Information Systems Security Officer II (ISSO2)

Runavir

Northern (KY)

Hybrid

USD 160,000 - 200,000

Full time

14 days+
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Job summary

Runavir in Hanover, MD seeks an Information Systems Security Officer II (ISSO2) to manage day-to-day security operations and monitor systems with limited supervision. The role emphasizes continuous monitoring, STIG checks, and secure tool health and coverage verification.

Responsibilities include coordinating remediation with admins and engineers, validating fixes via re-scan, maintaining evidence repositories, and providing posture inputs to support RMF reporting.

Qualifications

  • Experience in information systems security, vulnerability analysis, and RMF.
  • Ability to coordinate remediation with administrators and engineers.
  • TS/SCI with Polygraph clearance.

Responsibilities

  • Lead day-to-day security operations for assigned systems.
  • Plan and execute vulnerability and compliance scans.
  • Coordinate remediation with administrators and validate fixes.
  • Maintain security evidence repositories.
  • Support IAM control execution and access reviews.
  • Provide inputs for change control discussions.
  • Produce security posture inputs for reporting.

Skills

Security monitoring
Incident triage
Stig/compliance checks
RMF knowledge
Vulnerability assessment
System administration
Evidence repositories
Log analysis
Threat monitoring

Education

Bachelor's degree + 5 years of relevant experience
Master's degree + 3 years of relevant experience

Tools

Stig tools
Security scanning tools

Job description

Information Systems Security Officer II (ISSO2)

Location: Hanover, MD (On-Site) | Status: Open

We are currently seeking an Information Systems Security Officer II (ISSO2) to independently execute and coordinate day-to-day security operations for assigned systems with limited supervision. This role leads continuous monitoring technical activities, including scan scheduling and support, log/alert triage, STIG compliance verification, and security tool health and coverage checks. The ISSO2 coordinates remediation actions with system administrators and engineers, validates corrective actions through re-scan and re-check activities, and maintains accurate operational security evidence repositories, providing technical evidence and posture inputs to the ISSM to support RMF reporting and assessments. This role does not own RMF package governance, manage POA&Ms as the accountable authority, or make risk acceptance decisions.

If you are detail-oriented, comfortable owning day-to-day security operations, and enjoy driving remediation to closure, then this is the position for you!

Work Schedule

Courses run 0800-1700, Monday through Friday. Contract core hours are 1000-1400.

Essential Responsibilities (describe the day-to-day)
  • Lead day-to-day security operations for assigned systems, including monitoring and triage of security alerts and logs, validation of security tool health and coverage, and escalation of incidents per SOP.
  • Plan and execute vulnerability and compliance scanning activities (credentialed or non-credentialed, as approved), perform basic false-positive review, document results, and maintain remediation tickets with accurate technical detail.
  • Execute and validate STIG/compliance posture checks as assigned, coordinating remediation with administrators and validating fixes via re-check with documented completion evidence.
  • Maintain security evidence repositories for assigned systems (scan outputs, STIG checklists, tool status evidence, access review artifacts), ensuring proper labeling, access control, and retrievability.
  • Support IAM control execution by coordinating account actions with administrators and supporting periodic access reviews, documenting results and discrepancies for disposition by Government/ISSM.
  • Provide technical security-impact inputs for proposed changes (affected components, required re-scan/re-test recommendations, control evidence impacts) to support change control discussions, in a non-approval role.
  • Produce recurring technical posture inputs (scan trends, top recurring findings, remediation aging) for ISSM/government reporting, and keep tickets updated to reflect current status.
Work Environment, Physical Demands, and Mental Demands

General office environment. The work environment is fast-paced and sometimes involves extreme deadline pressures. The nature of the work requires a high degree of teamwork and cooperation with other members of the staff as well as individuals across the Company and Customers.

Minimum Requirements (Knowledge, Skills, and Abilities)
  • Experience in information systems design, development, programming, information/computer/cyber/network security, vulnerability analysis, penetration testing, computer forensics, computer systems research, reverse engineering, and/or systems engineering (requirements analysis, design, implementation, testing, integration, deployment/installation, and maintenance).
  • Network and system administration experience may satisfy some, but not all, of the relevant experience requirement.
Security Clearance Required

TS/SCI with Polygraph

Minimum Education

One of the following:

  • Doctoral degree, no experience required; or
  • Master's degree, plus three (3) years of relevant experience; or
  • Bachelor's degree, plus five (5) years of relevant experience; or
  • Associate's degree (or 18 semester hours of military coursework/training in a computer-related field), plus seven (7) years of relevant experience.

A degree in Information Assurance, Information Security, Information Systems, Information Technology, Computer Networking, Information Science, Cybersecurity, or a related field is preferred.

Required Certifications

Information Assurance Manager (IAM) Tier I certification must be obtained within six (6) months of assignment to the position. Continued certification must be maintained through continuous education or sustainment training while serving in this role.

Preferred Qualifications
  • Experience with the Risk Management Framework (RMF), Information Systems Security technologies, and IT policies, including the ability to interpret policies and directives.
Other Responsibilities

Procedure Compliance: Each employee must read, understand, and implement the general and specific operational, safety, quality, and environmental requirements of all plans, procedures, and policies pertaining to his/her job. Qualified applicants will receive consideration for employment without regard to race, color, religion, sex, age, national origin, ancestry, marital status, sexual orientation, gender identity or expression, disability, genetic information, pregnancy or pregnancy-related conditions, protected veteran status, or any other characteristic protected by applicable federal, state, or local law.

Compensation Details

$160,000 - $200,000

The compensation range or hourly rate listed for this position is provided as a good faith estimate of what the company intends to offer for this role at the time this posting was issued. Actual compensation may vary based on factors such as job responsibilities, education, experience, skills, internal equity, market data, applicable collective bargaining agreements, and relevant laws.

Benefits Overview

Our health and welfare benefits are designed to support you and your priorities. For a full overview of our offerings, visit runavir.com/benefits.

Note: Benefits may vary based on employment type, location, and applicable agreements.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

ISSO - (Active TS/SCI Clearance with Full Scope Poly Required)
ISSO - (Active TS/SCI Clearance with Full Scope Poly Required)

J&T Business Consulting • Corridor North (MD)

On-site
USD 140,000 - 190,000
Health Insurance
Dental and Vision Insurance
Life Insurance and Disability
+4
Information System Security Officer (ISSO) *
Information System Security Officer (ISSO) *

Mission Technologies, a division of HII • Bath Township (OH)

On-site
USD 72,000 - 100,000
Information Systems Security Officer 2-BP-162
Information Systems Security Officer 2-BP-162

Onyx Point, Inc. • Hanover (MD)

On-site
USD 78,000 - 250,000
Health coverage
401(k) plan
Paid time off
+8
Information System Security Officer (ISSO)
Information System Security Officer (ISSO)

Open Systems Technologies Corporation • Maryland

On-site
USD 120,000 - 180,000
3 weeks paid time off
11 Federal Holidays
Medical and dental coverage
+2
Information System Security Officer
Information System Security Officer

Inadev • Reston (VA)

Hybrid
USD 110,000 - 170,000
External Job Posting Title Information System Security Officer (ISSO)
External Job Posting Title Information System Security Officer (ISSO)

Peraton • Laurel (MD)

On-site
USD 104,000 - 166,000
Information System Security Officer
Information System Security Officer

Peraton • Corridor North (MD)

On-site
USD 104,000 - 166,000
Information System Security Officer II
Information System Security Officer II

Targeted Solutions, LLC • Albuquerque (NM)

On-site
USD 90,000 - 140,000
PTO and Flexible holidays
Tax-free healthcare reimbursement
401K with 4% match
Information System Security Officer II
Information System Security Officer II

Targeted Solutions, LLC • Warner Robins (GA)

On-site
USD 90,000 - 120,000
PTO and Flexible holidays
401K with matching (4%)
Tax-free healthcare cost reimbursement
Information System Security Officer (ISSO) II (TS, w/ SCI Eligibility)
Information System Security Officer (ISSO) II (TS, w/ SCI Eligibility)

RedTrace Technologies • Kirtland (NM)

On-site
USD 99,000 - 114,000
Competitive salary
401(k) plan
Annual performance bonus
+7