Information Systems Security Officer

Talentify

Annapolis (MD)

Hybrid

USD 120,000 - 154,000

Full time

14 days+
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Benefits offered by this job

Medical, dental & vision insurance
401(k) retirement plan
Short & long-term disability

Job summary

Actalent is seeking an Information Systems Security Officer (ISSO) to lead cybersecurity for DoD software projects, focusing on RMF compliance, AWS container workloads, and continuous security improvement.

You will collaborate with engineering, cybersecurity, business, and customer stakeholders, driving security packages, attestations, and incident response across multiple releases.

Qualifications

  • At least 5 years as an ISSE on DoD software projects.
  • Experience generating and submitting SSPs, POA&Ms, and RMF/STIG artifacts.
  • Hands-on DoD tools like eMASS and STIG Viewer for security package development.
  • Proven ability to obtain and maintain at least one DoD ATO for AWS-based workloads.
  • Knowledge of SAST tools (e.g., SonarQube) and container scanning (e.g., Trivy).
  • Experience with data protection, encryption, and access control strategies.
  • Strong RMF cybersecurity lifecycle communication with engineering, cybersecurity, business and customers.
  • Possession of one or more cybersecurity certifications (CISSP, CASP, Security+).

Responsibilities

  • Lead cybersecurity for DoD software projects across the full system lifecycle.
  • Prepare and submit SSPs, POA&Ms, and RMF/STIG artifacts for DoD workflows.
  • Use DoD tools (eMASS, STIG Viewer) to build and validate security packages.
  • Obtain/maintain DoD ATO for AWS container workloads.
  • Define mitigations from SAST results (SonarQube) and container scans (Trivy).
  • Advise on data protection and testing security controls.
  • Conduct threat modeling to identify attack vectors and prioritize mitigations.
  • Lead vulnerability management across development and operations teams.
  • Monitor security posture with ScSI tools and cloud monitoring services.
  • Collaborate with engineering, security, business and customers on risk and progress.
  • Support DevSecOps with security guidance across releases.
  • Utilize Wiz/eMASSter for posture assessment and compliance tracking.
  • Contribute to SOC design and operations using Splunk/CloudWatch.

Skills

RMF/DoD
ISSE experience
Threat modeling
Vulnerability mgmt
Security monitoring
Data protection
SAST tools
Container security
Certifications (CISSP/CASP/Security+)

Tools

eMASS
STIG Viewer
Wiz
eMASSter
SonarQube
Trivy
Splunk
CloudWatch
Security Hub
GuardDuty

Job description

Job Title: Information Systems Security OfficerJob Description

The Information Systems Security Officer will lead cybersecurity efforts for complex software projects within a United States Department of Defense (DoD) environment, with a strong focus on Risk Management Framework (RMF) compliance and secure cloud-based workloads. This role drives the creation, submission, and maintenance of security packages and authorizations, including obtaining and sustaining Authorization to Operate (ATO) for Amazon Web Services (AWS) container-based solutions. The position requires deep expertise in DoD cybersecurity processes, tools, and standards, as well as strong communication and collaboration skills across engineering, cybersecurity, business, and customer stakeholders.

Responsibilities
  • Serve as an Information Systems Security Engineer (ISSE) for DoD software projects, providing cybersecurity leadership and guidance across the full system lifecycle.
  • Generate and submit complete System Security Packages (SSPs), Plans of Action and Milestones (POA&Ms), and other required artifacts to support DoD Risk Management Framework (RMF) and Security Technical Implementation Guide (STIG) processes.
  • Apply DoD cybersecurity tools, including eMASS and STIG Viewer, to build, manage, and validate security packages and supporting documentation.
  • Obtain and maintain at least one DoD Authorization to Operate (ATO) for AWS-deployed container-based workloads, ensuring ongoing compliance with DoD security requirements.
  • Inform and define software mitigation requirements based on results from static application security testing (SAST) tools such as SonarQube and container scanning tools such as Trivy.
  • Recommend and validate data protection mechanisms, including encryption and access control strategies, to safeguard sensitive information in deployed workloads.
  • Test and verify security controls to ensure they function as designed and effectively reduce risk across applications and infrastructure.
  • Conduct threat modeling activities to identify potential attack vectors and prioritize security mitigations for software systems and cloud workloads.
  • Lead vulnerability management activities, including identifying, tracking, and coordinating remediation of security findings across development and operations teams.
  • Monitor the security posture of deployed workloads, leveraging appropriate tools and processes to detect and respond to anomalous or malicious activity.
  • Collaborate effectively with engineering, cybersecurity, business, and customer stakeholders throughout the RMF cybersecurity lifecycle, ensuring clear communication of risks, requirements, and progress.
  • Provide security guidance and input to DevSecOps teams across multiple software releases, helping integrate security best practices into continuous integration and deployment processes.
  • Use system security tools such as Wiz or eMASSter to support security posture assessment, reporting, and ongoing compliance activities.
  • Contribute to the design and operation of Security Operations Center (SOC) functions, using tools such as Splunk or CloudWatch to support monitoring and incident response.
  • Leverage AWS security services, including Security Hub and GuardDuty, to strengthen detection, response, and compliance capabilities in cloud environments.
  • Apply knowledge of CIS benchmarks and other industry security standards to align system configurations and controls with recognized best practices.
  • Support or coordinate activities related to penetration testing, fuzz testing, and dynamic application security testing (DAST), and use results to drive remediation and improvement.
  • Document security requirements, decisions, and outcomes clearly and comprehensively to support audits, assessments, and continuous improvement.
Essential Skills
  • At least 5 years of experience serving as an Information Systems Security Engineer (ISSE) for United States Department of Defense (DoD) software projects.
  • Proven experience generating and submitting System Security Packages (SSPs), Plans of Action and Milestones (POA&Ms), and other artifacts required for DoD Risk Management Framework (RMF) and Security Technical Implementation Guide (STIG) processes.
  • Hands-on experience applying DoD cybersecurity tools such as eMASS and STIG Viewer to develop and manage security packages.
  • Demonstrated success obtaining and maintaining at least one DoD Authorization to Operate (ATO) for an AWS-deployed container-based workload.
  • Strong background in cyber security, including threat modeling, vulnerability management, security monitoring, and data protection for deployed workloads.
  • Experience informing software mitigation requirements based on output from static application security testing (SAST) tools such as SonarQube.
  • Experience using container scanning tools such as Trivy to identify and remediate vulnerabilities in containerized workloads.
  • Demonstrated expertise in recommending and validating data protections and testing security controls for complex systems.
  • Track record of effective communication and collaboration throughout the RMF cybersecurity lifecycle with engineering, cybersecurity, business, and customer stakeholders.
  • Possession of one or more relevant cybersecurity certifications, such as CISSP, CASP, or Security+.
Additional Skills & Qualifications
  • Experience with United States Intelligence Community (IC) system cybersecurity processes and tools.
  • background in establishing or operating Security Operations Center (SOC) functions, including use of tools such as Splunk or CloudWatch.
  • Hands-on experience with AWS security services, such as Security Hub and GuardDuty, to enhance cloud security monitoring and compliance.
  • Experience serving as an ISSE on a DevSecOps team through multiple software releases, integrating security into continuous delivery pipelines.
  • Familiarity with system security tools such as Wiz or eMASSter for posture assessment and compliance tracking.
  • Knowledge of CIS benchmarks and other industry security standards, and the ability to apply them to system hardening and configuration.
  • Exposure to penetration testing, fuzz testing, and dynamic application security testing (DAST) tools and techniques, with the ability to interpret results and support remediation.
Work Environment

The role focuses on securing DoD and cloud-based software workloads, particularly AWS-deployed container environments, using a range of cybersecurity tools, frameworks, and industry standards. You will work closely with engineering, cybersecurity, business, and customer stakeholders in a collaborative setting that values clear communication and thorough documentation. The environment emphasizes adherence to DoD RMF, STIG requirements, and ATO processes, and makes extensive use of tools such as eMASS, STIG Viewer, SonarQube, Trivy, Wiz, eMASSter, Splunk, CloudWatch, and AWS security services like Security Hub and GuardDuty. The position supports a culture of continuous improvement in security posture, integration with DevSecOps practices, and proactive monitoring and vulnerability management across deployed workloads. Dress code and specific onsite or remote arrangements are determined by organizational policies and project needs.

Job Type & Location

This is a Contract position based out of Annapolis, MD.

Pay and Benefits

The pay range for this position is $120000.00 - $153920.00/hr.

Individual compensation offered for this position within this range will depend on many factors, including qualifications, skills, relevant experience, job knowledge, geographic location, internal equity, and other pertinent job-related factors.

Eligibility requirements apply to some benefits and may depend on your job classification and length of employment. Benefits are subject to change and may be subject to specific elections, plan, or program terms. If eligible, the benefits available for this temporary role may include the following: Medical, dental & vision Critical Illness, Accident, and Hospital 401(k) Retirement Plan – Pre-tax and Roth post-tax contributions available Life Insurance (Voluntary Life & AD&D for the employee and dependents) Short and long-term disability Health Spending Account (HSA) Transportation benefits Employee Assistance Program Time Off/Leave (PTO, Vacation or Sick Leave)

Workplace Type

This is a hybrid position in Annapolis,MD.

Application Deadline

This position is anticipated to close on Oct 2, 2026.

About Actalent

Actalent is a global leader in engineering and sciences services and talent solutions. We help visionary companies advance their engineering and science initiatives through access to specialized experts who drive scale, innovation and speed to market. With a network of almost 20,000 consultants and 5,000 clients across the U.S., Canada, Asia and Europe, Actalent serves many of the Fortune 500. We are proud to be an Engineering News-Record (ENR) Top 500 Design Firm for our engineering design services and a ClearlyRated Best of Staffing winner for both client and talent service.

The company is an equal opportunity employer and will consider all applications without regard to race, sex, age, color, religion, national origin, veteran status, disability, sexual orientation, gender identity, genetic information or any characteristic protected by law.

If you would like to request a reasonable accommodation, such as the modification or adjustment of the job application process or interviewing process due to a disability, please email actalentaccommodation@actalentservices.com for other accommodation options.

San Francisco Fair Chance Ordinance

Pursuant to the San Francisco Fair Chance Ordinance, for all positions located in the city and county of San Francisco, we will consider for employment qualified applicants with arrest and conviction records.

Massachusetts Lie Detector

It is unlawful in Massachusetts to require or administer a lie detector test as a condition of employment or continued employment. An employer who violates this law shall be subject to criminal penalties and civil liability.

Use of Artificial Intelligence (AI)

We may use Artificial Intelligence (AI) to support parts of our hiring process, including sourcing, screening, and evaluating candidates. AI helps assess applications and qualifications, but final decisions are made by our hiring team. By applying, you acknowledge and agree that your application may be reviewed using AI tools.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Information Systems Security Officer
Information Systems Security Officer

Actalent • United States

Hybrid
USD 120,000 - 154,000
Medical, dental & vision
401(k) Retirement Plan
Life Insurance
+1
Cyber Security Engineer
Cyber Security Engineer

Talentify • Manassas (VA)

On-site
USD 90,000 - 103,000
Medical, dental & vision
401(k) Retirement Plan
Onsite work environment
Full Stack Developer
Full Stack Developer

Talentify • Rockville (MD)

On-site
USD 110,000 - 180,000
Medical
Dental
Vision
+7
Systems Administrator
Systems Administrator

Actalent • Warrenton (VA)

Hybrid
USD 66,000 - 87,000
Hybrid work schedule
On-site onboarding in Warrenton
Competitive benefits
Software Engineer
Software Engineer

Actalent • Moorestown Township (NJ)

On-site
USD 59,000 - 96,000
Systems Engineer
Systems Engineer

Actalent • Odon (IN)

Hybrid
USD 69,000 - 96,000
Full Stack Developer
Full Stack Developer

Talentify • Maryland

On-site
USD 73,000 - 118,000
Medical, dental & vision
401(k) Retirement Plan
Life Insurance
+1
Network Engineer
Network Engineer

Talentify • Colorado Springs (CO)

On-site
USD 55,000 - 96,000
Medical, Dental & Vision
401(k)/Roth
Life & AD&D
+5
Systems Engineer - Requirements Management
Systems Engineer - Requirements Management

Actalent • Tampa (FL)

Hybrid
USD 103,000 - 131,000
Systems Analyst
Systems Analyst

Talentify • Moorestown Township (NJ)

On-site
USD 55,000 - 94,000
Medical, dental & vision
401(k) Retirement Plan
Life Insurance
+5