Information Systems Security Officer (ISSO)

Socket.dev

Reston (VA)

On-site

USD 120,000 - 150,000

Full time

5 days ago
Be an early applicant
Application generator

Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Benefits offered by this job

Medical, Dental and Vision Insurance
Paid Time Off
401(k) Options
Tuition Reimbursement
Professional Development Reimbursement
Gym and Fitness Reimbursement
Employee Assistance Program
Annual Salary Reviews

Job summary

Metron seeks a capable Information Systems Security Officer (ISSO) to own the cybersecurity posture and authorization lifecycle of multiple classified and unclassified information systems in Reston, VA. You will work closely with the ISSM, CISO, system administrators, program leadership, and government customers to manage day-to-day security operations and maintain readiness.

This mid-level role requires a solid RMF foundation and hands-on experience with RMF artifacts, A&A processes, and

Qualifications

  • Active Top Secret clearance and current SSBI or Tier 5 investigation.
  • 3+ years in cybersecurity, system administration, or information assurance for DoD RMF.
  • Hands-on RMF artifacts: SSPs, SCTMs, POA&Ms, eMASS.
  • Active DoD 8140 IAM Level II certification or higher (e.g., CASP+, CAP, CISM, CISSP).
  • Knowledge of NIST SP 800-53 controls in classified environments.
  • Experience with continuous monitoring or vulnerability management across enclaves.

Responsibilities

  • Manage A&A lifecycle for assigned systems following RMF, JSIG, NIST 800-53, DoD policy.
  • Develop and maintain SSPs, SCTMs, STIG packages, POA&Ms, risk assessments, and eMASS records.
  • Evaluate changes for cybersecurity and authorization impact; prepare for reviews and inspections.
  • Execute ConMon and vulnerability management; track findings to closure.
  • Review configuration, audit, access, and evidence against baselines and STIGs; drive POA&M actions.
  • Manage user and privileged access; enforce removable media and data handling rules.
  • Support COMSEC accountability, incident investigations, and SIPRNet operations.
  • Serve as main cybersecurity contact with program managers, vendors, and government representatives.

Skills

RMF knowledge
A&A lifecycle
Security operations
Policy enforcement

Education

Bachelor’s degree (CS/Cybersecurity)

Tools

Windows Server
eMASS
STIGs

Job description

About Metron

Metron is an employee-owned company dedicated to delivering innovative solutions for the most challenging national security problems. For over 40 years, our principled approach to problem-solving has yielded creative solutions at the intersection of advanced mathematics, computer science, physics, and engineering. Our people are leaders in their technical fields and are passionate about solving challenging problems. We look for individuals who share this same passion and can apply their experience in real-world settings.

Metron is seeking a capable Information Systems Security Officer (ISSO) to own the cybersecurity posture and authorization lifecycle of multiple classified and unclassified information systems. Working closely with the ISSM, CISO, system administrators, program leadership, and government customers, the ISSO manages day-to-day security operations, maintains authorization and accreditation documentation, and keeps systems compliant and mission ready.

This role suits a mid-level practitioner with a solid RMF foundation and hands-on classified system experience who is ready to take ownership of authorization packages with the support of an experienced ISSM and CISO. It is well suited to a strong system administrator or information assurance professional stepping into a dedicated ISSO role, and offers meaningful room to grow within an expanding classified program portfolio.

Core Responsibilities
  • Manage the Assessment and Authorization (A&A) lifecycle for assigned systems in accordance with RMF, JSIG, NIST SP 800-53, DISA STIG, and DoD/DCSA policy, under the direction of the ISSM, and maintain readiness for recurring assessments.
  • Develop and maintain SSPs, SCTMs, STIG packages, POA&Ms, risk assessments, and eMASS records, ensuring documentation reflects the current architecture and security posture.
  • Evaluate proposed system changes for cybersecurity, compliance, and authorization impact, and prepare systems for internal reviews, customer assessments, and inspections.
  • Execute and document continuous monitoring (ConMon) and vulnerability management across assigned classified enclaves, tracking findings through remediation and closure.
  • Review configuration, audit, access, and security-control evidence against applicable baselines and STIGs, and drive corrective actions under the POA&M process.
  • Administer user and privileged access based on role, need-to-know, and least privilege, and enforce requirements for removable media, data transfers, classified information handling, and secure equipment movement.
  • Support COMSEC accountability, incident investigation and reporting (policy violations, unauthorized access, data spills), and classified communications link operations including SIPRNet, in coordination with the ISSM.
  • Serve as the primary cybersecurity point of contact for assigned systems, coordinating with program managers, vendors, and government representatives including SCAs and AOs, and providing status on risk, compliance, and remediation.
Required Qualifications
  • Active Top Secret clearance (with current SSBI or Tier 5 investigation).
  • Minimum of 3 years of experience in a cybersecurity, system administration, or information assurance role supporting classified systems under the DoD RMF, including hands-on administration of Windows server and desktop environments in classified domains.
  • Hands-on experience contributing to RMF authorization activities and artifacts, such as SSPs, SCTMs, POA&Ms, and eMASS records.
  • Active DoD 8140 IAM Level II certification or higher (CASP+ CE, CAP, CISM, or CISSP).
  • Working knowledge of NIST SP 800-53 security controls in classified system environments.
  • Experience performing continuous monitoring, vulnerability management, or cybersecurity hygiene activities across classified network enclaves.
Desired Qualifications
  • Bachelor’s degree in Computer Science, Cybersecurity, Information Systems, or a related field.
  • Prior experience in a dedicated ISSO role, or independently managing or co-owning RMF authorization packages.
  • Experience supporting DCSA authorization processes and interfacing directly with SCAs or AOs in DCSA or DARPA contexts.
  • Experience managing multiple authorization packages or secure environments simultaneously, including SCI or SAP environments.
  • Experience with Linux operating systems; system hardening and STIG compliance experience.
  • Familiarity with NISPOM, DFARS 252.204-7012, and FISMA requirements; basic network administration (Cisco or equivalent).
Why Join Metron
  • Support mission-critical national security and advanced research programs, with direct ownership of the security posture of complex information systems.
  • Work with experienced cybersecurity, engineering, program, and government stakeholders across a growing portfolio of programs.
Location: Reston, VA

Perks and Benefits:

  • Medical, Dental and Vision Insurance
  • Accompanying FSA and HSA options
  • Additional Voluntary Benefits
  • Paid Time Off
  • 9 Observed Holidays and 2 Floating Holidays
  • Paid Parental Leave
  • Tuition Reimbursement
  • Professional Development Reimbursement
  • Annual Salary Reviews
  • Profit Sharing
  • 401(k) Traditional and Roth Options
  • Gym and Fitness Reimbursement
  • Employee Assistance Program
  • Employee Referral Program

Metron is an Equal Employment Opportunity (EEO) employer. It is the policy of the company to provide equal employment opportunities to all qualified applicants without regard to race, color, religious, sex, sexual orientation, gender identity, national origin, age, protected veteran or disabled status, or genetic information.

VEVRAA Federal Contractor

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Information Systems Security Officer (ISSO)
Information Systems Security Officer (ISSO)

Metron • Reston (VA)

On-site
USD 100,000 - 160,000
Medical Insurance
Dental Insurance
Vision Insurance
+2
ISSO: Own Security Posture & RMF for Classified Systems
ISSO: Own Security Posture & RMF for Classified Systems

Metron • Reston (VA)

On-site
USD 100,000 - 160,000
Medical Insurance
Dental Insurance
Vision Insurance
+2
Software Engineer, Infrastructure
Software Engineer, Infrastructure

Metron • Reston (VA)

On-site
USD 90,000 - 130,000
Medical Insurance
Relocation Assistance
Tuition Reimbursement
+5
Information Systems Security Officer
Information Systems Security Officer

Kids for the Future • Foster (VA)

Hybrid
USD 120,000 - 185,000
Information System Security Officer (ISSO)
Information System Security Officer (ISSO)

Peraton Labs • Laurel (MD)

On-site
USD 104,000 - 166,000
Medical benefits
401(k)
Paid time off (PTO)
Information System Security Manager (ISSM)
Information System Security Manager (ISSM)

MBL Technologies, Inc. • Virginia (IL), Northern (KY)

Hybrid
USD 120,000 - 180,000
401K
PTO
Remote work
+2
Software Engineer, Infrastructure
Software Engineer, Infrastructure

Metron Inc. • Reston (VA)

On-site
USD 110,000 - 150,000
Medical, Dental and Vision Insurance
Paid Time Off
Relocation Assistance
+3
Information System Security Officer (ISSO)
Information System Security Officer (ISSO)

Maximus • Northern (KY)

Hybrid
USD 90,000 - 140,000
Information System Security Officer (ISSO)
Information System Security Officer (ISSO)

MBL Technologies, Inc. • Virginia (IL), Northern (KY)

Hybrid
USD 120,000 - 160,000
Remote work
401K
PTO
+2
Senior Information System Security Officer (ISSO)
Senior Information System Security Officer (ISSO)

Peraton • Laurel (MD)

On-site
USD 135,000 - 216,000
Competitive salary
Discretionary bonus