Information Systems Security Officer (ISSO), Mid

Quantum Sky

Washington (District of Columbia)

On-site

USD 105,000 - 125,000

Full time

7 days ago
Be an early applicant
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Benefits offered by this job

Health/Dental/Vision
401(k) match
Paid Time Off
Parental leave

Job summary

Quantum Sky is seeking an Information Systems Security Officer (ISSO), Mid, to support a federal customer in Washington, DC. The role focuses on leading security, privacy, and GRC activities across RMF lifecycle and ensuring system security and compliance.

You will communicate with CORs and stakeholders, develop authorization packages per NIST SP 800-53, and drive remediation to completion. On-site with limited remote flexibility, competitive compensation from $105,000 to $125,000 plus benefits.

Qualifications

  • Bachelor's degree plus 4+ years in cybersecurity, IA, or GRC in RMF lifecycle.
  • Experience with federal privacy programs and Privacy Act compliance.
  • Ability to communicate complex security concepts to technical and executive stakeholders.
  • Knowledge of NIST SP 800-53, FISMA, and CNSS guidance.

Responsibilities

  • Lead RMF lifecycle activities including ATO and continuous monitoring.
  • Develop security authorization packages and related artifacts.
  • Advise CORs, system owners, and stakeholders on security requirements.
  • Coordinate privacy, contingency, and incident response activities.

Skills

RMF knowledge
Strong communication
COR liaison

Education

Bachelor's degree

Tools

NIST RMF
CSAM/ServiceNow
Nessus/Qualys

Job description

Description

Quantum Sky is searching for an Information Systems Security Officer (ISSO), Mid to support a federal customer in Washington, DC. We are looking for a highly organized, proactive, and customer-focused cybersecurity professional who excels at building trusted relationships, communicating with both technical and executive stakeholders, and independently driving complex initiatives to successful completion.

The ideal candidate thrives in a fast-paced environment, embraces ownership and accountability, and consistently delivers high-quality work while balancing customer needs with federal security and privacy requirements. In this role, you will serve as a trusted advisor to government customers while leading information security, privacy, and Governance, Risk, and Compliance (GRC) activities to ensure federal systems remain secure, compliant, and mission-ready.

Responsibilities:

  • Lead and support information system security responsibilities throughout the Risk Management Framework (RMF) lifecycle, including Authorization to Operate (ATO), continuous monitoring, and integration of security, privacy, and legal requirements.
  • Develop, maintain, and present security authorization packages and supporting documentation in accordance with client requirements and NIST SP 800-53, including SSPPs, RARs, SAPs, SARs, POA&Ms, contingency and incident response plans, SOPs, configuration management plans, STIG deviations, and related artifacts.
  • Own security and privacy initiatives from planning through completion by proactively managing tasks, driving remediation efforts, validating corrective actions, and ensuring deliverables are completed accurately and on schedule.
  • Perform security and privacy risk assessments, analyze vulnerability scan results, recommend risk-based solutions, and support continuous monitoring activities across applications, infrastructure, and databases.
  • Serve as a trusted cybersecurity advisor to Contracting Officer Representatives (CORs), system owners, business stakeholders, and technical teams by communicating complex security and privacy requirements clearly, professionally, and with a customer-focused approach.
  • Develop, coordinate, test, and maintain contingency planning, incident response, privacy, and continuity activities, including PTAs, PIAs, HVA support, privacy training, and privacy-by-design integration throughout the System Development Life Cycle (SDLC).
  • Develop and maintain privacy policies, directives, SOPs, and operational guidance while ensuring compliance with applicable federal privacy laws, OMB guidance, NIST publications, CJIS Security Policy, and Legislative Branch requirements.
  • Build strong cross-functional relationships while managing multiple concurrent priorities in a fast-paced environment, identifying process improvements, and maintaining exceptional attention to detail across all security and compliance activities.
  • Coordinate with internal and external stakeholders to support audits, agency data calls, reporting requirements, asset inventories, and other compliance initiatives.
Qualifications

Required:

  • Bachelor's degree and at least four (4) years of relevant experience supporting cybersecurity, information assurance, or Governance, Risk, and Compliance (GRC) activities within the NIST Risk Management Framework (RMF) lifecycle.
    • High school diploma with 8 years of experience in Functional Responsibility area may be substituted for a Bachelor’s Degree
    • PMP, ISO 27001, or CISM certifications equate to 3 years of experience in Functional Responsibility each
    • ITIL, CISSP, or other relevant IT management certifications equate to 2 years of general experience each
  • Knowledge of and proficiency in federal government privacy programs, including the Privacy Act of 1974, the E-Government Act of 2002, and related federal privacy laws and regulations.
  • Demonstrated understanding of information privacy principles, including information access, release of information, and implementation of privacy controls for electronic and non-electronic information.
  • Experience supporting Cybersecurity Awareness Training (CSAT) privacy initiatives, including training development, effectiveness evaluation, and privacy awareness programs.
  • Experience with HR privacy and behavioral privacy considerations related to workforce data and monitoring activities.
  • Thorough knowledge of FISMA, NIST RMF, Security and Privacy Assessment & Authorization (SPA&A), NIST publications, OMB circulars and memoranda, and CNSS guidance.
  • Strong written and verbal communication skills with experience developing technical documentation, presenting complex security and privacy concepts to technical and non-technical audiences, and building trusted relationships with Contracting Officer Representatives (CORs), government leadership, and cross-functional stakeholders.
  • Demonstrated ability to lead end-to-end security and compliance initiatives by proactively managing competing priorities, driving deliverables to completion, and exercising sound judgment in a fast-paced, customer-focused environment.
  • Highly organized, detail-oriented, and self-motivated with strong analytical and critical thinking skills, a commitment to producing audit-ready documentation, and the ability to identify process improvements while balancing customer service with regulatory compliance.

Desired:

  • CRISC, CAP, CISSP, or equivalent
  • Experience with FedRAMP and cloud service providers
  • Experience with CSAM and ServiceNow
  • Experience with vulnerability assessment tools such as Nessus and/or Qualys
  • Policy writing background is highly preferred

Clearance:

  • US Citizen with Public Trust eligibility required

Location:

  • On-site in DC, minimal remote flexibility
About Quantum Sky

Compensation:

  • Compensation is unique to each candidate and relative to the skills and experience they bring to the position. The salary range for this position is typically between $105,000-$125,000. This does not guarantee a specific salary as compensation is based upon multiple factors such as education, experience, certifications, and other requirements, and may fall outside of the above-stated range.

Benefits:

  • Highlights of our benefits include Health/Dental/Vision, 401(k) match, Paid Time Off, STD/LTD/Life Insurance, Referral Bonuses, professional development reimbursement, and parental leave.

The world the mission operates in is going post-quantum, contested, and machine-speed. Quantum Sky engineers the advantage across cyber, networks, software, and quantum because the mission demands dominance, not parity. We don't follow the map. We draw it.

At Quantum Sky, we believe that success starts with our people. We foster a collaborative, innovative, and mission-driven environment where every team member plays a critical role in shaping the future of technology. Are you ready to join #TeamQuantumSky?

Quantum Sky Engineering LLC is an Equal Opportunity Employer; all qualified applicants will receive consideration for employment without regard to race, color, religion, sex, [sexual orientation, gender identity,] national origin, disability, status as a protected veteran, or any characteristic protected by applicable law.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Information Systems Security Officer - Washington DC
Information Systems Security Officer - Washington DC

VetJobs • Washington

On-site
USD 105,000 - 125,000
Health/Dental/Vision
401(k) match
Paid Time Off
Senior Information System Security Officer (ISSO)
Senior Information System Security Officer (ISSO)

Quantum Sky • Washington

On-site
USD 140,000 - 150,000
Health/Dental/Vision
401(k) match
Paid Time Off
Security Control Assessor, Mid
Security Control Assessor, Mid

Quantum Sky • Washington

On-site
USD 95,000 - 109,000
Health/Dental/Vision
401(k) match
Paid Time Off
+1
Information Systems Security Officer (ISSO)
Information Systems Security Officer (ISSO)

Quantum Sky • Washington

On-site
USD 110,000 - 140,000
Cybersecurity Analyst - Journeyman
Cybersecurity Analyst - Journeyman

Quantum Sky • Colorado Springs (CO)

On-site
USD 80,000 - 95,000
Health/Dental/Vision
401(k) match
Flexible Time Off
+2
Information Security Analyst - SME
Information Security Analyst - SME

Quantum Sky • Quantico Base (VA)

On-site
USD 155,000 - 165,000
Health/Dental/Vision
401(k) match
Paid Time Off
+1
Information Security Analyst - SME
Information Security Analyst - SME

Quantum Sky • Marine Corps Base Camp Lejeune (NC)

On-site
USD 155,000 - 165,000
Health/Dental/Vision
401(k) match
Paid Time Off
+4
Information Security Analyst - SME
Information Security Analyst - SME

Quantum Sky • Jacksonville (NC)

On-site
USD 155,000 - 165,000
Health/Dental/Vision
401(k) match
Paid Time Off
+4
Cybersecurity DevSecOps Engineer
Cybersecurity DevSecOps Engineer

Quantum Sky • United States

Remote
USD 130,000 - 160,000
Health/Dental/Vision
401(k) match
Paid Time Off
+1
Cybersecurity / Information Assurance Lead
Cybersecurity / Information Assurance Lead

Quantum Sky • Arlington (VA)

On-site
USD 140,000 - 175,000