Information Systems Security Officer
Actalent
Information Systems Security Officer
The Information Systems Security Officer will lead cybersecurity efforts for complex software projects within a United States Department of Defense (DoD) environment, with a strong focus on Risk Management Framework (RMF) compliance and secure cloud-based workloads. This role drives the creation, submission, and maintenance of security packages and authorizations, including obtaining and sustaining Authorization to Operate (ATO) for Amazon Web Services (AWS) container-based solutions. The position requires deep expertise in DoD cybersecurity processes, tools, and standards, as well as strong communication and collaboration skills across engineering, cybersecurity, business, and customer stakeholders.
Responsibilities:
- Serve as an Information Systems Security Engineer (ISSE) for DoD software projects, providing cybersecurity leadership and guidance across the full system lifecycle.
- Generate and submit complete System Security Packages (SSPs), Plans of Action and Milestones (POA&Ms), and other required artifacts to support DoD Risk Management Framework (RMF) and Security Technical Implementation Guide (STIG) processes.
- Apply DoD cybersecurity tools, including eMASS and STIG Viewer, to build, manage, and validate security packages and supporting documentation.
- Obtain and maintain at least one DoD Authorization to Operate (ATO) for AWS-deployed container-based workloads, ensuring ongoing compliance with DoD security requirements.
- Inform and define software mitigation requirements based on results from static application security testing (SAST) tools such as SonarQube and container scanning tools such as Trivy.
- Recommend and validate data protection mechanisms, including encryption and access control strategies, to safeguard sensitive information in deployed workloads.
- Test and verify security controls to ensure they function as designed and effectively reduce risk across applications and infrastructure.
- Conduct threat modeling activities to identify potential attack vectors and prioritize security mitigations for software systems and cloud workloads.
- Lead vulnerability management activities, including identifying, tracking, and coordinating remediation of security findings across development and operations teams.
- Monitor the security posture of deployed workloads, leveraging appropriate tools and processes to detect and respond to anomalous or malicious activity.
- Collaborate effectively with engineering, cybersecurity, business, and customer stakeholders throughout the RMF cybersecurity lifecycle, ensuring clear communication of risks, requirements, and progress.
- Provide security guidance and input to DevSecOps teams across multiple software releases, helping integrate security best practices into continuous integration and deployment processes.
- Use system security tools such as Wiz or eMASSter to support security posture assessment, reporting, and ongoing compliance activities.
- Contribute to the design and operation of Security Operations Center (SOC) functions, using tools such as Splunk or CloudWatch to support monitoring and incident response.
- Leverage AWS security services, including Security Hub and GuardDuty, to strengthen detection, response, and compliance capabilities in cloud environments.
- Apply knowledge of CIS benchmarks and other industry security standards to align system configurations and controls with recognized best practices.
- Support or coordinate activities related to penetration testing, fuzz testing, and dynamic application security testing (DAST), and use results to drive remediation and improvement.
- Document security requirements, decisions, and outcomes clearly and comprehensively to support audits, assessments, and continuous improvement.
Essential Skills:
- At least 5 years of experience serving as an Information Systems Security Engineer (ISSE) for United States Department of Defense (DoD) software projects.
- Proven experience generating and submitting System Security Packages (SSPs), Plans of Action and Milestones (POA&Ms), and other artifacts required for DoD Risk Management Framework (RMF) and Security Technical Implementation Guide (STIG) processes.
- Hands-on experience applying DoD cybersecurity tools such as eMASS and STIG Viewer to develop and manage security packages.
- Demonstrated success obtaining and maintaining at least one DoD Authorization to Operate (ATO) for an AWS-deployed container-based workload.
- Strong background in cyber security, including threat modeling, vulnerability management, security monitoring, and data protection for deployed workloads.
- Experience informing software mitigation requirements based on output from static application security testing (SAST) tools such as SonarQube.
- Experience using container scanning tools such as Trivy to identify and remediate vulnerabilities in containerized workloads.
- Demonstrated expertise in recommending and validating data protections and testing security controls for complex systems.
- Track record of effective communication and collaboration throughout the RMF cybersecurity lifecycle with engineering, cybersecurity, business, and customer stakeholders.
- Possession of one or more relevant cybersecurity certifications, such as CISSP, CASP, or Security+.
Additional Skills & Qualifications:
- Experience with United States Intelligence Community (IC) system cybersecurity processes and tools.
- Background in establishing or operating Security Operations Center (SOC) functions, including use of tools such as Splunk or CloudWatch.
- Hands-on experience with AWS security services, such as Security Hub and GuardDuty, to enhance cloud security monitoring and compliance.
- Experience serving as an ISSE on a DevSecOps team through multiple software releases, integrating security into continuous delivery pipelines.
- Familiarity with system security tools such as Wiz or eMASSter for posture assessment and compliance tracking.
- Knowledge of CIS benchmarks and other industry security standards, and the ability to apply them to system hardening and configuration.
- Exposure to penetration testing, fuzz testing, and dynamic application security testing (DAST) tools and techniques, with the ability to interpret results and support remediation.
Work Environment:
The role focuses on securing DoD and cloud-based software workloads, particularly AWS-deployed container environments, using a range of cybersecurity tools, frameworks, and industry standards. You will work closely with engineering, cybersecurity, business, and customer stakeholders in a collaborative setting that values clear communication and thorough documentation. The environment emphasizes adherence to DoD RMF, STIG requirements, and ATO processes, and makes extensive use of tools such as eMASS, STIG Viewer, SonarQube, Trivy, Wiz, eMASSter, Splunk, CloudWatch, and AWS security services like Security Hub and GuardDuty. The position supports a culture of continuous improvement in security posture, integration with DevSecOps practices, and proactive monitoring and vulnerability management across deployed workloads. Dress code and specific onsite or remote arrangements are determined by organizational policies and project needs.
Job Type & Location:
This is a Contract position based out of Annapolis, MD.
Pay and Benefits:
The pay range for this position is $120000.00 - $153920.00/hr. Individual compensation offered for this position within this range will depend on many factors, including qualifications, skills, relevant experience, job knowledge, geographic location, internal equity, and other pertinent job-related factors. Eligibility requirements apply to some benefits and may depend on your job classification and length of employment. Benefits are subject to change and may be subject to specific elections, plan, or program terms. If eligible, the benefits available for this temporary role may include the following: • Medical, dental & vision • Critical Illness, Accident, and Hospital • 401(k) Retirement Plan – Pre-tax and Roth post-tax contributions available • Life Insurance (Voluntary Life & AD&D for the employee and dependents) • Short and long-term disability • Health Spending Account (HSA) • Transportation benefits • Employee Assistance Program • Time Off/Leave (PTO, Vacation or Sick Leave)
Workplace Type:
This is a hybrid position in Annapolis, MD.
Application Deadline:
This position is anticipated to close on Oct 2, 2026.
$120k - $130k
...Job Description We are seeking a Information System Security Officer (ISSO) to support the security and compliance posture of our systems. The ideal candidate has deep experience with the Risk Management Framework (RMF), security controls implementation, continuous...Suggested$50k - $120k
(Hiring) Information System Security Officer $50,000-$120,000 + Benefits We are seeking an Information System Security Officer to join our team! You will implement security measures for the protection of computer networks and information. Responsibilities:...Suggested- ...About the role Seeking a Senior Information System Security Officer (ISSO) to support a critical government contracting program in Annapolis Junction, MD. The ideal candidate will have extensive experience in information systems security, particularly in large software...Suggested
- ...Information System Security Officer (ISSO) Location: Maryland Clearance Required: Active TS/SCI with Polygraph Citizenship: U.S. Citizenship Required Position Overview Open Systems Technologies Corporation (OST) is seeking Information System Security...SuggestedTemporary work
- ...What You Will Do: At Independent Software, as a Senior Information Systems Security Officer, you will provide senior-level cybersecurity and information assurance support for classified systems supporting IC and DoD missions. You will maintain and strengthen system...Suggested
- ...Job Description: We currently seeking a Cybersecurity Information System Security Officer (ISSO) to support Department of Defense (DoD) and Special Access Program (SAP) activities in Annapolis Junction, MD. The selected candidate will rely on Cybersecurity...Work experience placement
- ...What you will be doing! As an Information System Security Officer, you will support a program, organization, system, or enclave's information assurance program. You will support proposing, coordinating, implementing, and enforcing information systems security policies...
- ...Full-time Description **A SECURITY CLEARANCE AND POLYGRAPH ARE REQUIRED... ...One (1) year experience in Enterprise IT systems and projects. Managing and performing integration... ...concurrently. DoD 8570 compliance with Information Assurance Management (IAM) Level 1 or higher...Full timeContract work
- ...Cybersecurity Engineer serves as a subject matter expert in ensuring system security compliance and risk management throughout the program life... ...to work full-time onsite in a Sensitive Compartmented Information Facility (SCIF) with flexible hours. Desired Attributes...Full timeInterim roleFlexible hours
- ...What You Will Do: At Independent Software, as a Senior Information System Security Officer (ISSO), you will support the security posture of mission-critical systems, programs, and enclaves. In this role, you will implement, maintain, and enforce information assurance...
$130k - $270k
...support of the mission to protect our country. Description Captivation Software is looking for a senior level Information Systems Security Officer to assist with daily responsibilities to support the program. Responsibilities Provides aid to the...Hourly payTemporary work- ...What You Will Do: As an Information Systems Security Officer at Independent Software, you will play a critical role in strengthening and defending the security posture of mission-critical systems supporting the Department of Defense and Intelligence Community. You...
$107.9k - $195.05k
...Leidos has a new and exciting opportunity for an Information Systems Security Officer (ISSO) in our Intelligence Sector, Cyber & Analytics Business Area (CABA) . Our talented team is at the forefront in Security Engineering, Computer Network Operations (CNO), Mission...Contract workImmediate startRelocation packageFlexible hours- ...Overview Position Title: Information System Security Officer Location: Annapolis Junction, MD Reports To: Technical Task Lead Job Type: Full-time Clearance Requirement: TS/SCI with polygraph, U.S. citizen Summary: Leave things better than you...Full timeContract workWork at officeLocal areaImmediate start
$131.3k - $237.35k
...Leidos has a new and exciting opportunity for a Senior Information System Security Officer in our National Security Sector's (NSS) Cyber & Analytics Business Area (CABA) . Our talented team is at the forefront in Security Engineering, Computer Network Operations (CNO...Immediate startFlexible hours- ...Que Technology Group, Inc. , is seeking an experienced Senior Information Systems Security Officer (ISSO) to support intelligence operations within an exciting organization. Job responsibilities include, but are not limited to: Enhancing security posture...Temporary workImmediate start
$141.5k - $236k
...at the forefront of national security, providing advanced solutions... ...focusedInformationSystem Security Officer (ISSO) to join our team... ...cybersecurity documentation, assess system vulnerabilities, and support... ...be able to exchange accurate information in these situations...Hourly payContract workTemporary workWork experience placementWork at officeLocal areaRemote work$111.16k - $150.39k
...None Experience: 8 + years of related experience US Citizenship Required: Yes Job Description: INFORMATION SYSTEMS SECURITY OFFICER YOUR IMPACT Own your opportunity to support national defense. Your work will help keep critical operations...Temporary workImmediate startRemote workWorldwideFlexible hours$10k
...rare within our industry. Please see information below Due to federal contract requirements... ...Citizenship and position appropriate security clearance is required. (e.g. Active TS/... ...). Capabilities Enhancing the system security posture by supporting the program...Hourly payFull timeContract workTemporary workWork experience placementSummer workImmediate start$200k
...Title: Information Systems Security Officer (ISSO) Location: Annapolis Junction, MD Type: Direct Hire Compensation: $200,000/year (salary) Schedule: 40 hours/week Clearance Required: Active TS/SCI with FSP Role Overview...Local area- ...Job Description Job Description ASSYST's Information Assurance and Cybersecurity Practice is seeking an experienced Information Systems Security Officer (ISSO) to support a Federal customer. ASSYST delivers comprehensive cybersecurity solutions to Federal, State,...Local areaFlexible hours
- ...NV5 Geospatial is seeking an experienced RMF Specialist to oversee RMF implementation for Air Force information systems and ensure DoD compliance. You will identify vulnerabilities, assess controls, and drive risk mitigation across complex DoD environments. The role requires...
$50k - $290k
...operational networks in Annapolis Junction, MD. Candidates must evaluate vulnerabilities, recommend countermeasures, and support security solutions. A Bachelor’s degree with relevant experience is required, with higher education preferred for advanced levels. The role...- ...mitigation of threats. Perform manual assessment of systems, services, and software; specializing in security issues beyond those identified by static analysis... ..., national origin, age, marital status, genetic information, mental or physical disability (and medical condition...Full timeTemporary workApprenticeshipLocal area
$120k - $160k
...and optimization of intrusion detection systems for both host and networkIntegrate and manage... ...in support of findings and providing security recommendations in order to secure... ...the last 5 years)Required Certification:Information Assurance Technical (IAT) Level IIIDesired...For contractors- Cymertek Corporation is seeking a proactive Threat Analyst to identify, analyze, and mitigate potential threats. The role involves monitoring risks, assessing vulnerabilities, and delivering actionable intelligence to support decision-making and safeguard assets. You will...
- .... Government missions via multiple Air to Global Information Grid (GIG) Gateways (A2G2's) supported by a Systems Integration Lab (SIL). This is a full-time position... ...Integration Laboratory (SIL), and the Government Security Operations Center (GSOC). Identify, diagnose,...Full timeContract work
$130k - $170k
...agencies with technology and systems engineered to connect, protect... ...and event execution Inform the development and implementation... ...intent and brief to general officer level. Experience with organizing... ...DESIRED. Special Requirements/Security Clearance Please note that...Full timeContract workTemporary workWork experience placementWorldwide$169.5k
...operating model, decisioning systems, and technology products that... ...CONDITIONS Position Type ~ Office-Basedor RemotePosition... ...employees may have access to covered information, cardholder data, or other... ...as well as all data security guidelines established within...For contractorsWork at officeLocal area$93.9k
...federal government and Maryland. # Must possess current CPR certification and be registered with CRISP (Chesapeake Regional Information System for Our Patients). # Shall provide documentation of current professional malpractice insurance with a minimum of $1 million...For contractorsWork at office
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Information Systems Security Officer. Be the first to apply!
- information security officer Annapolis, MD
- ciso Annapolis, MD
- chief information security officer ciso Annapolis, MD
- business information security officer Annapolis, MD
- information systems security officer Annapolis, MD
- chief information security officer Annapolis, MD
- information system intern Annapolis, MD
- information security Annapolis, MD
- sr information security engineer Annapolis, MD
- data center security officer Annapolis, MD

