Information System Security Officer (ISSO)

ECS

Fort Meade (MD)

On-site

USD 150,000 - 170,000

Full time

2 days ago
Be an early applicant
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Job summary

Everforth ECS is seeking an Information System Security Officer (ISSO) to work onsite at Fort Meade, MD, supporting IL-5 and IL-6 programs in an operational DoW environment. The role requires strong cybersecurity judgment, RMF familiarity, and hands-on experience with ACAS, Nessus, Trellix, and eMASS.

The ISSO will lead RMF activities, maintain ATO artifacts, coordinate with stakeholders, and ensure continuous monitoring across multiple enclaves in Azure DoW.

Qualifications

  • Must be a U.S. citizen
  • Active Secret clearance required
  • DoD 8140 IAT Level II Security+ (or higher) required
  • Ability to work onsite five days a week at Fort Meade, MD
  • Experience supporting RMF, ATO maintenance, continuous monitoring, and security documentation
  • Hands-on experience with eMASS or similar RMF/GRC software
  • Knowledge of cloud security with Azure/AWS responsibilities
  • Familiarity with ACAS/Nessus and Trellix endpoint security tools
  • Ability to translate vulnerabilities into actionable risk statements

Responsibilities

  • Support ISSO activities for a DoD Azure environment, including RMF, ATO maintenance, continuous monitoring, and compliance documentation.
  • Develop and maintain ATO artifacts, control evidence, vulnerability reports, diagrams, inventories, and risk documentation.
  • Perform security control assessments, audit readiness, continuous monitoring reviews, and authorization package updates for classified systems.
  • Manage POA&Ms for vulnerabilities, STIG findings, and other security risks; track remediation.
  • Maintain eMASS records, artifacts, POA&Ms, assessment results, and continuous monitoring evidence.
  • Review and validate STIG artifacts and remediation documentation.
  • Collaborate with engineers, cloud teams, and government stakeholders to validate findings and keep documentation current.
  • Administer ACAS/Nessus scanning, scheduling, and vulnerability reporting; troubleshoot credentialed scans.
  • Administer Trellix/ESS including ePO policies and endpoint protection settings.
  • Monitor alerts in Microsoft Sentinel; participate in cybersecurity status meetings and ATO coordination.
  • Other duties as assigned.

Skills

U.S. Citizen
Active Secret clearance
DoD 8140 IAT Level II Security+
Onsite five days a week
RMF/NIST 800-53 knowledge
ACAS/Nessus experience
Trellix experience
eMASS familiarity

Tools

ACAS/Nessus
Trellix / ESS
eMASS
Sentinel

Job description

Job Description

Everforth ECS is seeking an Information System Security Officer (ISSO) to work onsite at our Ft. Meade, MD office. Everforth ECS is seeking an experienced Information System Security Officer (ISSO) to support robust Impact Level (IL) 5 and IL6 programs in an operational DoW environment that houses multiple U.S. Coalition Mission Partner Environments (MPE).

This position is a demanding, high-energy role that requires strong cybersecurity judgement, attention to detail, and the ability to support authorization, compliance, and continuous monitoring activities across multiple enclaves in a dynamic Azure DoW environment. The ideal candidate has hands‑on ISSO experience supporting classified DoW programs, a working knowledge of RMF and NIST 800-53 controls, and familiarity with cyber tools such as ACAS and Trellix. They are organized, proactive, comfortable collecting and validating security artifacts, and able to communicate clearly with both technical and non-technical stakeholders. The ISSO reports to the Senior Technical Program Manager.

Job Responsibilities
  • Support:
    • ISSO activities for a DoD Azure environment, including RMF, ATO maintenance, continuous monitoring, and compliance documentation.
    • Development and maintenance of ATO artifacts, including security plans, control evidence, vulnerability reports, diagrams, inventories, and risk documentation.
    • Security control assessments, audit readiness, continuous monitoring reviews, and authorization package updates for classified systems.
  • Develop, update, and track POA&Ms for vulnerabilities, STIG findings, control gaps, audit findings, and other security risks.
  • Maintain eMASS records, including control implementation details, artifacts, POA&Ms, assessment results, risk documentation, and continuous monitoring evidence.
  • Review and validate STIG artifacts submitted by engineers, including checklists, scan results, remediation evidence, mitigations, and closure documentation.
  • Work with engineers, system administrators, cloud teams, and government stakeholders to validate findings, track remediation, and keep security documentation current.
  • Administer and maintain ACAS, including Nessus scanners, plugin updates, troubleshooting credentialed scan issues, scan scheduling, and vulnerability reporting.
  • Review ACAS scan results and prepare vulnerability reports, metrics, POA&M updates, and remediation tracking artifacts.
  • Administer and support Trellix / ESS, including ePO policies, endpoint protection settings, agent health, alert monitoring, and reporting.
  • Investigate Trellix endpoint alerts, suspicious activity, malware events, and agent issues; assist with tuning policies, exclusions, and alerting logic to reduce false positives while maintaining required security coverage.
  • Assist with monitoring, configuring, and documenting alerts, incidents, dashboards, and security events in Microsoft Sentinel.
  • Participate in cybersecurity status meetings, vulnerability reviews, POA&M reviews, and ATO‑related coordination with government and contractor teams.
  • Other duties, as assigned.

Salary Range: $150,000-170,000

Required Skills
  • U.S. Citizen.
  • Active Secret clearance
  • Active a DoD 8140 IAT Level II Security+ (or higher) active.
  • Ability to work five days a week onsite at Fort Meade, MD.
  • Experience supporting:
    • DoD RMF, ATO maintenance, continuous monitoring, and security authorization documentation.
    • vulnerability management activities using ACAS/Nessus.
  • Hands‑on experience with eMASS or similar RMF/GRC software, including control documentation, artifact management, POA&M tracking, and authorization package maintenance.
  • Knowledge of security control inheritance/ shared responsibility matrixing. Ability to map control responsibilities between cloud providers such as Azure/AWS.
  • Skilled in writing and updating System Security Plans, Plans of Actions and milestones (POA&Ms) and continuous monitoring strategies based on cloud architecture and configuration baselines.
  • Proficiency or knowledge of cloud platform security services such as Azure policy, MS Defender for Cloud to evaluate compliance posture.
  • Capability to analyze cloud audit trails and log monitoring services such as Sentinel.
  • Knowledge of hardening benchmarks (DISA STIGS)
  • Understanding of ACAS- credentialed scanning, loading and modifying DISA STIG benchmarks as well as analysis and categorization of vulnerabilities
  • Knowledge of how to prepare scan results for upload into eMASS or any other governance tools.
  • Ability to translate complex technical vulnerabilities into clear business mission risk statements for Authorizing Officials, ISSMs and/or System Owners.
  • Experience with:
    • Creating, updating, and managing POA&Ms for vulnerabilities, STIG findings, audit findings, and NIST800-53 controls.
    • Reviewing and validating DISA STIG artifacts and coordinating remediation activities with technical teams.
    • Trellix endpoint/security tools.
  • Familiarity with NIST SP 800-53 controls, DoD RMF processes, and cyber security assessment documentation.
  • Practical understanding of secured IT infrastructure, particularly Windows, RHEL, and Azure environments, with the ability to evaluate how network, identity, server, endpoint, authentication, logging, and core service components affect security, compliance, and authorization posture.
  • Strong problem‑solving and decision‑making capabilities, with a proven ability to weigh the relative costs and benefits of potential actions and identify the most appropriate solution.
  • Highly developed interpersonal and oral/written communication skills, with the ability to effectively and professionally interact with a diverse set of stakeholders (from peers to end-users to executive management).

Salary Range: $150,000-170,000

Desired Skills
  • Experience supporting:
    • Microsoft Azure or other cloud environments in a DoD or federal environment.
    • Security Control Assessments.
  • Experience with Microsoft Sentinel, Microsoft Defender for Cloud, Azure Policy, or other security monitoring/compliance tools.
  • Strong technical writing skills, including the ability to develop control implementation statements, risk mitigation narratives, POAM closure justifications, and ATO documentation.

ECS Federal LLC is an equal opportunity employer and does not discriminate or allow discrimination on the basis any characteristic protected by law. All qualified applicants will receive consideration for employment without regard to disability, status as a protected veteran or any other status protected by applicable federal, state, or local jurisdiction law.

Everforth ECS

Everforth ECS is the federal segment of Everforth, a $4B global organization with over 10,000 employees. Our nearly 3,500 professionals deliver advanced technology solutions in data and AI, cybersecurity, and enterprise transformation, serving defense, intelligence, and federal civilian agencies. Our work powers mission-critical outcomes, strengthens technology partnerships, and creates meaningful opportunities for our people. We are defined by a commitment to excellence in delivery, a culture of innovation, and an environment where talent can thrive and grow.

We Value
  • Attracting and developing top talent and high-performing teams
  • Fostering a culture that is engaging, accountable, and mission-driven

Meet the challenge. Make a difference with Everforth ECS!

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Information System Security Officer
Information System Security Officer

ECS • Arlington (VA)

On-site
USD 120,000 - 165,000
Information Systems Security Manager
Information Systems Security Manager

ECS • Fairfax (VA)

On-site
USD 170,000 - 190,000
Information Systems Security Manager
Information Systems Security Manager

Everforth ECS • Merrifield (VA)

On-site
USD 140,000 - 190,000
Information Systems Security Officer (ISSO) - Mid
Information Systems Security Officer (ISSO) - Mid

Everforth ECS • Winchester (VA)

On-site
USD 110,000 - 160,000
Senior Information Systems Security Officer (ISSO)
Senior Information Systems Security Officer (ISSO)

ECS • Washington

On-site
USD 102,000 - 127,000
Senior Information Systems Security Officer (ISSO)
Senior Information Systems Security Officer (ISSO)

Everforth ECS • Washington

On-site
USD 102,000 - 127,000
Senior Information Systems Security Officer (ISSO)
Senior Information Systems Security Officer (ISSO)

Everforth ECS • Quantico (VA)

On-site
USD 100,000 - 124,000
Senior Information Systems Security Officer (ISSO)
Senior Information Systems Security Officer (ISSO)

ECS • Quantico (VA)

On-site
USD 100,000 - 124,000
CISO
CISO

ECS • Sierra Vista (AZ)

On-site
USD 180,000 - 240,000
Junior Information Systems Security Officer (ISSO)
Junior Information Systems Security Officer (ISSO)

Everforth ECS • Washington

On-site
USD 90,000 - 120,000