1

Information System Security Officer Isso Jobs (NOW HIRING)

Information System Security Officer (ISSO) - Cybersecurity & Technology Operations Clearance Requirement: Active Top Secret security clearance (with eligibility for SAP access); must be able to ...

Showing results 21-40

Information System Security Officer Isso information

See salary details

$46K

$118.3K

$184.5K

How much do information system security officer isso jobs pay per year?

As of Sep 14, 2026, the average yearly pay for information system security officer isso in the United States is $118,327.00, according to ZipRecruiter salary data. Most workers in this role earn between $95,000.00 and $138,000.00 per year, depending on experience, location, and employer.

What is an information system security officer ISSO?

An Information System Security Officer (ISSO) is responsible for ensuring the security and compliance of an organization's information systems. They develop, implement, and enforce security policies, conduct risk assessments, and ensure adherence to regulatory requirements. ISSOs also monitor security controls, respond to incidents, and collaborate with IT and management to maintain system integrity. Their role is critical in protecting sensitive data and preventing cyber threats.

What are the main challenges an information system security officer ISSO might face in their role?

One of the main challenges for an ISSO is staying ahead of constantly evolving cyber threats while ensuring compliance with complex and sometimes changing regulatory requirements. ISSOs often juggle competing priorities, such as responding to security incidents, conducting risk assessments, and ensuring policies are up to date. Frequent collaboration across different departments is needed to align security controls with business operations. Successfully managing these challenges requires continuous learning, adaptability, and clear communication with both technical and non-technical stakeholders.

What are the key skills and qualifications needed to thrive as an information system security officer ISSO, and why are they important?

To thrive as an Information System Security Officer (ISSO), you need a robust understanding of cybersecurity principles, risk management frameworks, and regulatory compliance, often backed by a degree in information technology or a related field. Familiarity with tools such as SIEM platforms, vulnerability scanners, and certifications like CISSP, CISM, or Security+ is highly valued. Strong attention to detail, problem-solving abilities, and effective communication skills are vital soft skills for this role. These competencies are crucial for ensuring organizations adequately protect sensitive data and comply with industry and government security standards.

More about Information System Security Officer Isso jobs

What cities are hiring for Information System Security Officer Isso jobs?

Cities with the most Information System Security Officer Isso job openings:

What states have the most Information System Security Officer Isso jobs?

States with the most job openings for Information System Security Officer Isso jobs include:

What are popular job titles related to Information System Security Officer Isso jobs?

For Information System Security Officer Isso jobs, the most frequently searched job titles are:

Infographic showing various Information System Security Officer Isso job openings in the United States as of September 2026, with employment types broken down into 1% As Needed, 76% Full Time, 20% Part Time, and 3% Contract. Highlights an 91% Physical, 2% Hybrid, and 7% Remote job distribution, with an average salary of $118,327 per year, or $56.9 per hour.

Information System Security Officer (ISSO)

Albuquerque, NM โ€ข On-site

Full-time

Posted 24 days ago


Job description

Applied Research Associates, Inc. (ARA), Southwest Division (SWD) is looking for an experienced Information System Security Officer (ISSO) to join our security team located in Albuquerque, New Mexico. The Information System Security Officer (ISSO) supports the ISSM in the management, operation, and compliance of classified information systems (IS) operating under the National Industrial Security Program (NISP). This role is governed by the requirements of 32 CFR Part 117 (NISPOM Rule) and the DCSA Assessment and Authorization Guide (DAAG), which implements the Risk Management Framework (RMF) for cleared contractor facilities. The ISSO serves as a hands-on security practitioner responsible for the day-to-day security posture of assigned systems, ensuring continuous compliance with DCSA authorization requirements and maintaining a valid Authority to Operate (ATO).
Essential Functions as an ISSO
  • Possessing sufficient experience and technical competence commensurate with the complexity of the systems to include patch management, account management, STIGs/SCAPs, application updates and installs, hardware configuration and troubleshooting
  • Ensure all hardware and software additions, removals, and modifications follow approved change management processes
  • Maintain configuration management documentation for all hardware and software changes to classified systems
  • Implement and validate security controls on classified systems per NIST SP 800-53, CNSSI 1253, and applicable STIGs.
  • Ensuring user activity monitoring data and audit records are analyzed, stored, and protected in accordance with the ITPSO policies and procedures and System Security Plan (SSP)
  • Review system audit record findings related to inappropriate or unusual activity and escalate findings to the ISSM
  • Report all security-related incidents to the ISSM in accordance with 32 CFR Part 117 requirements
  • Assess changes to assigned systems that could affect authorization status and notify the ISSM
  • Assist and support the ISSM in all the following tasks:
  • Executing all phases of the RMF lifecycle: Prepare, Categorize, Select, Implement, Assess, Authorize, and Monitor to include decommission
  • Development, maintenance, and continuous updating of Information Systems
  • Populate and maintain system records, artifacts, and security documentation in eMASS throughout the RMF lifecycle
  • Preparation and submission of authorization packages through the Package Approval Chain (PAC) workflow
  • Conducting periodic assessments and continuous monitoring of authorized systems and providing the corrective actions for all identified findings and vulnerabilities
  • Development and tracking of Plans of Action and Milestones (POA&Ms) for identified vulnerabilities

Experience and Skills Required
  • Minimum 2-4 years of experience in information technology, with at least 2 years in an ISSO or equivalent role supporting classified information systems
  • Demonstrated working knowledge of 32 CFR Part 117 ยง117.18, the DCSA Assessment and Authorization Guide (DAAG), and NIST 800-series publications
  • Experience managing the RMF lifecycle for classified information systems under DCSA cognizance
  • Active (or ability to obtain) Top Secret clearance with SCI eligibility or clearance commensurate with the highest classification level processed on facility systems
  • Strong technical knowledge of Windows and/or Linux security hardening, STIG application, network security fundamentals, and audit log management
  • Experience with classified system configuration management, media control, and sanitization/destruction procedures

Core Competencies
  • Technical understanding of classified system security controls, network architecture, and risk management
  • Knowledge of NISPOM and related CFRs, DAAG, NIST SPs, CNSSI directive
  • Analytical thinking, technical writing, and the ability to produce clear security documentation (SSPs, POA&Ms, incident reports)
  • Effective collaboration with the ISSM, FSO, ITPSO, IT staff, and program managers
  • Discretion and integrity in handling classified information and sensitive cybersecurity data
  • Commitment to continuous professional development and staying current with evolving cybersecurity threats and DCSA guidance

Preferred
  • Security+
  • Prior industry ISSO or cybersecurity assessor experience (DCSA, NSA, or IC)
  • Knowledge of cross-domain solutions, classified cloud environments (IL4/IL5), and network interconnection security
  • Experience with eMASS or equivalent RMF workflow tools, vulnerability scanners, SIEM/Auditing and STIG Viewer / SCAP compliance tool

Equal Opportunity Employer/Protected Veterans/Individuals with Disabilities
This employer is required to notify all applicants of their rights pursuant to federal employment laws.
For further information, please review the Know Your Rights notice from the Department of Labor.