1

Isso Issm Jobs in Washington (NOW HIRING)

It will be required to work in close coordination with the ISSM and ISO in monitoring the ... Perform ISSO duties in support of in-house and external customers * Conduct continuous monitoring ...

It will be required to work in close coordination with the ISSM and ISO in monitoring the ... Perform ISSO duties in support of in-house and external customers * Conduct security impact ...

Takes operational direction from the DFC ISSM. Serves as the single point of contact to the Contracting Officer's Representative. Core responsibilities. * Direct contractor ISSO activities and ensure ...

Showing results 21-40

Isso Issm information

What are the main challenges faced by an ISSO or ISSM when working with cross-functional teams?

ISSO/ISSMs often collaborate with IT, compliance, and business units to ensure security policies align with organizational goals. A common challenge is bridging the communication gap between technical and non-technical stakeholders to ensure security requirements are understood and implemented effectively. Additionally, balancing strict security controls with operational needs requires negotiation and adaptability. Building strong relationships and maintaining clear documentation are key to overcoming these challenges and ensuring a secure and compliant environment.

What are the key skills and qualifications needed to thrive as an ISSO or ISSM?

To thrive as an ISSO/ISSM, you need a solid understanding of cybersecurity principles, risk management frameworks (such as NIST RMF), and compliance requirements, usually supported by a degree in information security or a related field. Familiarity with security tools like SIEM systems, vulnerability scanners, and certifications such as CISSP or Security+ are typically required. Strong analytical thinking, attention to detail, and the ability to communicate complex security concepts to diverse audiences are essential soft skills. These skills ensure the effective protection of organizational assets, compliance with regulations, and the ability to respond proactively to evolving security threats.

What is the difference between Isso Issm vs Project Manager?

AspectIsso IssmProject Manager
CertificationsTypically requires ISSM certification, security clearancesOften requires PMP or CAPM certifications
Work EnvironmentPrimarily in cybersecurity, information systems securityIn various industries managing projects across departments
Industry UsageCommon in defense, government, IT security sectorsWidely used across construction, IT, healthcare, and more

While both roles involve managing technical aspects, Isso Issm focuses on information security management within cybersecurity environments, often requiring specific security certifications. Project Managers oversee a broad range of projects across industries, emphasizing planning, execution, and delivery. Understanding these differences helps clarify career paths and employer expectations in respective fields.

What is an Information Systems Security Officer (ISSO)?

Information System Security Officers (ISSOs) and Information System Security Managers (ISSMs) are cybersecurity professionals responsible for the protection and oversight of information systems within an organization, particularly in compliance-driven environments like government or defense. ISSOs focus on the day-to-day security operations, monitoring, and implementation of security controls, while ISSMs are typically responsible for the overall security program management and ensuring compliance with relevant regulations and policies. Both roles are crucial for maintaining the confidentiality, integrity, and availability of sensitive data.

What are popular job titles related to Isso Issm jobs in Washington?

For Isso Issm jobs in Washington, the most frequently searched job titles are:

What cities in Washington are hiring for Isso Issm jobs?

Cities in Washington with the most Isso Issm job openings:

Cleared On Site Information Systems Security Officers (ISSO) (5359)

SMX

Washington, DC • On-site

Full-time

Re-posted 27 days ago


Job description

SMX is seeking a highly experienced Information System Security Officer (ISSO) - Sr to support a mission-critical federal program in Washington, DC. This individual will serve as a senior cybersecurity professional and trusted advisor responsible for ensuring the security, compliance, and operational integrity of enterprise information systems supporting critical mission functions. The selected candidate will function as the principal advisor to System Owners (SOs), Business Process Owners, Information System Security Managers (ISSMs), and cybersecurity leadership on all matters involving information system security. This role requires extensive experience implementing and maintaining security controls, supporting Risk Management Framework (RMF) activities, leading authorization efforts, and providing technical guidance across multiple systems and projects. The ISSO - Sr will serve as a technical expert responsible for evaluating security posture, mitigating risk, recommending security improvements, and ensuring compliance with federal cybersecurity requirements. This position is on site in Washington, DC and requires an active TS/SCI clearance.  

Essential Duties & Responsibilities:

  • Serve as the principal security advisor to System Owners (SOs), Business Process Owners, ISSMs, and program leadership on matters related to information system security
  • Lead implementation, maintenance, and continuous improvement of security controls across enterprise systems and applications
  • Direct and coordinate RMF activities including system categorization, control implementation, security assessments, authorization activities, and continuous monitoring
  • Develop, review, and maintain System Security Plans (SSPs), POA&Ms, Security Assessment Plans, security procedures, and related authorization documentation
  • Evaluate system security posture and recommend corrective actions to address risks, vulnerabilities, and compliance deficiencies
  • Lead security reviews and assessments to validate implementation and effectiveness of security controls
  • Coordinate with engineers, system administrators, developers, and government stakeholders to ensure security requirements are integrated throughout the system lifecycle
  • Support Authorization to Operate (ATO) activities and ongoing authorization maintenance efforts
  • Direct vulnerability management activities including identification, remediation tracking, risk assessment, and validation of corrective actions
  • Review and validate access control implementations, privileged account management, hardware inventories, software inventories, and security configurations
  • Develop security reports, dashboards, metrics, and recommendations for government leadership
  • Support audit activities, compliance reviews, inspections, and security assessments conducted by internal and external organizations
  • Provide guidance regarding physical and logical protection of information system assets
  • Evaluate security program effectiveness and recommend improvements to policies, procedures, and operational practices
  • Support incident response, security investigations, and remediation activities as required
  • Lead major security initiatives and provide mentorship and guidance to junior cybersecurity personnel
  • Advise leadership on emerging threats, cybersecurity risks, and security modernization opportunities

Required Skills & Experience

  • Active TS/SCI clearance required
  • Minimum of 8 years of professional experience supporting cybersecurity, information assurance, RMF, or information system security activities
  • Demonstrated experience serving as an ISSO, ISSM support resource, cybersecurity lead, or senior security practitioner within a federal environment
  • Extensive experience supporting Risk Management Framework (RMF) activities and Authorization to Operate (ATO) processes
  • Experience developing and maintaining SSPs, POA&Ms, Security Assessment Plans, authorization artifacts, and related security documentation
  • Strong knowledge of NIST 800-53, NIST 800-37, FISMA, and federal cybersecurity requirements
  • Experience implementing, assessing, and maintaining security controls across enterprise information systems
  • Experience supporting continuous monitoring programs, vulnerability management, and compliance initiatives
  • Experience evaluating system security risks and developing risk-based mitigation strategies
  • Experience supporting audits, assessments, inspections, and compliance reviews
  • Strong understanding of access control management, security documentation, risk assessment, and security operations
  • Strong analytical, troubleshooting, and problem-solving skills
  • Ability to communicate technical security concepts to technical and non-technical audiences
  • Strong written and verbal communication skills
  • Ability to work independently while managing multiple priorities and supporting complex security initiatives

Desired Skills & Experience 

  • Bachelor's degree in Cybersecurity, Information Technology, Computer Science, Information Systems, Engineering, or related field
  • Advanced degree preferred
  • Experience supporting federal government, law enforcement, intelligence community, or national security programs
  • Experience supporting cloud environments and cloud security compliance requirements
  • Experience supporting Governance, Risk, and Compliance (GRC) platforms and security workflow management solutions
  • Familiarity with enterprise cybersecurity tools including:
  • Splunk
  • Tenable Nessus
  • Security Center
  • SIEM Platforms
  • Vulnerability Management Tools
  • Endpoint Detection and Response (EDR) Solutions
  • Experience supporting Zero Trust initiatives and cybersecurity modernization efforts
  • Familiarity with Agile delivery methodologies and DevSecOps practices
  • One or more of the following certifications preferred:
    • CISSP
    • CAP (Certified Authorization Professional)
    • CISM
    • CASP+
    • CCSP
    • Security+
    • GSEC
    • Other relevant cybersecurity certifications
  • Experience supervising, mentoring, or leading cybersecurity teams preferred

Application Deadline:  9-4-2026

# LI-SA1