Information System Security Officer (ISSO)
Quick Summary
Support RMF activities for the AWS IL5 environment throughout system development, IATT, ATO, and continuous monitoring, including security assessments, audit readiness,
Everforth ECS is seeking an experienced Information System Security Officer (ISSO) to work in a hybrid capacity at our Fairfax, VA office.
The ISSO will support the development, authorization, and ongoing cybersecurity compliance of Jupiter, a newly established DISA IL5 AWS environment supporting CUI. The environment will house multiple U.S. Coalition Mission Partner Environments (MPE).
This position is a demanding, high energy role that requires strong cybersecurity judgement, attention to detail, and the ability to help build an RMF authorization package from the ground up across multiple enclaves in a dynamic AWS DoW environment. The ISSO will work closely with the ISSM, cloud and systems engineers, and government cybersecurity team to prepare the environment for an Interim Authorization to Test (IATT) and ultimately an Authorization to Operate (ATO).
The ideal candidate has hands-on ISSO experience supporting DoW programs, a strong working knowledge of RMF and NIST 800-53 controls, DISA STIGs, eMASS, ACAS/Nessus, POA&M management, and security authorization documentation. The candidate should be technically capable of independently investigating DTO’s, control artifacts, reviewing system configurations and scan results, and working directly with engineers to validate and remediate cybersecurity findings. Experience supporting AWS DoW environments strongly preferred. The ISSO reports to the Senior Information System Security Manager.
Job Responsibilities:
- Support RMF activities for the AWS IL5 environment throughout system development, IATT, ATO, and continuous monitoring, including security assessments, audit readiness, and authorization package updates.
- Develop and maintain authorization artifacts, including security plans, control implementation evidence, vulnerability documentation, diagrams, inventories, risk documentation, policies, procedures, and SOPs.
- Maintain eMASS records, including control implementation details, artifacts, assessment results, POA&Ms, risk documentation, and continuous monitoring evidence.
- Develop, maintain, and track POA&Ms for vulnerabilities, STIG findings, control deficiencies, assessment findings, and other identified cybersecurity risks.
- Review and validate DISA STIG artifacts and supporting evidence, including checklists, scan results, remediation evidence, mitigations, and closure documentation.
- Perform hands-on vulnerability analysis using ACAS/Nessus, including reviewing scan results, affected assets, credentialed scan status, plugin output, remediation guidance, and scan coverage.
- Evaluate DTOs, CVEs, cybersecurity directives, and vulnerability notifications to determine potential impact to Jupiter; configure, modify, or troubleshoot ACAS scans as necessary to validate system exposure.
- Work with engineering teams to validate vulnerabilities and security findings, track remediation, conduct rescans and maintain supporting vulnerability and closure documentation.
- Review the cybersecurity impact of new AWS services, applications, Kubernetes workloads, software packages, architecture changes, and system changes and ensure associated authorization documentation remains current.
- Support and validate endpoint security, logging, monitoring, identity and access management, configuration management, and other technical security controls implemented within the environment.
- Coordinate cybersecurity and authorization activities with engineering, program leadership, and government stakeholders.
- Other duties, as assigned.
Salary Range: $140,000-160,000
- U.S. Citizen.
- Ability to obtain Secret clearance (active preferred)
- Active DoD 8140 IAT Level II Security+ (or higher).
- Ability to work up to 3 days a week in a hybrid capacity out of Fairfax, VA. Additional onsite support may be required based on operational or mission needs.
- Minimum 5 years of relevant cybersecurity experience, including experience supporting DoW information systems, RMF, security authorization, or continuous monitoring activities.
- Hands-on experience with DoD RMF, NIST SP 800-53, eMASS, authorization packages, control implementation documentation, POA&Ms, and continuous monitoring activities.
- Working knowledge of AWS security and compliance concepts, including cloud shared responsibility, inherited controls, identity and access management, logging, network security, and security control implementation within cloud environments.
- Practical understanding of secured IT infrastructure, including AWS, Kubernetes, Linux, Windows, Entra ID/Active Directory, networking, authentication, endpoint security, logging, and monitoring, with the ability to evaluate how these technologies affect the system's security and authorization posture.
- Ability to develop and maintain cybersecurity documentation including System Security Plans, control implementation statements, POA&Ms, risk documentation, policies, procedures, SOPs, and continuous monitoring artifacts.
- Hands-on experience with ACAS/Nessus, including credentialed scanning, vulnerability analysis, scan configuration, troubleshooting scan coverage or authentication issues, and targeted vulnerability assessments.
- Ability to analyze DTOs, CVEs, cybersecurity directives, and vulnerability notifications and independently determine potential system exposure using ACAS/Nessus and other available technical information.
- Experience reviewing and validating DISA STIGs, security configuration evidence, remediation documentation, mitigations, and vulnerability closure evidence.
- Ability to work directly with cloud, system, network, and application engineers to validate technical security controls, investigate findings, determine remediation approaches, and collect sufficient evidence to support RMF requirements.
- Ability to translate technical vulnerabilities and control deficiencies into clear mission and cybersecurity risk statements for ISSMs, system owners, government stakeholders, and Authorizing Officials.
- Strong analytical, problem solving, technical writing, and verbal communication skills, with the ability to independently investigate cybersecurity issues and communicate effectively with both technical and non-technical stakeholders.
- Strong problem-solving and decision-making capabilities, with a proven ability to weigh the relative costs and benefits of potential actions and identify the most appropriate solution.
- Highly developed interpersonal and oral/written communication skills, with the ability to effectively and professionally interact with a diverse set of stakeholders (from peers to end-users to executive management).
Location & Eligibility
Listing Details
- First seen
- October 9, 2026
- Last seen
- October 9, 2026
Posting Health
- Days active
- -1
- Repost count
- 1
- Trust Level
- 51%
- Scored at
- October 9, 2026
Signal breakdown
4 other jobs at
View all →Similar Governance Risk and Compliance Manager jobs
View all →Browse Similar Jobs
Stay ahead of the market
Get the latest job openings, salary trends, and hiring insights delivered to your inbox every week.
No spam. Unsubscribe at any time.