~1h ago
↻ Repost

Information System Security Officer (ISSO)

United StatesUnited StatesNormalmid
CybersecurityGovernance Risk and Compliance Manager
3 views0 saves0 applied

Quick Summary

Key Responsibilities

Support RMF activities for the AWS IL5 environment throughout system development, IATT, ATO, and continuous monitoring, including security assessments, audit readiness,

Technical Tools
CybersecurityGovernance Risk and Compliance Manager

Everforth ECS is seeking an experienced Information System Security Officer (ISSO) to work in a hybrid capacity at our Fairfax, VA office.

  

The ISSO will support the development, authorization, and ongoing cybersecurity compliance of Jupiter, a newly established DISA IL5 AWS environment supporting CUI. The environment will house multiple U.S. Coalition Mission Partner Environments (MPE).

 

This position is a demanding, high energy role that requires strong cybersecurity judgement, attention to detail, and the ability to help build an RMF authorization package from the ground up across multiple enclaves in a dynamic AWS DoW environment. The ISSO will work closely with the ISSM, cloud and systems engineers, and government cybersecurity team to prepare the environment for an Interim Authorization to Test (IATT) and ultimately an Authorization to Operate (ATO).

 

The ideal candidate has hands-on ISSO experience supporting DoW programs, a strong working knowledge of RMF and NIST 800-53 controls, DISA STIGs, eMASS, ACAS/Nessus, POA&M management, and security authorization documentation. The candidate should be technically capable of independently investigating DTO’s, control artifacts, reviewing system configurations and scan results, and working directly with engineers to validate and remediate cybersecurity findings. Experience supporting AWS DoW environments strongly preferred. The ISSO reports to the Senior Information System Security Manager.

 

Job Responsibilities:

  • Support RMF activities for the AWS IL5 environment throughout system development, IATT, ATO, and continuous monitoring, including security assessments, audit readiness, and authorization package updates.
  • Develop and maintain authorization artifacts, including security plans, control implementation evidence, vulnerability documentation, diagrams, inventories, risk documentation, policies, procedures, and SOPs.
  • Maintain eMASS records, including control implementation details, artifacts, assessment results, POA&Ms, risk documentation, and continuous monitoring evidence.
  • Develop, maintain, and track POA&Ms for vulnerabilities, STIG findings, control deficiencies, assessment findings, and other identified cybersecurity risks.
  • Review and validate DISA STIG artifacts and supporting evidence, including checklists, scan results, remediation evidence, mitigations, and closure documentation.
  • Perform hands-on vulnerability analysis using ACAS/Nessus, including reviewing scan results, affected assets, credentialed scan status, plugin output, remediation guidance, and scan coverage.
  • Evaluate DTOs, CVEs, cybersecurity directives, and vulnerability notifications to determine potential impact to Jupiter; configure, modify, or troubleshoot ACAS scans as necessary to validate system exposure.
  • Work with engineering teams to validate vulnerabilities and security findings, track remediation, conduct rescans and maintain supporting vulnerability and closure documentation.
  • Review the cybersecurity impact of new AWS services, applications, Kubernetes workloads, software packages, architecture changes, and system changes and ensure associated authorization documentation remains current.
  • Support and validate endpoint security, logging, monitoring, identity and access management, configuration management, and other technical security controls implemented within the environment.
  • Coordinate cybersecurity and authorization activities with engineering, program leadership, and government stakeholders.
  • Other duties, as assigned.

Salary Range: $140,000-160,000

  • U.S. Citizen.
  • Ability to obtain Secret clearance (active preferred)
  • Active DoD 8140 IAT Level II Security+ (or higher).
  • Ability to work up to 3 days a week in a hybrid capacity out of Fairfax, VA. Additional onsite support may be required based on operational or mission needs.
  • Minimum 5 years of relevant cybersecurity experience, including experience supporting DoW information systems, RMF, security authorization, or continuous monitoring activities.
  • Hands-on experience with DoD RMF, NIST SP 800-53, eMASS, authorization packages, control implementation documentation, POA&Ms, and continuous monitoring activities.
  • Working knowledge of AWS security and compliance concepts, including cloud shared responsibility, inherited controls, identity and access management, logging, network security, and security control implementation within cloud environments.
  • Practical understanding of secured IT infrastructure, including AWS, Kubernetes, Linux, Windows, Entra ID/Active Directory, networking, authentication, endpoint security, logging, and monitoring, with the ability to evaluate how these technologies affect the system's security and authorization posture.
  • Ability to develop and maintain cybersecurity documentation including System Security Plans, control implementation statements, POA&Ms, risk documentation, policies, procedures, SOPs, and continuous monitoring artifacts.
  • Hands-on experience with ACAS/Nessus, including credentialed scanning, vulnerability analysis, scan configuration, troubleshooting scan coverage or authentication issues, and targeted vulnerability assessments.
  • Ability to analyze DTOs, CVEs, cybersecurity directives, and vulnerability notifications and independently determine potential system exposure using ACAS/Nessus and other available technical information.
  • Experience reviewing and validating DISA STIGs, security configuration evidence, remediation documentation, mitigations, and vulnerability closure evidence.
  • Ability to work directly with cloud, system, network, and application engineers to validate technical security controls, investigate findings, determine remediation approaches, and collect sufficient evidence to support RMF requirements.
  • Ability to translate technical vulnerabilities and control deficiencies into clear mission and cybersecurity risk statements for ISSMs, system owners, government stakeholders, and Authorizing Officials.
  • Strong analytical, problem solving, technical writing, and verbal communication skills, with the ability to independently investigate cybersecurity issues and communicate effectively with both technical and non-technical stakeholders.
  • Strong problem-solving and decision-making capabilities, with a proven ability to weigh the relative costs and benefits of potential actions and identify the most appropriate solution.
  • Highly developed interpersonal and oral/written communication skills, with the ability to effectively and professionally interact with a diverse set of stakeholders (from peers to end-users to executive management).

Location & Eligibility

Where is the job
United States
On-site within the country
Who can apply
US

Listing Details

First seen
October 9, 2026
Last seen
October 9, 2026

Posting Health

Days active
-1
Repost count
1
Trust Level
51%
Scored at
October 9, 2026

Signal breakdown

freshnesssource trustcontent trustemployer trust
Newsletter

Stay ahead of the market

Get the latest job openings, salary trends, and hiring insights delivered to your inbox every week.

A
B
C
D
Join 12,000+ marketers

No spam. Unsubscribe at any time.

Information System Security Officer (ISSO)