Information System Security Officer (ISSO)

Testpros

Washington (District of Columbia)

On-site

USD 70,000 - 145,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Testpros is hiring an Information System Security Officer (ISSO) in Washington, DC, responsible for supporting the cybersecurity and compliance requirements of federal systems. Key duties include documentation, risk assessment, and maintaining security posture.

The ideal candidate holds a Bachelor's degree in a related field and has at least 3 years of relevant experience. This role offers a salary range of $70,000 - $145,000 based on experience and qualifications.

Qualifications

  • Bachelor's degree or equivalent experience.
  • 3+ years in federal cybersecurity or RMF.
  • Experience with security documentation.

Responsibilities

  • Support RMF processes and compliance.
  • Develop security documentation.
  • Conduct security control assessments.

Skills

NIST 800-53
Risk Management Framework (RMF)
Vulnerability management
Communication skills

Education

Bachelor's degree in Information Technology, Cybersecurity, Computer Science, or related field

Tools

eMASS
XACTA
GovCloud
AWS
Azure

Job description

TestPros delivers innovative independent IT assessment solutions to critical challenges facing the nation and the world. We support the U.S. Federal Government and Commercial clients within the continental USA. TestPros is dedicated to making lives better, safer and more secure.

Start: Future projects late 2026 or 2027 (not an immediate job opening).

Overview

The Information System Security Officer (ISSO) supports the cybersecurity and compliance requirements of federal information systems in accordance with NIST, RMF, FISMA, FedRAMP, DoD, and agency-specific security requirements. The ISSO serves as the primary liaison between system owners, cybersecurity teams, and government stakeholders to ensure systems maintain an acceptable security posture and remain compliant throughout the system lifecycle.

Responsibilities
  • Support the implementation and maintenance of Risk Management Framework (RMF) processes.
  • Develop, review, and maintain security documentation, including:
    • System Security Plans (SSPs)
    • Security Assessment Reports (SARs)
    • Plans of Action & Milestones (POA&Ms)
    • Security Control Traceability Matrices (SCTMs)
    • Continuous Monitoring (ConMon) documentation
  • Conduct security control assessments and compliance reviews.
  • Coordinate Authorization to Operate (ATO), Interim ATO (IATO), and authorization package updates.
  • Support vulnerability management activities, including reviewing and tracking findings from tools such as Nessus, ACAS, Tenable, Qualys, and SCAP.
  • Monitor and assess cybersecurity risks and recommend mitigation strategies.
  • Coordinate with system administrators, network engineers, developers, and security personnel to address security requirements.
  • Review system changes and participate in configuration control boards (CCBs) as required.
  • Support audits, inspections, and cybersecurity assessments.
  • Ensure compliance with NIST 800-53, FISMA, agency policies, and applicable federal regulations.
  • Maintain security metrics and provide regular status reports to government stakeholders.
  • Support incident response activities and security investigations when required.
Required Qualifications
  • Bachelor's degree in Information Technology, Cybersecurity, Computer Science, or related field (or equivalent experience).
  • 3+ years of experience supporting federal cybersecurity, RMF, or information assurance programs.
  • Experience developing and maintaining RMF authorization packages.
  • Working knowledge of:
    • NIST 800-53
    • NIST 800-37
    • FISMA
    • Security Control Assessments
    • Continuous Monitoring
  • Experience with vulnerability scanning and remediation processes.
  • Strong written and verbal communication skills.
  • Active Top Secret or Secret or Pubic Trust clearance or ability to obtain one.
Preferred Qualifications
  • Experience with eMASS, XACTA, CSAM, or similar governance and compliance tools.
  • Knowledge of FedRAMP, DoD RMF, or Intelligence Community security requirements.
  • Experience supporting cloud environments (AWS, Azure, GovCloud).
  • Security certification such as:
    • Security+
    • CISSP
    • CAP
    • CISM
    • GSLC
Desired Skills
  • Risk assessment and mitigation
  • Security compliance and auditing
  • Vulnerability management
  • Cybersecurity policy implementation
  • Security documentation development
  • Stakeholder coordination
  • Continuous monitoring and reporting

Typical Federal Customers: DHS, DoD, VA, HHS, Treasury, and other civilian federal agencies.

Salary Range: $70,000 - $145,000 (depending on experience, clearance level, and location). This rangerepresentsagood-faithestimate and is not a guarantee; final compensation isdeterminedby factors such as experience, qualifications, and government contract labor rate requirements and may fall outside the stated range.

Equal Opportunity Employer

TestPros is an equal‑opportunity employer and does not discriminate in employment based on race, color, religion, sex (including pregnancy and gender identity), national origin, political affiliation, sexual orientation, marital status, disability, genetic information, age, membership in an employee organization, retaliation, parental status, military service, or any other non‑merit factor.

Offer Considerations

TestPros considers several factors when extending an offer, including but not limited to, Federal Government contract labor categories and contract wage rates, relevant prior work experience, specific skills and competencies, geographic location, education, and certifications.

Federal Compliance

As a federal contractor, TestPros is subject to all federal and state mandates and/or other customer requirements.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Information Systems Security Officer (ISSO) Mid Level (TS w/ SCI Eligibility) -
Information Systems Security Officer (ISSO) Mid Level (TS w/ SCI Eligibility) -

RedTrace Technologies • Washington

On-site
USD 80,000 - 100,000
Competitive salary
401(k) plan
Annual performance bonus
+5
ISSO - Information Systems Security Officer
ISSO - Information Systems Security Officer

Anavationllc • Huntsville (AL)

On-site
USD 95,000 - 150,000
Senior Information System Security Officers (ISSO)
Senior Information System Security Officers (ISSO)

Global Solutions Consulting LLC. • Baltimore (MD)

Hybrid
USD 80,000 - 110,000
Competitive salary and benefits package
Flexible work arrangements
Professional development opportunities
Information System Security Officer (ISSO)
Information System Security Officer (ISSO)

ASSYST • Maryland

On-site
USD 120,000 - 160,000
Information Systems Security Officer (FORECASTED)
Information Systems Security Officer (FORECASTED)

Columbia Technology Partners • Corridor North (MD)

On-site
USD 110,000 - 170,000
Information Systems Security Officer (Technical ISSO / RMF Assessor)
Information Systems Security Officer (Technical ISSO / RMF Assessor)

Peraton • Riverdale Park (MD)

On-site
USD 112,000 - 179,000
Heavily subsidized employee benefits
25 days of PTO annually
Eligibility for bonus plan
Cybersecurity - Lead ISSO
Cybersecurity - Lead ISSO

Securepro Inc • Arlington (VA)

On-site
USD 120,000 - 190,000
401(k)
401(k) matching
Dental insurance
+1
Information Systems Security Officer (ISSO)
Information Systems Security Officer (ISSO)

Skysoft Inc. • Maryland

Hybrid
USD 120,000 - 170,000
Information System Security Officer (ISSO)
Information System Security Officer (ISSO)

Cgsfederal • Tampa (FL)

On-site
USD 110,000 - 140,000
Health, dental, vision
401k
Flexible Spending Account (Health, Dep
Information System Security Officer (ISSO)
Information System Security Officer (ISSO)

Cgsfederal • New York (NY)

On-site
USD 90,000 - 150,000
Health, Dental, and Vision
Life Insurance
401k
+2