Information Systems Security Officer (Technical ISSO / RMF Assessor)

Peraton

Herndon (VA)

On-site

USD 120,000 - 180,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Peraton seeks a highly skilled Information Systems Security Officer (ISSO) in Herndon, VA to develop, implement, and validate RMF security controls within DoD environments. You will write STPs, build SCTMs, interpret STIG findings, and produce audit-ready documentation.

The ideal candidate has hands-on RMF experience, TS/SCI eligibility or current clearance with polygraph, and strong Splunk/ACAS/Nessus skills. This role supports ATO efforts and continuous monitoring across DoD systems.

Qualifications

  • Bachelor's degree in a relevant technical field with 8+ years of relevant experience, or 12+ years of experience in lieu of a degree.
  • 8+ years of hands-on experience as an ISSO, ISSE, Assessor, Security Engineer, or closely related DoD cybersecurity role.
  • Experience writing STPs, creating SCTMs, and developing implementation statements.
  • Hands-on experience performing STIG interpretation and remediation.
  • Experience reviewing and validating ACAS/Nessus vulnerability scan results.
  • Ability to use Splunk (or similar SIEM) to validate security controls and investigate anomalies.
  • Direct experience authoring ATO documentation (SSP, SAR, POA&M, etc.).
  • Strong working knowledge of NIST SP 800-53, RMF, and DoD cybersecurity requirements.
  • Experience using Xacta or eMASS to manage RMF artifacts.
  • DoD 8570 IAM-II compliant certification (e.g., Security+, CISSP, CISM).
  • Strong written and verbal communication skills with the ability to explain technical topics clearly.

Responsibilities

  • Develop, write, and maintain Security Test Procedures (STPs) for NIST SP 800-53 controls.
  • Create and update Security Controls Traceability Matrices (SCTMs).
  • Draft, review, and refine control implementation statements for all control families.
  • Interpret and remediate STIG/SCAP findings across operating systems, applications, and infrastructure.
  • Conduct and analyze ACAS/Nessus vulnerability scan results; validate findings with engineering teams; track remediation to closure.
  • Perform Splunk log analysis to validate control operation and investigate anomalies.
  • Prepare and update core ATO documentation including SSPs, SARs, POA&Ms, Contingency Plans, Continuous Monitoring artifacts, and other related BoE components.
  • Lead and support RMF Steps 1–6 for assigned systems.
  • Manage, validate, and maintain control evidence in alignment with NIST SP 800-53 and DoD requirements.
  • Support continuous monitoring activities, including log review, vulnerability assessments, and control re-validation.
  • Coordinate directly with system owners and engineering teams to address security gaps.
  • Ensure system documentation is maintained accurately and entered in tools such as Xacta or eMASS.
  • Provide security guidance for system changes, risk assessments, and configuration updates.
  • Communicate technical risks, findings, and required actions to system owners, government counterparts, and internal leadership.
  • Participate in security meetings, assessments, and audits.
  • Assist with incident response activities as needed, including log review and security control validation.

Skills

Clearance handling
Security engineering
RMF/NIST SP 800-53
Vulnerability analysis
Splunk analysis
STIG interpretation

Education

Bachelor's degree in a relevant technical field

Tools

Splunk
ACAS/Nessus
Xacta
eMASS

Job description

Required Qualifications


  • Active TS clearance with SCI eligibility OR TS/SCI clearance adjudication with current polygraph OR the ability to pass a polygraph.

  • Bachelor's degree in a relevant technical field with 8+ years of relevant experience, or 12+ years of experience in lieu of a degree.

  • 8+ years of hands-on experience as an ISSO, ISSE, Assessor, Security Engineer, or closely related DoD cybersecurity role.

  • Demonstrated experience writing STPs, creating SCTMs, and developing implementation statements.

  • Hands-on experience performing STIG interpretation and remediation.

  • Experience reviewing and validating ACAS/Nessus vulnerability scan results.

  • Ability to use Splunk (or similar SIEM) to validate security controls and investigate anomalies.

  • Direct experience authoring ATO documentation (SSP, SAR, POA&M, etc.).

  • Strong working knowledge of NIST SP 800-53, RMF, and DoD cybersecurity requirements.

  • Experience using Xacta or eMASS to manage RMF artifacts.

  • DoD 8570 IAM-II compliant certification (e.g., Security+, CISSP, CISM).

  • Strong written and verbal communication skills with the ability to explain technical topics clearly.


Desired Qualifications


  • Experience as a Security Control Assessor (SCA) or assessor support.

  • Familiarity with FISMA, FISCAM, and federal audit requirements.

  • Experience supporting cloud environments (AWS GovCloud preferred).

  • Experience with automation or scripting to support security tasks.

  • Strong understanding of Zero Trust principles.

  • Experience supporting SAP/SAR or other high-side environments.


Peraton offers enhanced benefits to employees working on this critical National Security program, which include heavily subsidized employee benefits coverage for you and your dependents, 25 days of PTO accrued annually up to a generous PTO cap and eligible to participate in an attractive bonus plan


Job Summary

We are seeking a highly skilled and technically proficient Information Systems Security Officer (ISSO) with hands-on experience developing, implementing, and validating security controls within DoD RMF environments. This role requires deep technical understanding of NIST SP 800-53 controls, STIG implementation, vulnerability analysis, and the ability to produce assessable, audit-ready security documentation.


The ideal candidate will be confident writing Security Test Procedures (STPs), building Security Controls Traceability Matrices (SCTMs), interpreting ACAS/Nessus scan results, and using Splunk to verify control effectiveness. This ISSO will work closely with system owners, engineers, and government stakeholders to support ATO efforts and continuous monitoring activities.


Duties & Responsibilities:

Core Technical Responsibilities


  • Develop, write, and maintain Security Test Procedures (STPs) for NIST SP 800-53 controls.

  • Create and update Security Controls Traceability Matrices (SCTMs).

  • Draft, review, and refine control implementation statements for all control families.

  • Interpret and remediate STIG/SCAP findings across operating systems, applications, and infrastructure.

  • Conduct and analyze ACAS/Nessus vulnerability scan results; validate findings with engineering teams; track remediation to closure.

  • Perform Splunk log analysis to validate control operation and investigate anomalies.

  • Prepare and update core ATO documentation including SSPs, SARs, POA&Ms, Contingency Plans, Continuous Monitoring artifacts, and other related Body of Evidence (BoE) components.


RMF & Security Lifecycle


  • Lead and support RMF Steps 1–6 for assigned systems.

  • Manage, validate, and maintain control evidence in alignment with NIST SP 800-53 and DoD requirements.

  • Support continuous monitoring activities, including log review, vulnerability assessments, and control re-validation.

  • Coordinate directly with system owners and engineering teams to address security gaps.

  • Ensure system documentation is maintained accurately and entered in tools such as Xacta or eMASS.

  • Provide security guidance for system changes, risk assessments, and configuration updates.


Collaboration & Stakeholder Support


  • Communicate technical risks, findings, and required actions to system owners, government counterparts, and internal leadership.

  • Participate in security meetings, assessments, and audits.

  • Assist with incident response activities as needed, including log review and security control validation.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Information Systems Security Officer (Technical ISSO / RMF Assessor)
Information Systems Security Officer (Technical ISSO / RMF Assessor)

Peraton • Riverdale Park (MD)

On-site
USD 112,000 - 179,000
Heavily subsidized employee benefits
25 days of PTO annually
Eligibility for bonus plan
Information System Security Officer (ISSO)
Information System Security Officer (ISSO)

Peraton • Maryland

On-site
USD 90,000 - 120,000
Information System Security Officer
Information System Security Officer

Inadev • Reston (VA)

Hybrid
USD 110,000 - 170,000
Senior Information System Security Officer (ISSO)
Senior Information System Security Officer (ISSO)

Peraton • Maryland

On-site
USD 120,000 - 160,000
Information Systems Security Officer
Information Systems Security Officer

Peraton • Maryland

On-site
USD 100,000 - 130,000
Information Security Analyst
Information Security Analyst

SANMINA-SCI TECHNOLOGY INDIA PRIVATE LIMITED • Huntsville (AL)

On-site
USD 95,000 - 140,000
Senior Information Security Analyst
Senior Information Security Analyst

Wood River Federal • San Antonio (TX)

On-site
USD 100,000 - 150,000
Information System Security Officer (ISSO)
Information System Security Officer (ISSO)

Ara • Albuquerque (NM), Northern (KY)

Hybrid
USD 95,000 - 130,000
Information Systems Security Officer (ISSO)
Information Systems Security Officer (ISSO)

Cgsfederal • Atlanta (GA)

On-site
USD 110,000 - 140,000
Health, Dental, and Vision
Life Insurance
401k
+2
Information Systems Security Manager (ISSM)
Information Systems Security Manager (ISSM)

The Mission Essential Group, LLC • Fairfax (VA)

On-site
USD 170,000 - 195,000
Medical Insurance
Dental Insurance
Vision Insurance
+4