ISSO

PROVATOHR INC

Reston (VA)

On-site

USD 83,000 - 124,000

Part time

14 days+
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Job summary

PROVATOHR INC in Reston, VA seeks an Information System Security Officer (ISSO) to manage the Authorization to Operate lifecycle for classified systems in a SCIF environment. The role focuses on RMF governance, control enforcement, and compliance with ICD directives.

Responsibilities include developing SSPs, leading security assessments, monitoring vulnerabilities, and ensuring continuous authorization across the system.

Qualifications

  • 5–8 years in ISSO/ISSM or equivalent
  • Active TS/SCI with Full Scope Polygraph
  • IC ISSO training program completion
  • Strong experience with NIST RMF and ATO lifecycle
  • Experience developing SSPs and security packages
  • Knowledge of ICD 503, 704, 705
  • Experience in SCIF environments
  • Strong NIST 800-53 understanding
  • Independent work in highly regulated environments
  • Excellent documentation and audit readiness skills

Responsibilities

  • Own the ATO lifecycle for classified systems
  • Develop and maintain SSPs and RMF documentation
  • Lead security assessments and authorization decisions
  • Operate continuous monitoring programs
  • Track vulnerabilities and remediation activities
  • Ensure proper review and approval of system changes
  • Maintain oversight of privileged access and security-relevant changes
  • Collaborate with agency teams on secure system design and deployment

Skills

ATO lifecycle ownership
RMF governance
NIST 800-53 controls
SSP development
Certification & Accreditation
SCIF operations
Documentation & audit readiness
Independent decision making

Education

Bachelor's degree in Cybersecurity/IS/CS

Tools

ConMon

Job description

Information System Security Officer (ISSO) – SCIF (Mid/Senior Level)

Engagement Type: Contract, Part time

Office Location: Reston Town Center area (Reston, VA)

Environment: SCIF (IC Customer Support Environment)

Clearance Required: FSP

About the Role

Seeking a Information System Security Officer (ISSO) to serve as the security authorization authority for classified information systems operating within a SCIF environment. This is a systems security function focused on authorization, control enforcement, and compliance oversight. This role is responsible for ensuring systems are authorized, continuously monitored, and compliant with the NIST Risk Management Framework (RMF) and applicable Intelligence Community Directives (ICD 503, ICD 704, ICD 705).

Key Responsibilities

System Authorization & RMF Governance

  • Own the Authorization to Operate (ATO) lifecycle for classified systems
  • Develop and maintain System Security Plans (SSPs) and RMF documentation
  • Lead security assessments, authorization decisions, and reauthorization activities
  • Ensure alignment with NIST 800-53 control requirements

Continuous Monitoring & Risk Management

  • Operate continuous monitoring (ConMon) programs for in-scope systems
  • Track and manage vulnerabilities, control gaps, and remediation activities
  • Ensure timely resolution of findings impacting system authorization status

Security Governance & Control Independence

  • Enforce segregation of duties between system administration and security authorization
  • Validate that system changes are properly reviewed, approved, and documented
  • Maintain oversight of privileged access and security-relevant system modifications

Engineering & Platform Collaboration

  • Partner with Agency infrastructure, platform, and application teams on secure system design and operation
  • Provide security requirements during system deployment and change activities
  • Support remediation of audit findings and control deficiencies
Required Qualifications
  • 5–8 years of experience in ISSO, ISSM, or equivalent systems security role
  • Active TS/SCI with Full Scope Polygraph
  • Completion of an IC ISSO training program (or equivalent)
  • Strong experience with NIST RMF and ATO lifecycle management
  • Experience developing and maintaining SSPs and security authorization packages
  • Working knowledge of ICD 503, ICD 704, ICD 705
  • Experience operating in classified or SCIF environments
  • Strong understanding of NIST 800-53 security controls and assessment processes
  • Ability to work independently in a highly regulated environment
  • Strong documentation, communication, and audit readiness skills
Preferred Experience
  • Prior experience supporting IC or DoD classified system environments
  • Experience with continuous monitoring (ConMon) and control automation
  • Background in cloud, hybrid, or on-prem classified infrastructure environments
  • Experience supporting security assessments, ATO renewals, and audit remediation
  • Familiarity with enterprise security and vulnerability management tooling
Education

Bachelor’s degree in Cybersecurity, Information Systems, Computer Science, or related field preferred; equivalent experience considered.

Additional Information

This role is focused exclusively on information system security authorization and compliance, not personnel security, facility security, or clearance management. Supports SCIF-based classified systems operating under IC customer requirements and requires sustained focus on security control integrity, authorization continuity, and compliance monitoring.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Information System Security Officer ISSO SCIF
Information System Security Officer ISSO SCIF

Eitacies Inc • Reston (VA)

On-site
USD 110,000 - 165,000
Information System Security Officer ISSO SCIF
Information System Security Officer ISSO SCIF

EITACIES Inc. • Reston (VA)

On-site
USD 120,000 - 180,000
Senior Information Systems Security Officer (ISSO)
Senior Information Systems Security Officer (ISSO)

Independent Software, Inc. • Maryland

On-site
USD 100,000 - 130,000
ISSO
ISSO

Occam Solutions, Inc. • Arlington (VA)

On-site
USD 85,000 - 125,000
Information Systems Security / Information System Security Officer (ISSO)
Information Systems Security / Information System Security Officer (ISSO)

Astrion • Columbia (MD)

On-site
USD 110,000 - 140,000
Information System Security Officer (ISSO)
Information System Security Officer (ISSO)

JAAW™ Group • Hill Air Force Base (UT)

On-site
USD 90,000 - 130,000
Information System Security Officer (ISSO) / System Administrator
Information System Security Officer (ISSO) / System Administrator

Sanmina-SCI Systems de México • Huntsville (AL)

On-site
USD 90,000 - 150,000
ME00679-ISSO 1
ME00679-ISSO 1

Rippling, Inc. • Annapolis (MD)

On-site
USD 120,000 - 180,000
11 paid holidays
PTO (minimum 3 weeks)
Company sponsored group medical plan
+4
Senior Information System Security Officers (ISSO)
Senior Information System Security Officers (ISSO)

Gsc Llc • Maryland

On-site
USD 80,000 - 110,000
Competitive salary and benefits package
Flexible work arrangements
Professional development opportunities
Information Systems Security Officer (ISSO)
Information Systems Security Officer (ISSO)

Intellect Solutions LLC • Acer Lane (MD)

On-site
USD 90,000 - 120,000