Information System Security Officer (ISSO) Job Category: Information Technology Requisition Number ... Experience with eMASS or equivalent RMF workflow tools, vulnerability scanners, SIEM/Auditing and ...
Information System Security Officer (ISSO) Job Category: Information Technology Requisition Number ... Experience with eMASS or equivalent RMF workflow tools, vulnerability scanners, SIEM/Auditing and ...
Information System Security Officer (ISSO) Job Category: Information Technology Requisition Number ... Experience with eMASS or equivalent RMF workflow tools, vulnerability scanners, SIEM/Auditing and ...
Information System Security Officer (ISSO) Job Category: Information Technology Requisition Number ... Experience with eMASS or equivalent RMF workflow tools, vulnerability scanners, SIEM/Auditing and ...
... auditing) using SIEM tools or the native audit reduction capability of the operating system ... Experience as an ISSO supporting classified systems under the JSIG, ICD 503, and/or 32 CFR Part 117 ...
... auditing) using SIEM tools or the native audit reduction capability of the operating system ... Experience as an ISSO supporting classified systems under the JSIG, ICD 503, and/or 32 CFR Part 117 ...
The ISSO serves as a hands-on security practitioner responsible for the day-to-day security posture ... Experience with eMASS or equivalent RMF workflow tools, vulnerability scanners, SIEM/Auditing and ...
The ISSO serves as a hands-on security practitioner responsible for the day-to-day security posture ... Experience with eMASS or equivalent RMF workflow tools, vulnerability scanners, SIEM/Auditing and ...
Senior Information Systems Security Officer (ISSO) Location: Huntsville, AL Employment Type: Direct ... auditing, and cybersecurity operations Knowledge of DISA STIGs, NIST standards, and federal ...
Senior Information Systems Security Officer (ISSO) Location: Huntsville, AL Employment Type: Direct ... auditing, and cybersecurity operations Knowledge of DISA STIGs, NIST standards, and federal ...
The ISSO serves as a hands-on security practitioner responsible for the day-to-day security posture ... Experience with eMASS or equivalent RMF workflow tools, vulnerability scanners, SIEM/Auditing and ...
The ISSO serves as a hands-on security practitioner responsible for the day-to-day security posture ... Experience with eMASS or equivalent RMF workflow tools, vulnerability scanners, SIEM/Auditing and ...
Cyber Security Analyst/ISSO
Tucson, AZ · On-site
$88K - $110K/yr
Hands-on experience in security auditing, continuous monitoring, and documentation of control ... Cyber Analyst/ISSO 2: $88,000 - $110,000 [minimum 2-year experience] However, Arete considers ...
Cyber Security Analyst/ISSO
Tucson, AZ · On-site
$88K - $110K/yr
Hands-on experience in security auditing, continuous monitoring, and documentation of control ... Cyber Analyst/ISSO 2: $88,000 - $110,000 [minimum 2-year experience] However, Arete considers ...
The ISSO will provide rigorous, specialized validation of cybersecurity artifacts against NIST 800 ... Work closely with the CSSP Auditor in maintain highly organized, audit-ready repositories of ...
The ISSO will provide rigorous, specialized validation of cybersecurity artifacts against NIST 800 ... Work closely with the CSSP Auditor in maintain highly organized, audit-ready repositories of ...
Cyber Security Analyst/ISSO
Northridge, CA · On-site
$80K - $110K/yr
Hands-on experience in security auditing, continuous monitoring, and documentation of control ... Cyber Analyst/ISSO 2: $88,000 - $110,000 [minimum 2-year experience] However, Arete considers ...
Quick apply
Cyber Security Analyst/ISSO
Northridge, CA · On-site
$80K - $110K/yr
Hands-on experience in security auditing, continuous monitoring, and documentation of control ... Cyber Analyst/ISSO 2: $88,000 - $110,000 [minimum 2-year experience] However, Arete considers ...
Cyber Security Analyst/ISSO
Tucson, AZ · On-site
$80K - $110K/yr
Hands-on experience in security auditing, continuous monitoring, and documentation of control ... Cyber Analyst/ISSO 2: $88,000 - $110,000 [minimum 2-year experience] However, Arete considers ...
Quick apply
Cyber Security Analyst/ISSO
Tucson, AZ · On-site
$80K - $110K/yr
Hands-on experience in security auditing, continuous monitoring, and documentation of control ... Cyber Analyst/ISSO 2: $88,000 - $110,000 [minimum 2-year experience] However, Arete considers ...
Specialist, Cyber Intelligence (ISSO)
Colorado Springs, CO · On-site
$80K - $149K/yr
Specialist, Cyber Intelligence (ISSO) Job Code: 42800 Job Location: Colorado Springs, CO Job ... Experience auditing information system and user activity using SIEM tools like Splunk, and/or Log ...
Specialist, Cyber Intelligence (ISSO)
Colorado Springs, CO · On-site
$80K - $149K/yr
Specialist, Cyber Intelligence (ISSO) Job Code: 42800 Job Location: Colorado Springs, CO Job ... Experience auditing information system and user activity using SIEM tools like Splunk, and/or Log ...
The ISSO serves as the primary cybersecurity and information assurance lead, ensuring systems ... Serve as the primary cybersecurity liaison for government customers and external auditors.
The ISSO serves as the primary cybersecurity and information assurance lead, ensuring systems ... Serve as the primary cybersecurity liaison for government customers and external auditors.
Description ISSO / RMF Cybersecurity Analyst Xcelerate Solutions seeks an Information System ... Ensure log management, system auditing, and boundary protections are maintained in compliance with ...
Description ISSO / RMF Cybersecurity Analyst Xcelerate Solutions seeks an Information System ... Ensure log management, system auditing, and boundary protections are maintained in compliance with ...
Certifications, such as Network+ and Security +, CISSP and Security auditing are recommended. A senior ISSO role will highlight past experiences over a 5-to-10-year period. Qualifications Previous ...
Certifications, such as Network+ and Security +, CISSP and Security auditing are recommended. A senior ISSO role will highlight past experiences over a 5-to-10-year period. Qualifications Previous ...
The ISSO serves as the primary cybersecurity and information assurance lead, ensuring systems ... Serve as the primary cybersecurity liaison for government customers and external auditors.
The ISSO serves as the primary cybersecurity and information assurance lead, ensuring systems ... Serve as the primary cybersecurity liaison for government customers and external auditors.
Specialist, Cyber Intelligence (ISSO)
Colorado Springs, CO · On-site
$80K - $149K/yr
Specialist, Cyber Intelligence (ISSO) Job Code: 42800 Job Location: Colorado Springs, CO Job ... Experience auditing information system and user activity using SIEM tools like Splunk, and/or Log ...
Specialist, Cyber Intelligence (ISSO)
Colorado Springs, CO · On-site
$80K - $149K/yr
Specialist, Cyber Intelligence (ISSO) Job Code: 42800 Job Location: Colorado Springs, CO Job ... Experience auditing information system and user activity using SIEM tools like Splunk, and/or Log ...
The ISSO serves as the primary cybersecurity and information assurance lead, ensuring systems ... Serve as the primary cybersecurity liaison for government customers and external auditors.Monitor ...
Quick apply
The ISSO serves as the primary cybersecurity and information assurance lead, ensuring systems ... Serve as the primary cybersecurity liaison for government customers and external auditors.Monitor ...
ISSO II
Arlington, VA · On-site
ISSO II Work Location: Hybrid; Arlington, VA. Clearance Required: DHS Public Trust EOD, Alpha Omega ... Certified Information Systems Auditor (CISA) * Certified Ethical Hacker (CEH) * Certified ...
ISSO II
Arlington, VA · On-site
ISSO II Work Location: Hybrid; Arlington, VA. Clearance Required: DHS Public Trust EOD, Alpha Omega ... Certified Information Systems Auditor (CISA) * Certified Ethical Hacker (CEH) * Certified ...
The ISSO is accountable for the accuracy, completeness, and audit readiness of security artifacts ... Engage with government stakeholders, assessors, and auditors during reviews and evaluations.
The ISSO is accountable for the accuracy, completeness, and audit readiness of security artifacts ... Engage with government stakeholders, assessors, and auditors during reviews and evaluations.
ISSO II
Arlington, VA · Hybrid
ISSO II Work Location: Hybrid; Arlington, VA. Clearance Required: DHS Public Trust EOD, US Citizen ... Certified Information Systems Auditor (CISA) * Certified Ethical Hacker (CEH) * Certified ...
ISSO II
Arlington, VA · Hybrid
ISSO II Work Location: Hybrid; Arlington, VA. Clearance Required: DHS Public Trust EOD, US Citizen ... Certified Information Systems Auditor (CISA) * Certified Ethical Hacker (CEH) * Certified ...
Isso Auditor information
See salary details
$41.5K - $49.1K
7% of jobs
$49.1K - $56.7K
13% of jobs
$58.8K is the 25th percentile. Wages below this are outliers.
$56.7K - $64.3K
18% of jobs
The median wage is $71.5K / yr.
$64.3K - $71.9K
13% of jobs
$71.9K - $79.5K
12% of jobs
$79.5K - $87K
13% of jobs
$87.3K is the 75th percentile. Wages above this are outliers.
$87K - $94.6K
9% of jobs
$94.6K - $102.2K
3% of jobs
$102.2K - $109.8K
5% of jobs
$109.8K - $117.4K
6% of jobs
$117.4K - $125K
1% of jobs
$41.5K
$78.2K
$125K
How much do isso auditor jobs pay per year?
What cities are hiring for Isso Auditor jobs?
Cities with the most Isso Auditor job openings:
What states have the most Isso Auditor jobs?
States with the most job openings for Isso Auditor jobs include:
What are popular job titles related to Isso Auditor jobs?
For Isso Auditor jobs, the most frequently searched job titles are:

Information System Security Officer (ISSO)
Albuquerque, NM • On-site
Other
Posted 19 days ago
Job description
Job Category: Information Technology
Requisition Number: INFOR010052
- Posted : August 21, 2026
- Full-Time
- On-site
Showing 1 location
Applied Research Associates, Inc. (ARA), Southwest Division (SWD) is looking for an experienced Information System Security Officer (ISSO) to join our security team located in Albuquerque, New Mexico. The Information System Security Officer (ISSO) supports the ISSM in the management, operation, and compliance of classified information systems (IS) operating under the National Industrial Security Program (NISP). This role is governed by the requirements of 32 CFR Part 117 (NISPOM Rule) and the DCSA Assessment and Authorization Guide (DAAG), which implements the Risk Management Framework (RMF) for cleared contractor facilities. The ISSO serves as a hands‑on security practitioner responsible for the day‑to‑day security posture of assigned systems, ensuring continuous compliance with DCSA authorization requirements and maintaining a valid Authority to Operate (ATO).
Essential Functions as an ISSO
- Possessing sufficient experience and technical competence commensurate with the complexity of the systems to include patch management, account management, STIGs/SCAPs, application updates and installs, hardware configuration and troubleshooting
- Ensure all hardware and software additions, removals, and modifications follow approved change management processes
- Maintain configuration management documentation for all hardware and software changes to classified systems
- Implement and validate security controls on classified systems per NIST SP 800-53, CNSSI 1253, and applicable STIGs.
- Ensuring user activity monitoring data and audit records are analyzed, stored, and protected in accordance with the ITPSO policies and procedures and System Security Plan (SSP)
- Review system audit record findings related to inappropriate or unusual activity and elevate findings to the ISSM
- Report all security‑related incidents to the ISSM in accordance with 32 CFR Part 117 requirements
- Assess changes to assigned systems that could affect authorization status and notify the ISSM
- Assist and support the ISSM in all the following tasks:
- Executing all phases of the RMF lifecycle: Prepare, Categorize, Select, Implement, Assess, Authorize, and Monitor to include decommission
- Development, maintenance, and continuous updating of Information Systems
- Populate and maintain system records, artifacts, and security documentation in eMASS throughout the RMF lifecycle
- Preparation and submission of authorization packages through the Package Approval Chain (PAC) workflow
- Conducting periodic assessments and continuous monitoring of authorized systems and providing the corrective actions for all identified findings and vulnerabilities
- Development and tracking of Plans of Action and Milestones (POA&Ms) for identified vulnerabilities
Experience and Skills Required
- Minimum 2‑4 years of experience in information technology, with at least 2 years in an ISSO or equivalent role supporting classified information systems
- Demonstrated working knowledge of 32 CFR Part 117 §117.18, the DCSA Assessment and Authorization Guide (DAAG), and NIST 800‑series publications
- Experience managing the RMF lifecycle for classified information systems under DCSA cognizance
- Active (or ability to obtain) Top Secret clearance with SCI eligibility or clearance commensurate with the highest classification level processed on facility systems
- Strong technical knowledge of Windows and/or Linux security hardening, STIG application, network security fundamentals, and audit log management
- Experience with classified system configuration management, media control, and sanitization/destruction procedures
Core Competencies
- Technical understanding of classified system security controls, network architecture, and risk management
- Knowledge of NISPOM and related CFRs, DAAG, NIST SPs, CNSSI directive
- Analytical thinking, technical writing, and the ability to produce clear security documentation (SSPs, POA&Ms, incident reports)
- Effective collaboration with the ISSM, FSO, ITPSO, IT staff, and program managers
- Discretion and integrity in handling classified information and sensitive cybersecurity data
- Commitment to continuous professional development and staying current with evolving cybersecurity threats and DCSA guidance
Preferred
- Security+
- Prior industry ISSO or cybersecurity assessor experience (DCSA, NSA, or IC)
- Knowledge of cross‑domain solutions, classified cloud environments (IL4/IL5), and network interconnection security
- Experience with eMASS or equivalent RMF workflow tools, vulnerability scanners, SIEM/Auditing and STIG Viewer / SCAP compliance tool
Works well as a member of a group
Functional ExpertConsidered a thought leader on a subject
Detail OrientedCapable of carrying out a given task with all details necessary to get the task done well
DedicatedDevoted to a task or purpose with loyalty or integrity
Self‑StarterInspired to perform without outside help
Goal CompletionInspired to perform well by the completion of tasks
Ability to Make an ImpactInspired to perform well by the ability to contribute to the success of a project or the organization
EducationBachelors or better in Cybersecurity or related field.
Experience2-4 years:
Equal Opportunity Employer/Protected Veterans/Individuals with Disabilities
This employer is required to notify all applicants of their rights pursuant to federal employment laws.For further information, please review the Know Your Rights notice from the Department of Labor.