Information System Security Officer (ISSO)

Maximus

Northern (KY)

Hybrid

USD 90,000 - 140,000

Full time

20 hours ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Maximus is seeking an Information Systems Security Officer (ISSO) in Arlington, VA, to secure and manage the organization's DoD/COTS information systems. You will implement policies, conduct security audits, and ensure compliance with JSIG, RMF, and NIST standards.

The role requires TS/SCI clearance, a technical degree, and 8+ years in cybersecurity with DoD/IC experience. You will work across teams to maintain CUI/PII protections, manage eMASS and STIGs, and lead vulnerability remediation.

Qualifications

  • Active TS/SCI clearance required at hire, eligible for CI poly after hire.
  • Bachelor's degree in a technical field; 8 years of cybersecurity experience may substitute.
  • 8+ years in cybersecurity with DoD/IC experience.
  • Strong knowledge of RMF, NIST, FIPS 199/200, and FedRAMP.
  • Experience with RMF-based security controls and DoD STIGs.
  • Ability to work independently and collaboratively.

Responsibilities

  • Verify data security access controls per JSIG guidelines.
  • Monitor and enforce media control and data protection procedures.
  • Manage eMASS configuration and DoD STIG compliance.
  • Produce POA&M and vulnerability risk analyses.
  • Develop security programs and coordinate with stakeholders.

Skills

TS/SCI Clearance
RMF / NIST / FISMA
Cybersecurity governance
Team player
Quick learner

Education

Bachelor's degree in Computer Science, Information Systems, Engineering, or related technical discipline
Security+ or DoD 8570 equivalent

Tools

Splunk
eMASS
ACAS
JSIG guidance

Job description

Information System Security Officer (ISSO)

General information

Date

Thursday, August 20, 2026

City

Arlington

State

VA

Country

United States

Working time

Full-time

Description & Requirements

Maximus is seeking a highly skilled Information Systems Security Operator (ISSO) to join our team in Rosslyn, VA.

The ideal candidate will be responsible for ensuring the security and integrity of our information systems by implementing and maintaining robust security measures. This includes developing and enforcing security policies, conducting regular security audits, and staying up to date with the latest cybersecurity threats and trends.

Job-Specific Essential Duties and Responsibilities
  • Verify data security access controls based on the Joint Special Access Program Implementation Guide (JSIG).
  • Implement media control procedures and continuously monitor for compliance.
  • Verify data security access controls and assign privileges based on need-to-know.
  • Investigate suspected cybersecurity incidents in accordance with Departmental directives and applicable Risk Management Implementation Plans (RMIPs).
  • Verify authenticator generation and verification requirements and processes.
  • Execute media sanitization (clearing, purging, or destroying) and reuse procedures.
  • Protect Controlled Unclassified Information (CUI), Special Access Programs (SAP), Sensitive Compartmented Information (SCI), and Personally Identifiable Information (PII).
  • Create and manage the Body of Evidence (BOE).
  • Maintain privilege access control logs.
  • Create and manage Interconnection Security Agreements (ISA).
  • Ensure JSIG compliance of applications within multiple accredited boundaries.
  • Track vulnerabilities by creating Plan of Action and Milestones (POA&M).
  • Manage the configuration and documentation in the program’s instance of Enterprise Mission Assurance Support Services (eMASS).
  • Maintain and manage continuous monitoring of DoD Security Technical Implementation Guide (STIG) compliance.
  • Enforce continuous monitoring strategies using tools such as Splunk, Oracle Cloud Control, ACAS reports, and scripts for database/application user/privilege review.
  • Conduct code reviews for database and application development and configuration management activities.
  • Analyze events or test results and prepare POA&Ms.
  • Integrate project management, configuration management, continuous monitoring, and POA&M processes.
  • Prepare reports identifying the results of compliance and performance tests.
  • Develop and implement information assurance/security standards and procedures.
  • Coordinate, develop, and evaluate security programs for the organization.
  • Review information assurance/security solutions to support customer requirements.
  • Identify, report, and resolve security violations.
  • Establish and satisfy information assurance and security requirements based on user, policy, regulatory, and resource demands.
  • Perform vulnerability/risk analysis of computer systems and applications during all phases of the system development life cycle.
Job-Specific Minimum Requirements
  • Active TS/SCI Clearance required at the time of hire. Candidate must be eligible for and willing to successfully complete a CI Polygraph after hire.
  • Bachelor's degree with preference for Computer Science, Information Systems, Engineering, or related technical discipline.
  • 4 years of relevant work experience may be considered in lieu of the degree requirement.
  • Minimum of 8 years of general experience in cybersecurity or a related field.
  • 4+ years of experience displaying strong knowledge of operating systems (e.g., Windows, Linux).
  • 4+ years of cybersecurity experience in the Department of Defense (DoD) or Intelligence community.
  • Strong knowledge of cybersecurity principles, tools, and techniques.
  • Demonstrated experience with the Risk Management Framework (RMF), Federal Information Security Management Act (FISMA), and National Institute of Standards and Technology (NIST) FIPS 199/200 and Special Publications.
  • Experience with the Federal Risk and Authorization Management Program (FedRAMP).
  • Security+ or equivalent (DoD 8570) if no current preferred IAM Level II certification (below).
  • Quick learner and team player.
Preferred Skills and Qualifications
  • IAM level II certification (CASP+, GSLC, CISM, CISSP).
  • Experience as a Cyber or Security Analyst or Security Control Assessor (SCA) for federal information systems.
  • Experience with the Special Access Programs (SAPs) and Intelligence Community (IC).
  • Knowledge and/or understanding of Joint Special Access Program Implementation Guide (JSIG)
  • The ability to adapt in fast paced environments, comfort with ambiguity.
  • Familiarity with cloud technologies, security practices, and agile methodologies.
  • Strong self-organization and self-management skills with emphasis on self-initiation and follow-through.
  • Proven written and oral communication skills.
  • Experience in reviewing proposed change requests related to system design/configuration and performing security impact analysis.
  • The ability to work independently.
Pay Transparency

Maximus compensation is based on various factors including but not limited to job location, a candidate's education, training, experience, expected quality and quantity of work, required travel (if any), external market and internal value analysis including seniority and merit systems, as well as internal pay alignment. Annual salary is just one component of Maximus's total compensation package. Other rewards may include short- and long-term incentives as well as program-specific awards. Additionally, Maximus provides a variety of benefits to employees, including health insurance coverage, life and disability insurance, a retirement savings plan, paid holidays and paid time off. Compensation ranges may differ based on contract value but will be commensurate with job duties and relevant work experience. An applicant's salary history will not be used in determining compensation. Maximus will comply with regulatory minimum wage rates and exempt salary thresholds in all instances.

Accommodations

Maximus provides reasonable accommodations to individuals requiring assistance during any phase of the employment process due to a disability, medical condition, or physical or mental impairment. If you require assistance at any stage of the employment process—including accessing job postings, completing assessments, or participating in interviews,—please contact People Operations at applicantaccom@maximus.com .

EEO Statement

Maximus is an equal opportunity employer. We evaluate qualified applicants without regard to race, color, religion, sex, age, national origin, disability, veteran status, genetic information and other legally protected characteristics.

Maximus TCS (Technology and Consulting Services) Internal Job Profile Code: TCS040, T4, Band 7

TCS040, T4, Band 7

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Information System Security Officer (ISSO)
Information System Security Officer (ISSO)

Maximus • Arlington (TX)

On-site
USD 120,000 - 160,000
Information System Security Officer (ISSO)
Information System Security Officer (ISSO)

Maximus • Arlington (VA)

On-site
USD 116,500 - 155,000
Security Operations Manager
Security Operations Manager

Maximus • United States

On-site
USD 100,000 - 155,000
Sr. Information Systems Security Officer (ISSO)
Sr. Information Systems Security Officer (ISSO)

Themis Insight, LLC. • Fort Meade (MD)

On-site
USD 120,000 - 180,000
Health plans with premiums covered
401k with company contributions
13 holidays plus PTO
Sr. Information Systems Security Officer (ISSO)
Sr. Information Systems Security Officer (ISSO)

Themis Insight • Fort Meade (MD)

On-site
USD 125,000 - 160,000
Competitive health, dental, and vision
401k with 6% contribution
11 holidays and 25 days PTO
+2
Information Systems Security Officer(ISSO), Mid (MCSES III)
Information Systems Security Officer(ISSO), Mid (MCSES III)

AMERICAN SYSTEMS • McLean (VA)

On-site
USD 140,000 - 160,000
Healthcare benefits
Paid leave
Retirement plans
+1
Security Operations Shift Lead
Security Operations Shift Lead

Maximus • United States

On-site
USD 60,000 - 100,000
Sr. Information Systems Security Officer (ISSO)
Sr. Information Systems Security Officer (ISSO)

Themis Insight, LLC • Fort Meade (MD)

On-site
USD 110,000 - 150,000
Health benefits
401k with 6% employer contribution
Paid holidays and PTO
+2
Sr. Information Systems Security Officer (ISSO)
Sr. Information Systems Security Officer (ISSO)

Power3 • Laurel (MD)

On-site
USD 120,000 - 180,000
Competitive health, dental, and vision
401k retirement contributions
Time off: holidays + PTO
+2
Information System Security Officer (ISSO) - Mid / Senior Level - FULLY CLEARED with POLYGRAPH [...]
Information System Security Officer (ISSO) - Mid / Senior Level - FULLY CLEARED with POLYGRAPH [...]

Cti Md • Maryland

On-site
USD 120,000 - 160,000
Healthcare
Dental insurance
Vision with employer-paid premium
+4