Information System Security Officers (ISSO)
- Hiring from
- United States
- Work type
- Remote
- Posted
- Oct 2, 2026
Job Description
This is a remote position.
Information System Security Officers (ISSO)
Location: Remote
Clearance Requirement: Active Secret
Employment Type: Full-Time
About Company
Disruptive Solutions, a Service-Disabled Veteran-Owned Small Business (SDVOSB) delivering mission-focused cybersecurity and technology solutions for federal and commercial clients. We specialize in advanced cybersecurity operations, AI/ML integration, cloud modernization, data governance, and risk management. With a proven track record supporting agencies like the Department of Defense (DoD), Department of Homeland Security (DHS), Cybersecurity and Infrastructure Security Agency (CISA), and the Department of Treasury, we deliver innovative solutions that maximize efficiency and strengthen cyber resilience. At our core, we are dedicated partners committed to securing the mission with innovation, integrity, and measurable impact.
Job Summary
Disruptive Solutions is seeking multiple experienced Information System Security Officers (ISSO) to support cybersecurity and information assurance activities for State. The ISSO will provide hands-on cybersecurity support for assigned information systems throughout the system lifecycle, maintaining visibility into authorization status, security posture, vulnerabilities, and cybersecurity risk. The candidate will work closely with ISSMs, system owners, security engineers, SCAs, technical teams, and other stakeholders to maintain system authorizations and ensure compliance with federal and State cybersecurity requirements.
Key Responsibilities
- Serve as the ISSO for assigned State information systems and support cybersecurity activities throughout the complete system lifecycle.
- Execute and support all phases of the NIST Risk Management Framework (RMF) and system authorization process.
- Maintain accurate information regarding system lifecycle stage, authorization status, ATO expiration, security controls, vulnerabilities, and overall risk posture.
- Develop, maintain, and update RMF and authorization documentation, including System Security Plans (SSPs), Security Assessment Plans (SAPs), Security Assessment Reports (SARs), POA&Ms, risk assessments, contingency plans, incident response plans, and supporting security artifacts.
- Support system categorization, security control selection and tailoring, inherited controls, control implementation, assessment, authorization, and continuous monitoring activities.
- Coordinate with system owners and technical teams to obtain, review, and validate security control implementation evidence.
- Maintain version control and quality of RMF documentation and supporting security artifacts.
- Prepare systems for independent Security Control Assessments (SCAs), including implementation readiness activities and collection and validation of supporting evidence.
- Identify, document, track, and manage cybersecurity risks, vulnerabilities, and remediation activities through the POA&Ms lifecycle.
- Review vulnerability and compliance findings from Tenable, Wiz/cloud security platforms, iPost, and comparable security technologies and translate technical findings into risk and remediation activities.
- Track vulnerability findings and support remediation in accordance with applicable CISA Binding Operational Directives (BODs), Known Exploited Vulnerabilities (KEV), STIGs, and State requirements.
- Support continuous monitoring activities to ensure systems maintain an acceptable security posture and authorization documentation remains current.
- Support FISMA metrics, annual FISMA reviews, cybersecurity audits, data calls, and compliance reporting.
- Develop and maintain supporting security artifacts such as evidence indexes, inherited control matrices, system boundary and data-flow documentation, and control implementation statements.
- Support security requirements for new and existing systems throughout the SDLC and DevSecOps lifecycle.
- Support cloud and hybrid system authorization activities, including FedRAMP control inheritance and cloud security requirements.
- Participate in cybersecurity risk governance activities and provide recommendations to system owners, ISSMs, security engineers, and other stakeholders.
- Support post-incident activities and ensure relevant findings are incorporated into risk assessments, POA&Ms, SSPs, and control implementation statements.
Required Qualifications
- 5–15 years of cybersecurity experience, including experience as an ISSO or performing Information Assurance, Assessment & Authorization, RMF, or comparable cybersecurity responsibilities.
- Demonstrated experience supporting federal information systems through the RMF and ATO lifecycle.
- Strong knowledge of NIST SP 800-37, NIST SP 800-53, NIST SP 800-60, FISMA, and FIPS 199/200.
- Experience developing and maintaining SSPs, SAPs, SARs, POA&Ms, risk assessments, and other authorization artifacts.
- Experience assessing security controls and validating implementation evidence.
- Experience with vulnerability management, remediation tracking, and continuous monitoring.
- Experience using enterprise GRC platforms to manage authorization packages, security controls, and POA&Ms.
- Ability to interpret vulnerability and compliance results from technologies such as Tenable, Wiz, and other enterprise security platforms.
- Understanding of STIGs, CISA KEV, BODs, vulnerability remediation, and configuration compliance.
- Strong written and verbal communication skills with the ability to communicate security risks to technical and non-technical stakeholders.
- Experience supporting federal cybersecurity environments.
- Active Secret clearance.
- U.S. Citizenship required.
Preferred Qualifications
- Bachelor's degree in Computer Science, Information Technology, Cybersecurity, Information Systems, or a related field is preferred. Relevant professional experience may be considered in lieu of a degree based on program requirements.
Equal Opportunity Statement
Disruptive Solutions, LLC is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, disability, protected veteran status, sexual orientation, gender identity, or any other characteristic protected by law.