2

Remote Isso Jobs in Reston, VA (NOW HIRING)

ORA_REMOTE Description SAIC is seeking an Information System Security Officer (ISSO) for our team to support a government customer. This position is remote, but the candidate must be local to the DC ...

Information Systems Security Officer

Mclean, VA ยท On-site +1

$70K - $115K/yr

Overview Steampunk wants you to be an Information System Security Officer (ISSO) on our team to support a government customer. In this challenging and rewarding role you'll be asked take initiative ...

Information Systems Security Officer

Mclean, VA ยท On-site +1

$70K - $115K/yr

Overview Steampunk wants you to be an Information System Security Officer (ISSO) on our team to support a government customer. In this challenging and rewarding role you'll be asked take initiative ...

ORA_REMOTE Description SAIC is seeking an Information System Security Officer (ISSO) for our team to support a government customer. This position is remote, but the candidate must be local to the DC ...

Oversee ISSO SA&A activities to ensure information agency systems become and remain accredited per required schedules (e.g., ATT/ATO); validate that JCAM entries are current and complete * Advise ...

next page

Showing results 1-20

Remote Isso information

See Reston, VA salary details

$47.9K

$123.1K

$191.9K

How much do remote isso jobs pay per year?

As of Jun 21, 2026, the average yearly pay for remote isso in Reston, VA is $123,102.00, according to ZipRecruiter salary data. Most workers in this role earn between $98,800.00 and $143,600.00 per year, depending on experience, location, and employer.

What are the key skills and qualifications needed to thrive in the Remote Isso position, and why are they important?

To thrive as a Remote ISSO (Information Systems Security Officer), candidates need a robust understanding of information security principles, risk management frameworks (such as NIST), and compliance requirements, often backed by a degree in cybersecurity or a related field. Familiarity with security tools like vulnerability scanners, SIEM platforms, and certifications such as CISSP or CISM are highly valued. Excellent written communication, analytical thinking, and the ability to work independently are crucial soft skills in this remote context. These attributes enable effective oversight of organizational security, ensure compliance, and facilitate collaboration while working off-site.

What is a Remote ISSO job?

A Remote ISSO (Information Systems Security Officer) job involves managing and ensuring the security of an organization's IT systems while working remotely. Responsibilities include implementing security policies, conducting risk assessments, ensuring compliance with regulations like NIST and FISMA, and responding to security incidents. Remote ISSOs collaborate with IT teams to safeguard sensitive data and maintain system integrity. Strong knowledge of cybersecurity frameworks and federal compliance standards is essential for this role.

What are some common challenges faced by Remote ISSOs and how can they be overcome?

Remote ISSOs often face the challenge of maintaining strong oversight of security protocols and compliance across distributed teams and systems without being onsite. To overcome this, successful ISSOs utilize secure remote access tools, implement robust communication practices, and foster strong relationships with IT and compliance stakeholders. Regular virtual meetings, clear documentation, and proactive incident response planning help ensure security standards are consistently met. Staying updated on evolving cyber threats and engaging in continuous professional development also help remote ISSOs remain effective and adaptable in a dynamic environment.

What are the most commonly searched types of Isso jobs in Reston, VA? The most popular types of Isso jobs in Reston, VA are:
What are popular job titles related to Remote Isso jobs in Reston, VA? For Remote Isso jobs in Reston, VA, the most frequently searched job titles are:
What job categories do people searching Remote Isso jobs in Reston, VA look for? The top searched job categories for Remote Isso jobs in Reston, VA are:
What cities near Reston, VA are hiring for Remote Isso jobs? Cities near Reston, VA with the most Remote Isso job openings:
Infographic showing various Remote Isso job openings in Reston, VA as of June 2026, with employment types broken down into 71% Full Time, and 29% Part Time. Highlights an 100% Remote job distribution, with an average salary of $123,102 per year, or $59.2 per hour.

Information System Security Officer

Hiring Our Heroes

Arlington, VA โ€ข Remote

Full-time

Posted 4 days ago


Job description

Information System Security Officer

MILITARY FRIENDLY & PREFERRED - HOH SPONSOR

The Information Systems Security Officer (ISSO) is responsible for supporting the full lifecycle of security assessment and authorization (A&A) activities for information systems. The ISSO ensures that assigned systems comply with federal cybersecurity standards and maintain their Authority to Operate (ATO) through continuous monitoring and documentation.

The ISSO will be responsible for developing and providing risk assessments, Security Control Assessments (SCA), A&A documentation and various reports, based on NIST guidelines and client's policies, procedures and request. The ISSO will be responsible for providing security recommendations on any system changes or new technologies, analysis on vulnerability scans, conducting continuous monitoring activities, and provide mitigation recommendations for any risks or threats.

RESPONSIBILITIES:

  • Lead and conduct Pre-Security Assessment and Authorization (A&A) activities, including stakeholder identification, change request submissions, appointment memorandums, and IT Security Kickoff meetings.
  • Supports the ISBO in day-to-day IT security activities.
  • Assists the ISBO with reviews of the security posture of the system and report any findings to the ISBO, CISO, and the AO.
  • Conduct Information System Categorization by identifying information types, completing FIPS-199 assessments, and facilitating Business Impact Analyses (BIA), Privacy Threshold Analyses (PTA), and Privacy Impact Assessments (PIA).
  • Develop and maintain system security documentation, including:
    • System Administration Plan (SAM)
    • Configuration Management Plan (CMP)
    • IT Contingency Plan (ITCP)
    • Information Security Continuous Monitoring (ISCM) Plan
    • Incident Response Plan (IRP)
    • Security Assessment Report (SAR)
    • System Security Plan (SSP)
  • Coordinate initial and annual ITCP testing in collaboration with the OCIO Business Continuity and Disaster Recovery (BCDR) Office.
  • Develop and manage inter-agency agreements and documentation such as MOUs, MOAs, ISAs, IT Security Waivers, and Risk Acceptance Memorandums.
  • Document and maintain Security Control Implementation details, ensuring updates are made according to required frequency.
  • Coordinate vulnerability and compliance scans, Security Control Assessments (SCA), and track remediation efforts with the IT Security Test Team.
  • Manage and update Plan of Action and Milestones (POA&M) entries, submitting remediated findings for closure.
  • Prepare and present SAR to Authorizing Officials to obtain or renew ATO.
  • Perform Information Security Continuous Monitoring (ISCM) activities to ensure ongoing compliance and security posture of systems.
  • Develop and update project schedule, including A&A / SCA task and milestones, task dependencies, and personnel resources.
  • Conduct A&A activities and tasks and obtain ATO in line with NIST and client guidance and directives.
  • Determining the baseline IT Security requirements for IT Systems, identifying system boundaries, determining information categories, assisting with FIPS-199.
  • Ensure that IT Systems are operated, used, maintained, and disposed of in accordance with internal security policies and practices.
  • Enforce security policies and safeguards on all personnel having access to the IT System for which the ISSO has responsibility.
  • Ensure users and system support personnel have the required authorization and need-to-know; have been indoctrinated; and are familiar with internal security practices before access to the IT System.
  • Implement security controls based on IT System FIPS categorization.
  • Document security control implementation in the system's Security Plan using the client's GRC tool.
  • Document system's risk assessment per client directives and requirements.
  • Review and monitoring system security and audit logs.
  • Develop and maintain Plan of Actions and Milestones (POA&Ms) for IT systems.
  • Update A&A documentation and artifacts on a regular basis (e.g. annually, after approved change).

QUALIFICATIONS:

  • A minimum of five (5) years of demonstrated experience in the Information Security or IT field.
  • Demonstrates a proficiency with developing, maintaining and managing SA&A packages.
  • Experience with developing and managing POA&M's.
  • Strong problem solving and analysis skills, self-motivated, and able to work and communicate in a team environment.
  • Strong understanding of federal cybersecurity frameworks (e.g., NIST RMF, FIPS-199, FISMA).
  • Experience in developing and maintaining security documentation and plans.
  • Possess experience conducting CPT's.
  • Experience conducting audit log reviews.
  • Technical experience with conducting vulnerability management, compliance scanning, and providing mitigation techniques.
  • Excellent communication and coordination skills with technical and non-technical stakeholders.
  • Ability to manage multiple systems and projects simultaneously in a dynamic environment.
  • Excellent communication (written and verbal) skills.

CERTIFICATION:

  • A minimum of at least one (1) certification that meet DOD 8570 IAT Level II (e.g., Security+, GSEC, CASP) requirements or any equivalent or more advanced.

CLEARANCE:

  • Client Suitability and Public Trust

LOCATION and HOURS:

  • Location: Primary location is at Zermount HQ (Arlington, VA) and the Client Site (Washington, D.C.). Remote work is authorized.
    • Onsite work at the primary location., may be occasionally required.
  • Hours of Operation (Business Hours): 8:00 am ET - 5:30 pm ET