized, with the ability to balance competing priorities in a fast-paced environment.
  • This position requires U.S. citizenship and an active DoD Top Secret clearance. Selected candidate will be subject to a government security investigation and must meet eligibility requirements for access to classified information.

Nice To Haves

  • At least 5 years of related IA/Cybersecurity experience is preferred.

Responsibilities

  • Support Risk Management Framework (RMF) activities throughout the system lifecycle, including security control implementation, assessment preparation, authorization, and continuous monitoring.
  • Develop, update, and maintain cybersecurity documentation, including System Security Plans (SSPs), security control implementation statements, supporting evidence, and authorization package artifacts.
  • Maintain system security records and authorization documentation in eMASS or other Government-designated repositories.
  • Coordinate with technical teams to maintain accurate hardware and software inventories, system boundary descriptions, network diagrams, and configuration baselines.
  • Perform and review vulnerability assessments using the Assured Compliance Assessment Solution (ACAS), applicable DISA Security Technical Implementation Guides (STIGs), and the Security Content Automation Protocol (SCAP) Compliance Checker.
  • Evaluate scan results and STIG findings, coordinate remediation with system and network administrators, and validate corrective actions.
  • Develop and maintain Plans of Action and Milestones (POA&Ms), track remediation progress, and prepare mitigation statements and supporting documentation for Government review.
  • Monitor compliance with applicable cybersecurity policies, approved system configurations, and authorization conditions.
  • Review proposed hardware, software, network, and system configuration changes for cybersecurity impacts and support established configuration management processes.
  • Coordinate cybersecurity requirements for system installations, upgrades, integration activities, and deployments.
  • Review security logs and monitoring information, identify potential concerns, and coordinate follow-up with appropriate technical and cybersecurity personnel.
  • Report suspected cybersecurity incidents through established channels and assist with evidence collection, documentation, and corrective actions.
  • Support inspections, security control assessments, and authorization reviews by organizing evidence, addressing findings, and tracking follow-up actions.

Benefits

  • 100% employee-owned company.
  • Comprehensive benefits package, including 11 paid holidays, medical/dental/vision coverage, HSA/FSA options, disability insurance, and more!
  • 401(k) with company match
  • Tuition assistance for undergraduate and graduate education
  • Veteran-friendly employer
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service