1

Isso Issm Jobs in Springfield, VA (NOW HIRING)

Information Systems Security Manager (ISSM)

Washington, DC ยท On-site

$165K - $190K/yr

  • Medical

  • Dental

  • Vision

  • Life

  • Retirement

  • PTO

During the facility standup phase, the ISSM will carry direct ISSO responsibilities for initial systems prior to additional security team staffing, these responsibilities will diminish as the ...

Director of Information Assurance

Reston, VA ยท On-site

$176 - $282/hr

This role leads a distributed team of direct-report managers plus their ISSM/ISSO staff supporting programsacross the Department of Defense and the Intelligence Community. The role sits withinPeraton ...

Director of Information Assurance

Reston, VA ยท On-site

$176K - $282K/yr

This role leads a distributed team of direct-report managers plus their ISSM/ISSO staff supporting programs across the Department of Defense and the Intelligence Community. The role sits within ...

This role leads a distributed team of direct-report managers plus their ISSM/ISSO staff supporting programs across the Department of Defense and the Intelligence Community. The role sits within ...

Showing results 41-60

Isso Issm information

See Springfield, VA salary details

$48K

$123.6K

$192.7K

How much do isso issm jobs pay per year?

As of Aug 17, 2026, the average yearly pay for isso issm in Springfield, VA is $123,595.00, according to ZipRecruiter salary data. Most workers in this role earn between $99,200.00 and $144,100.00 per year, depending on experience, location, and employer.

What are the main challenges faced by an ISSO or ISSM when working with cross-functional teams?

ISSO/ISSMs often collaborate with IT, compliance, and business units to ensure security policies align with organizational goals. A common challenge is bridging the communication gap between technical and non-technical stakeholders to ensure security requirements are understood and implemented effectively. Additionally, balancing strict security controls with operational needs requires negotiation and adaptability. Building strong relationships and maintaining clear documentation are key to overcoming these challenges and ensuring a secure and compliant environment.

What are the key skills and qualifications needed to thrive as an ISSO or ISSM?

To thrive as an ISSO/ISSM, you need a solid understanding of cybersecurity principles, risk management frameworks (such as NIST RMF), and compliance requirements, usually supported by a degree in information security or a related field. Familiarity with security tools like SIEM systems, vulnerability scanners, and certifications such as CISSP or Security+ are typically required. Strong analytical thinking, attention to detail, and the ability to communicate complex security concepts to diverse audiences are essential soft skills. These skills ensure the effective protection of organizational assets, compliance with regulations, and the ability to respond proactively to evolving security threats.

What is the difference between Isso Issm vs Project Manager?

AspectIsso IssmProject Manager
CertificationsTypically requires ISSM certification, security clearancesOften requires PMP or CAPM certifications
Work EnvironmentPrimarily in cybersecurity, information systems securityIn various industries managing projects across departments
Industry UsageCommon in defense, government, IT security sectorsWidely used across construction, IT, healthcare, and more

While both roles involve managing technical aspects, Isso Issm focuses on information security management within cybersecurity environments, often requiring specific security certifications. Project Managers oversee a broad range of projects across industries, emphasizing planning, execution, and delivery. Understanding these differences helps clarify career paths and employer expectations in respective fields.

What is an Information Systems Security Officer (ISSO)?

Information System Security Officers (ISSOs) and Information System Security Managers (ISSMs) are cybersecurity professionals responsible for the protection and oversight of information systems within an organization, particularly in compliance-driven environments like government or defense. ISSOs focus on the day-to-day security operations, monitoring, and implementation of security controls, while ISSMs are typically responsible for the overall security program management and ensuring compliance with relevant regulations and policies. Both roles are crucial for maintaining the confidentiality, integrity, and availability of sensitive data.

What are popular job titles related to Isso Issm jobs in Springfield, VA?

For Isso Issm jobs in Springfield, VA, the most frequently searched job titles are:

What job categories do people searching Isso Issm jobs in Springfield, VA look for?

The top searched job categories for Isso Issm jobs in Springfield, VA are:

What cities near Springfield, VA are hiring for Isso Issm jobs?

Cities near Springfield, VA with the most Isso Issm job openings:

Infographic showing various Isso Issm job openings in Springfield, VA as of June 2026, with employment types broken down into 89% Full Time, 7% Part Time, and 4% Contract. Highlights an 96% Physical, 2% Hybrid, and 2% Remote job distribution, with an average salary of $123,595 per year, or $59.4 per hour.

ISSO with Security Clearance

STEM Solutions & Consultants LLC

Lorton, VA โ€ข On-site

Other

Re-posted 23 days ago


Job description

Information Systems Security Officer (ISSO) Our partner is seeking an experience Information System Security Officer (ISSO) to support cybersecurity, compliance and risk management activities for Department of Defense (DoD) information systems operating in classified and controlled environments. This position plays a critical role in maintaining security compliance, support authorization efforts and ensuring operational systems meet Joint Special Access Program (SAP) Implementation Guide (JSIG), Risk Management Frameworks (RMF) and applicable DoD and Intelligence Community cybersecurity requirements. The ISSO will work closely with the Information System Security Manager (ISSM), system administrators, engineers, program managers and government stakeholders to support Authorization Operate (ATO) activities, continuous monitoring, vulnerability management, and overall cybersecurity compliance efforts. Key Responsibilities: Information Assurance & ISSM Support * Support the ISSM in executing cybersecurity responsibilities and serve as acting ISSM when required. * Ensure systems are operated, maintained and disposed of in accordance with approved security policies and authorization requirements. * Verify users possess appropriate security clearance, authorizations, and need-to-know prior to system access. * Conduct periodic security reviews and compliance assessments to validate continued adherence to approved security baselines. * Participate in Configuration Control Board (CCB) activities and evaluate proposed system changes for security impact. * Coordinate hardware, software, and firmware modifications with security stakeholders prior to implementation. * Notify appropriate authorities of system changes that may impact authorization status. * Monitor system recovery efforts to ensure security controls are restored and functioning properly. * Participate in Agile planning sessions and provide cybersecurity input on development and infrastructure activities. Risk Management Framework (RMF) & Compliance * Support the implementation and maintenance of cybersecurity controls in accordance with JSIG, RMF, NIST SP 800-53, and DoD cybersecurity requirements. * Develop, update and maintain RMF documentation, including: * System Security Plans (SSPs) * Security Control Traceability Matrices (SCTMs) * Plans of Action & Milestones (POA&Ms) * Security Assessment Reports (SARs) * Continuous Monitoring Plans * Assist with system authorization activities throughout the RMF lifecycle. * Ensure security controls are implemented, documented, and maintained according to approved baselines. * Support security assessments, audits, inspections and authorization reviews. Continuous Monitoring & Vulnerability Management * Perform continuous monitoring activities to maintain Authorization to Operate (ATO) status. * Review and analyze vulnerability scan results from ACAS, Tenable, and similar tools. * Track vulnerability remediation efforts and validate closure of findings. * Support risk assessments and recommend mitigation strategies. * Monitor system changes and assess potential cybersecurity impacts. * Assist with configuration management activities to ensure compliance with approved baselines. Security Operations * Support cybersecurity incident response activities and document security incidents. * Ensure audit logs and security records are collected, reviewed, retained, and analyzed according to policy requirements. * Validate implementation of STIGs, system hardening standards, and secure configuration requirements. * Work with system administrators and engineers to maintain secure system configurations. * Support enforcement of least privilege, separation of duties, and access control requirements. * Provide cybersecurity guidance and support to system users and administrators. Documentation & Reporting * Maintain accurate cybersecurity documentation, records and compliance artifacts. * Prepare reports, status updates, and briefings for program leadership, government representatives, and security stakeholders. * Maintain evidence required for audits, inspections, and authorization activities. * Support internal and external cybersecurity reviews and assessments. Required Qualifications: * Bachelor's degree in Cybersecurity, Information Technology, Computer Science, Information Systems, or a related discipline (or equivalent combination of education and experience). * Mininum of 5 years of experience in cybersecurity, information assurance, information systems security, or related fields. * Experience supporting DoD Risk Management Framework (RMF) processes and cybersecurity compliance initiatives. * Working knowledge of: * Joint SAP Implementation Guide (JSIG) * NIST SP 800-53 Security Controls * DoD RMF Process * Security Technical Implementation Guides (STIGs) * Vulnerability Management Programs * Active TS/SCI security clearance. * Current DoD 8570/8140 compliant certification such as CISSP, CISM, CASP+, or CISA. * Strong analytical, troubleshooting and problem-solving skills. * Excellent written and verbal communications skills. * Ability to work independently and collaboratively in a fast-paced, mission-focused environment. * Strong attention to detail and documentation accuracy. Preferred Qualifications: * Experience supporting SAP, SCI or other classified environments. * Experience securing Windows, Linux and virtualized environments. * Familiarity with Cross Domain Solutions (CDS). * Experience with cybersecurity tools including: * ACAS * Splunk * Tenable * Trellix ePO * Similar enterprise security platforms * Knowledge of cloud security requirements within DoD environments. * Experience supporting security assessments and authorization package development. * Stroing understanding of cybersecurity risk management and compliance frameworks. Additional Requirements: * Must reside within driving distance of Lorton, Virginia or be willing to relocate (relocation assistance available). * Must be able to work onsite. * Must be willing to support occasional after-hours activities, incident response efforts and on-call responsibilities. * Must be willing and able to travel frequently. * Active TS/SCI Clearance is required and must be maintained throughout employment.