Jobs · Information Technology · Maryland

Information Systems Security Officer (ISSO) (GC-2)

Legato, LLC · Annapolis Junction, MD · 1 mo ago
On-siteInformation Technology$160k–$180k/yrFull-time

Information Systems Security Officer (ISSO) position in Hanover, MD. Active TS/SCI with Polygraph clearance required.

About the role

The Information Systems Security Officer (ISSO) will support the security posture of mission-critical information systems by implementing, maintaining, and enforcing information assurance policies, standards, and procedures throughout the system lifecycle. This role ensures systems remain compliant with security requirements while supporting the Risk Management Framework (RMF) authorization process for classified environments.

The ISSO will maintain the day-to-day operational security of assigned information systems, supporting approximately 10–15 System Security Plans (SSPs). They will work closely with system owners, engineers, ISSMs, and cybersecurity teams to ensure security controls are implemented, documented, and maintained in accordance with customer and regulatory requirements.

Responsibilities

  • Prepare, review, and maintain RMF documentation, including System Security Plans (SSPs), Risk Assessment Reports (RARs), Security Assessment and Authorization (A&A) packages, and System Requirements Traceability Matrices (SRTMs).
  • Support security authorization activities in accordance with the National Institute of Standards and Technology (NIST) Risk Management Framework (RMF).
  • Assist with vulnerability assessments, risk analysis, and continuous monitoring activities.
  • Evaluate security solutions to ensure they meet security requirements for processing classified information.
  • Support configuration management activities for security-related hardware, software, and firmware.
  • Assess the security impact of system changes.
  • Coordinate with stakeholders to implement information system security policies and maintain compliance.
  • Support ongoing cybersecurity operations.

Requirements

  • Ten (10) years of experience as an Information Systems Security Officer (ISSO) supporting programs or contracts of similar scope, type, and complexity.
  • Experience supporting the National Institute of Standards and Technology (NIST) Risk Management Framework (RMF) and security authorization processes.
  • Experience preparing and maintaining System Security Plans (SSPs), Risk Assessment Reports (RARs), Assessment and Authorization (A&A) packages, and System Requirements Traceability Matrices (SRTMs).
  • Experience performing vulnerability assessments, risk analysis, continuous monitoring activities, and configuration management of security-related hardware, software, and firmware.
  • Experience evaluating the security impact of system changes and maintaining compliance with information assurance policies, standards, and procedures.
  • Experience supporting the day-to-day security operations of multiple information systems, typically managing a portfolio of approximately 10–15 System Security Plans (SSPs).
  • Strong written and verbal communication skills with the ability to collaborate effectively with system owners, engineers, cybersecurity professionals, and government stakeholders.
  • Bachelor's degree in Computer Science or a related technical discipline from an accredited college or university. Four (4) additional years of ISSO experience may be substituted for a bachelor's degree.
  • Current IAT Level II certification or higher.

Skills

  • Experience with eMASS, Xacta, or similar RMF management tools (desired).
  • Experience supporting classified systems (desired).
  • Knowledge of Security Technical Implementation Guides (STIGs), Security Content Automation Protocol (SCAP), and vulnerability scanning tools such as ACAS, Nessus, or Tenable Security Center (desired).
  • Knowledge of current security tools, hardware and software security implementation, communication protocols, and encryption technologies (desired).
  • Experience supporting security control assessments, audits, and continuous monitoring activities (desired).

About the company

Legato, LLC is a dynamic small business headquartered in Columbia, near Ft. Meade, MD. Our positions include Cyber, Software, Systems, Networking, Data Science, and other complex engineering capabilities. We set ourselves apart by employing individuals at the top of their field who enjoy working at Legato due to its attention to employees, aggressive compensation, and upward mobility possibilities.

Benefits

  • Individual and family health, vision, and dental benefits.
  • A minimum of four (4) weeks of paid time off, including a week of sick leave.
  • 11 federal holidays off.
  • 401(k) employer match with no vesting schedule.
  • Opportunity to earn referral benefits or bank hours if the contract allows.

Pay

Salary range: $160,000–$180,000, depending on experience.

Similar jobs

Security Officer

Guardian Security Services, Inc.Downers Grove, IL· 1 mo ago
Information Technologyapply on de.jobsyn.org

Security Officer

Per Mar Security ServicesMinneapolis, MN· 1 mo ago
Information Technologyapply on joblinkapply.com

Security Officer

Signet JewelersNew York, NY· 1 mo ago
Information Technology$28–$35/hrapply on signetjewelers.wd1.myworkdayjobs.com

Security Officer

Securitas Security Services USA, Inc.Grand Rapids, MN· 1 mo ago
Information Technology$18.35/hrapply on ekaw.fa.us2.oraclecloud.com

Security Officer

SedgebrookLincolnshire, IL· 2 mo ago
Information Technology$18/hrapply on eexs.fa.us2.oraclecloud.com

Security Officer

CARTILittle Rock, AR· 2 mo ago
Information Technologyapply on secure4.saashr.com