Information Systems Security Officer (ISSO)

The Mission Essential Group, LLC

Fairfax (VA)

On-site

USD 120,000 - 135,000

Full time

3 days ago
Be an early applicant
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Benefits offered by this job

Medical insurance
Dental insurance
Vision insurance
Life insurance
Disability insurance
Paid time off
Retirement benefits

Job summary

The Mission Essential Group, LLC (MEG) is a Fairfax, Virginia-based provider of information management and cybersecurity services, delivering RMF/A&A support, vulnerability management, and continuous monitoring across DoD programs. This ISSO role focuses on implementing security controls, assessing authorization, and coordinating with stakeholders to maintain secure, compliant information systems.

This position requires an active TS clearance and a strong background in RMF, eMASS/Xacta, and

Qualifications

  • Active TS clearance.
  • Bachelor's degree in computer science, Information Systems, Cybersecurity, Information Technology.
  • Minimum of five (5) years of Cyber Security experience.
  • Minimum of three (3) years of RMF experience per NIST SP 800-37 Rev. 2.
  • Working knowledge of federal and DoD cybersecurity standards (NIST SP 800-60, SP 800-53 Rev 5, CNSSI 1253 Rev 5, DoDI 8510.01).
  • Experience supporting SIPRNet-connected systems and environments.
  • Strong knowledge of Windows server and workstation administration.
  • Experience managing RMF packages using eMASS/Xacta.
  • Experience with encryption, data protection, IAM, PAM, vulnerability management, and continuous monitoring.
  • Current CompTIA Security+ or equivalent 8570/8140 baseline.

Responsibilities

  • Support A&A activities including RMF package development, security control implementation, assessment, validation, monitoring, POA&M tracking, and ATO processes using eMASS and/or Xacta.
  • Verify changes to systems that may impact security posture and authorization status.
  • Serve as liaison between system owners, ISSMs, engineers, assessors, and cybersecurity stakeholders.
  • Ensure day-to-day implementation, oversight, monitoring, and security compliance of multiple information systems.
  • Lead meetings with SMEs to identify, document, validate, and track cybersecurity requirements.
  • Conduct vulnerability assessments and security scans with Nessus and related tools.
  • Implement and track protective and corrective actions for incidents, vulnerabilities, or deficiencies.
  • Perform risk assessments and assist with mitigation of cybersecurity risks.
  • Support installation, configuration, and maintenance of hardware/software in secure environments.
  • Apply security patches and configuration changes to maintain compliance.
  • Develop Security Control Traceability Matrices (SCTMs) mapping requirements to DoD/NIST controls.
  • Stay current with federal/DoD cybersecurity policies and framework updates.
  • Support audits, compliance reviews, and security inspections.

Skills

RMF experience
Vulnerability management
Security scanning

Education

Bachelor's degree in computer science/Information Systems/Cybersecurity/IT

Tools

eMASS
Xacta
Nessus
SCAP Compliance Checker

Job description

Position: ISSO

Location: Fairfax, VA

Clearance: TS/SIC

Salary Range: $120,000 - $135,000

Job Description

The Mission Essential Group, LLC (MEG) is a premier service provider of information management solutions for complex, mission-critical needs. MEG has earned a reputation as an innovator and pioneer. Headquartered in Fairfax, VA, MEG employs professionals in offices located throughout the United States and around the world. MEG offers a competitive benefits package including a competitive salary; medical, dental, vision, life and disability insurance; paid time off; and retirement benefits.

MEG is a leading provider of Information Management system engineering, software development, information assurance, system sustainment and is the primary provider of technical support for the Integrated Broadcast Service (IBS) Enterprise. IBS is the worldwide Department of Defense (DoD) joint program for transporting intelligence, surveillance & reconnaissance (ISR) and targeting data to all levels of tactical and strategic operational users.

IBS provides global, 24/7, dissemination of time sensitive Indications & Warning and Force Protection data to Joint Warfighters and Collaborating Nation partners conducting military operations around the world. MEG serves a vital role in supporting the IBS Enterprise, providing continuity in skills crucial to support military operations. MEG integrates the talents and skills of team members to form an IBS Enterprise Support Services Team to provide world-class IBS customer support.

MEG provides innovative software tools, technical services, and rapid development of solutions to support end user requirements. As such our systems and products require are high level of quality and configuration management to ensure they meet and/or exceed customer expectations.

The ISSO serves as a key contributor to the organization's cybersecurity program, supporting the implementation of security controls, Risk Management Framework (RMF) activities, continuous monitoring, and Assessment and Authorization (A&A) efforts. This hands‑on position requires a strong understanding of information assurance principles, cybersecurity best practices, and federal and DoD regulatory requirements to ensure the confidentiality, integrity, and availability of mission‑critical information systems. The position is located at the company's headquarters in Fairfax, Virginia.

Duties and Responsibilities:
  • Support Assessment and Authorization (A&A) activities, including RMF package development, security control implementation, assessment, validation, continuous monitoring, vulnerability management, POA&M tracking, and Authority to Operate (ATO) processes using eMASS and/or Xacta.
  • Verify that system changes, upgrades, and modifications that may impact the security posture or authorization status of information systems are identified, documented, and communicated to appropriate stakeholders.
  • Serve as the primary liaison between system owners, Information System Security Managers (ISSMs), engineers, assessors, and other cybersecurity stakeholders.
  • Ensure the day‑to‑day implementation, oversight, continuous monitoring, and security compliance of multiple information systems.
  • Lead and facilitate meetings with technical and functional subject matter experts to identify, document, validate, and track cybersecurity and compliance requirements.
  • Conduct vulnerability assessments and security scans using tools such as Nessus, SCAP Compliance Checker, and other approved scanning solutions.
  • Ensure appropriate protective and corrective actions are implemented and tracked when security incidents, vulnerabilities, or compliance deficiencies are identified.
  • Perform risk assessments and assist with the identification, analysis, and mitigation of cybersecurity risks.
  • Support the installation, configuration, and maintenance of hardware and software within secure computing environments.
  • Apply security patches, updates, and configuration changes to maintain system compliance and reduce cybersecurity risk.
  • Conduct cybersecurity investigations and develop reports, findings, recommendations, and corrective action plans as required.
  • Develop and maintain Security Control Traceability Matrices (SCTMs) to map security requirements to DoD and NIST security controls.
  • Research emerging technologies, cybersecurity threats, vulnerabilities, and industry best practices to support continuous improvement of security programs.
  • Stay current with applicable federal and DoD cybersecurity policies, standards, regulations, and framework updates.
  • Support audit activities, compliance reviews, and security inspections to ensure adherence to organizational and regulatory requirements.
  • Assist with continuous monitoring activities, including vulnerability remediation, incident tracking, configuration management, and ongoing authorization support.
Minimum Qualifications:
  • Active TS clearance
  • Bachelor's degree in computer science, Information Systems, Cybersecurity, Information Technology
  • Minimum of Five (5) years of Cyber Security experience
  • Minimum of three (3) years of experience applying the NIST Risk Management Framework (RMF) in accordance with NIST SP 800-37 Revision 2
  • Working knowledge of federal and DoD cybersecurity standards and guidance, including NIST SP 800-60, NIST SP 800-53 Revision 5, CNSSI 1253 Revision 5, DoDI 8510.01 (RMF), and related authorization/accreditation processes.
  • Experience supporting, administering, and maintaining SIPRNet-connected systems and environments.
  • Strong knowledge and hands‑on administration of Microsoft Windows server and workstation operating environments.
  • Experience managing RMF packages and authorization activities using eMASS and/or Xacta workflow tools.
  • Practical experience implementing and supporting cybersecurity technologies and controls, including encryption, data protection, identity and access management, privileged access management, vulnerability management, and continuous monitoring.
  • Possession of a current CompTIA Security+ certification or equivalent DoD 8570/8140‑approved baseline certification.
Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Information System Security Officer (ISSO)
Information System Security Officer (ISSO)

JFL Consulting LLC • Omaha (NE)

On-site
USD 120,000 - 140,000
Full medical coverage (incl. depend.)
FSAs
Life and disability insurance
+3
Information System Security Officer (ISSO) / System Administrator
Information System Security Officer (ISSO) / System Administrator

Sanmina-SCI Systems de México • Huntsville (AL)

On-site
USD 90,000 - 150,000
Senior Information Systems Security Officer (ISSO)
Senior Information Systems Security Officer (ISSO)

Independent Software, Inc. • Maryland

On-site
USD 100,000 - 130,000
Information System Security Manager (ISSM)
Information System Security Manager (ISSM)

JFL Consulting LLC • Springfield (VA)

On-site
USD 155,000 - 175,000
Salary 155k-175k
Medical/dental/vision premiums
FSA accounts
+4
Information System Security Officer (ISSO)
Information System Security Officer (ISSO)

Peraton • Laurel (MD)

On-site
USD 120,000 - 190,000
Sign-on bonus (may apply)
Information Systems Security Officer (ISSO)
Information Systems Security Officer (ISSO)

Mount Mary University • Washington

Hybrid
USD 110,000 - 140,000
ISSO 3 - Information Sytems Security Officer
ISSO 3 - Information Sytems Security Officer

InisCore Technologies • Fort Meade (MD)

On-site
USD 120,000 - 150,000
Information System Security Officer (ISSO)
Information System Security Officer (ISSO)

PD Inc • Washington

On-site
USD 120,000 - 170,000
ISSO 2 - Information Systems Security Officer
ISSO 2 - Information Systems Security Officer

InisCore Technologies • Maryland

On-site
USD 120,000 - 160,000
Information System Security Officer (ISSO) / System Administrator
Information System Security Officer (ISSO) / System Administrator

Sanmina Corporation • Huntsville (AL)

On-site
USD 90,000 - 120,000