Information Systems Security Officer (Technical ISSO / RMF Assessor)
$112,000–$179,000 year
On-siteWashington, District of Columbia, United States or Herndon, Virginia, United States
Job Summary
Develop and maintain Security Test Procedures (STPs), Security Controls Traceability Matrices (SCTMs), and implementation statements for NIST SP 800-53 controls. Interpret ACAS/Nessus scan results, perform Splunk log analysis to validate control effectiveness, and remediate STIG findings across infrastructure. Lead RMF Steps 1–6, prepare ATO documentation including SSPs, SARs, and POA&Ms, and coordinate with system owners to address security gaps and validate continuous monitoring artifacts. Ensure documentation is entered in Xacta or eMASS while communicating technical risks to government stakeholders. Support incident response activities and participate in security assessments and audits.
Required Qualifications
- Active TS clearance with SCI eligibility OR TS/SCI clearance adjudication with current polygraph OR the ability to pass a polygraph
- Bachelor's degree in a relevant technical field with 8+ years of relevant experience, or 12+ years of experience in lieu of a degree
- 8+ years of hands-on experience as an ISSO, ISSE, Assessor, Security Engineer, or closely related DoD cybersecurity role
- Demonstrated experience writing STPs, creating SCTMs, and developing implementation statements
- Hands-on experience performing STIG interpretation and remediation
- Experience reviewing and validating ACAS/Nessus vulnerability scan results
- Ability to use Splunk (or similar SIEM) to validate security controls and investigate anomalies
- Direct experience authoring ATO documentation (SSP, SAR, POA&M, etc.)
- Strong working knowledge of NIST SP 800-53, RMF, and DoD cybersecurity requirements
- Experience using Xacta or eMASS to manage RMF artifacts
- DoD 8570 IAM-II compliant certification (e.g., Security+, CISSP, CISM)
- Strong written and verbal communication skills with the ability to explain technical topics clearly
Desired Qualifications
- Experience as a Security Control Assessor (SCA) or assessor support
- Familiarity with FISMA, FISCAM, and federal audit requirements
- Experience supporting cloud environments (AWS GovCloud preferred)
- Experience with automation or scripting to support security tasks
- Strong understanding of Zero Trust principles
- Experience supporting SAP/SAR or other high-side environments
Additional Requirements
- Must possess an active TS/SCI clearance
Hiring someone like this?
Get your role in front of qualified candidates on Sorce.