ISSO (Information System Security Officer)

Nationwide IT Services, Inc.

Cambridge (MA)

On-site

USD 100,000 - 130,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Nationwide IT Services, Inc. is seeking an experienced Information System Security Officer (ISSO) based in Cambridge, MA. This role supports the U.S. Department of Transportation at the Volpe Center, ensuring compliance with cybersecurity requirements and managing operational security.

The ideal candidate will have over 5 years of federal information security experience and a Bachelor's degree in a relevant field. Key responsibilities include developing security documentation and managing security assessments.

Qualifications

  • 5+ years of experience in information security supporting federal information systems.
  • Understanding of NIST SP 800-53 security controls and compliance requirements.
  • Experience as ISSO or similar security role.

Responsibilities

  • Maintain operational security posture for assigned systems.
  • Develop and maintain security documentation including SSPs.
  • Manage security operations and user access controls.

Skills

Experience in information security
Communication skills
NIST Risk Management Framework knowledge
Experience with GRC tools

Education

Bachelor's degree in Cybersecurity or related field

Tools

Xacta
AWS
Azure

Job description

ISSO (Information System Security Officer)

Location: Cambridge, MA (Volpe Center) 100% on site

Customer: U.S. Department of Transportation (DOT) – John A. Volpe National Transportation Systems Center

Clearance Requirements: Active Top Secret/SCI Eligible

Position Overview

Nationwide IT Services is seeking an experienced Information System Security Officer (ISSO) to support the U.S. Department of Transportation (DOT), John A. Volpe National Transportation Systems Center (Volpe Center). The ISSO will be responsible for maintaining the operational security posture of assigned information systems, supporting Risk Management Framework (RMF) activities, ensuring compliance with federal cybersecurity requirements, and coordinating with program managers, system owners, and cybersecurity stakeholders throughout the system lifecycle.

The successful candidate will serve as the primary security representative for assigned systems and will ensure that security controls, continuous monitoring activities, documentation, and authorization artifacts remain current and compliant with federal and DOT cybersecurity requirements.

Key Responsibilities
  • Maintain the appropriate operational security posture for assigned information systems and programs.
  • Develop, update, and maintain system security documentation, including System Security Plans (SSPs), security authorization packages, and associated artifacts.
  • Ensure systems are operated, maintained, and disposed of in accordance with approved security authorization documentation.
  • Manage day-to-day security operations for assigned systems.
  • Monitor information systems and environments of operation, assessing the impact of system changes and modifications.
  • Coordinate and document security-related system changes, including patches, upgrades, and configuration updates.
  • Maintain comprehensive records of system and network changes.
  • Manage user accounts and access controls in accordance with organizational policies and cybersecurity guidance.
  • Perform Security Impact Analyses (SIAs) and support change management activities.
  • Support RMF continuous monitoring activities and validate control assessment results.
  • Track and remediate security findings, vulnerabilities, and Plan of Action & Milestones (POA&M) items.
  • Ensure security deficiencies identified during assessments are mitigated, corrected, or formally accepted through the appropriate risk acceptance process.
  • Coordinate with Information System Security Managers (ISSMs), System Owners, Program Managers, Security Control Assessors (SCAs), and Authorizing Officials (AOs).
  • Support authorization activities including ATO packages, annual reviews, and continuous authorization efforts.
  • Participate in post-production reviews and document baseline deviations as required.
  • Maintain ISSO appointment documentation and ensure compliance with governance requirements.
Required Qualifications
  • Bachelor's degree in Cybersecurity, Information Technology, Computer Science, Information Systems, or related field.
  • 5+ years of information security experience supporting federal information systems.
  • Experience serving as an ISSO, Information Assurance Analyst, Cybersecurity Analyst, or similar security role.
  • Strong understanding of the NIST Risk Management Framework (RMF).
  • Experience with NIST SP 800-53 security controls and federal cybersecurity compliance requirements.
  • Experience supporting Authority to Operate (ATO) processes and continuous monitoring programs.
  • Knowledge of vulnerability management, configuration management, and change control processes.
  • Experience working with system owners, program managers, and technical teams in a federal environment.
  • Excellent written and verbal communication skills.
Preferred Qualifications
  • Experience supporting U.S. Department of Transportation (DOT) programs.
  • Experience with Xacta or similar Governance, Risk, and Compliance (GRC) tools.
  • Knowledge of FISMA, FedRAMP, and DHS cybersecurity guidance.
  • Security+ CE, CISSP, CAP, CISM, or equivalent cybersecurity certification.
  • Experience supporting cloud-based environments (AWS, Azure, or GovCloud).
About the Customer

The John A. Volpe National Transportation Systems Center (Volpe Center) is the U.S. Department of Transportation's premier federal research and transportation systems center, providing advanced technical expertise, cybersecurity, engineering, and program support across multiple transportation domains.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Onsite ISSO: Federal RMF & Security Compliance Expert
Onsite ISSO: Federal RMF & Security Compliance Expert

Nationwide IT Services, Inc. • Cambridge (MA)

On-site
USD 100,000 - 130,000
Information System Security Officer (ISSO)
Information System Security Officer (ISSO)

Digital Global Connectors • McLean (VA)

Hybrid
USD 120,000 - 150,000
Information Systems Security Officer (ISSO)
Information Systems Security Officer (ISSO)

Skysoft Inc. • Maryland

Hybrid
USD 120,000 - 170,000
Information System Security Officer
Information System Security Officer

Inadev • Reston (VA)

Hybrid
USD 110,000 - 170,000
Information Systems Security Officer
Information Systems Security Officer

Demand Drive Solutions LLC • Washington

On-site
USD 110,000 - 120,000
Information System Security Officer (ISSO)
Information System Security Officer (ISSO)

Astrion • United States

On-site
USD 90,000 - 120,000
Information Systems Security Officer (ISSO)
Information Systems Security Officer (ISSO)

Modern Technology Solutions, Inc. (MTSI) • Washington

On-site
USD 90,000 - 130,000
Senior Information Systems Security Officer
Senior Information Systems Security Officer

ECS Corporate Services • Washington

On-site
USD 120,000 - 145,000
ISSO Lead
ISSO Lead

Paragon Technology Group, Inc. • Washington

On-site
USD 130,000 - 190,000
Information System Security Officer (ISSO)
Information System Security Officer (ISSO)

Ara • Albuquerque (NM), Northern (KY)

Hybrid
USD 95,000 - 130,000