Information Systems Security Officer (ISSO) (GC-2)

LegatoAnnapolis Junction, MD
Onsite

About The Position

The Information Systems Security Officer (ISSO) will support the security posture of mission-critical information systems by implementing, maintaining, and enforcing information assurance policies, standards, and procedures throughout the system lifecycle. This role is responsible for ensuring systems remain compliant with security requirements while supporting the Risk Management Framework (RMF) authorization process for classified environments. The ISSO will maintain the day-to-day operational security of assigned information systems, supporting approximately 10–15 System Security Plans (SSPs). They will work closely with system owners, engineers, ISSMs, and cybersecurity teams to ensure security controls are implemented, documented, and maintained in accordance with customer and regulatory requirements. The successful candidate will prepare, review, and maintain RMF documentation, including System Security Plans (SSPs), Risk Assessment Reports (RARs), Security Assessment and Authorization (A&A) packages, and System Requirements Traceability Matrices (SRTMs). They will support security authorization activities in accordance with the National Institute of Standards and Technology (NIST) Risk Management Framework (RMF) and assist with vulnerability assessments, risk analysis, and continuous monitoring activities. The ISSO will evaluate security solutions to ensure they meet security requirements for processing classified information, support configuration management activities for security-related hardware, software, and firmware, and assess the security impact of system changes. They will also coordinate with stakeholders to implement information system security policies, maintain compliance, and support ongoing cybersecurity operations.

Requirements

  • Ten (10) years of experience as an Information Systems Security Officer (ISSO) supporting programs or contracts of similar scope, type, and complexity.
  • Experience supporting the National Institute of Standards and Technology (NIST) Risk Management Framework (RMF) and security authorization processes.
  • Experience preparing and maintaining System Security Plans (SSPs), Risk Assessment Reports (RARs), Assessment and Authorization (A&A) packages, and System Requirements Traceability Matrices (SRTMs).
  • Experience performing vulnerability assessments, risk analysis, continuous monitoring activities, and configuration management of security-related hardware, software, and firmware.
  • Experience evaluating the security impact of system changes and maintaining compliance with information assurance policies, standards, and procedures.
  • Experience supporting the day-to-day security operations of multiple information systems, typically managing a portfolio of approximately 10–15 System Security Plans (SSPs).
  • Strong written and verbal communication skills with the ability to collaborate effectively with system owners, engineers, cybersecurity professionals, and government stakeholders.
  • Bachelor's degree in Computer Science or a related technical discipline from an accredited college or university. Four (4) additional years of ISSO experience may be substituted for a bachelor's degree.
  • Current IAT Level II certification or higher.
  • Security Clearance Required: TS/SCI w/ Polygraph

Nice To Haves

  • Experience with eMASS, Xacta, or similar RMF management tools.
  • Experience supporting classified systems.
  • Knowledge of Security Technical Implementation Guides (STIGs), Security Content Automation Protocol (SCAP), and vulnerability scanning tools such as ACAS, Nessus, or Tenable Security Center.
  • Knowledge of current security tools, hardware and software security implementation, communication protocols, and encryption technologies.
  • Experience supporting security control assessments, audits, and continuous monitoring activities.

Responsibilities

  • Implement, maintain, and enforce information assurance policies, standards, and procedures.
  • Ensure systems remain compliant with security requirements.
  • Support the Risk Management Framework (RMF) authorization process for classified environments.
  • Maintain the day-to-day operational security of assigned information systems.
  • Support approximately 10–15 System Security Plans (SSPs).
  • Work closely with system owners, engineers, ISSMs, and cybersecurity teams to ensure security controls are implemented, documented, and maintained.
  • Prepare, review, and maintain RMF documentation, including System Security Plans (SSPs), Risk Assessment Reports (RARs), Security Assessment and Authorization (A&A) packages, and System Requirements Traceability Matrices (SRTMs).
  • Support security authorization activities in accordance with the National Institute of Standards and Technology (NIST) Risk Management Framework (RMF).
  • Assist with vulnerability assessments, risk analysis, and continuous monitoring activities.
  • Evaluate security solutions to ensure they meet security requirements for processing classified information.
  • Support configuration management activities for security-related hardware, software, and firmware.
  • Assess the security impact of system changes.
  • Coordinate with stakeholders to implement information system security policies.
  • Maintain compliance with information assurance policies, standards, and procedures.
  • Support ongoing cybersecurity operations.

Benefits

  • Individual and family health, vision and dental benefits
  • A minimum of four (4) weeks of paid time off including a week of sick leave
  • 11 federal holidays off
  • 401(k) employer match with no vesting schedule
  • Opportunity to earn referral benefits
  • Opportunity to bank hours if the contract allows
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service