Information System Security Officer

2 weeks ago


Arlington, VA, United States LIGHTFEATHER IO LLC Full time

LightFeather is seeking a highly skilled and detail-oriented Information System Security Officer (ISSO) to join our team, providing critical security oversight and Certification & Accreditation (C&A) support for the CISA Gateway. This role offers the opportunity to support impactful, high-visibility security initiatives within a collaborative environment. You'll safeguard enterprise systems, strengthen compliance posture, and contribute to an organization that values innovation, agility, and professionalism.

Location: Arlington, VA (Hybrid)
Job Type: Full-time
Citizenship: U.S. Citizenship Required
Clearance Requirement: Active Public Trust Security Clearance
Key Responsibilities

  • Serve as the Information System Security Officer (ISSO) for assigned enterprise systems, managing all security and compliance requirements.
  • Support the Certification & Accreditation (C&A) process by maintaining and updating system security documentation and artifacts.
  • Draft and maintain System Security Plans (SSPs), Contingency Plans (CPs), Interconnection Security Agreements (ISAs), and related security documentation.
  • Maintain and update security artifacts in governance, risk, and compliance (GRC) systems to ensure all materials remain current and complete for the system's Authority to Operate (ATO).
  • Implement and oversee National Institute of Standards and Technology (NIST) 800-53 and 800-37 (Risk Management Framework) controls.
  • Manage and track Plans of Action and Milestones (POA&Ms) from identification through remediation.
  • Conduct security audits, review system audit logs, and identify potential vulnerabilities or misconfigurations.
  • Utilize Tenable Nessus scanning tools to identify and remediate vulnerabilities.
  • Support security requirements for AWS GovCloud (US) or other cloud environments, ensuring compliance with federal security standards.
  • Coordinate with stakeholders, developers, and system owners to ensure adherence to Federal Information Security Modernization Act (FISMA) and other federal security oversight requirements.
  • Prepare and submit complete system security authorization packages for Authorization Official (AO) approval.
Required Qualifications
  • U.S. Citizenship.
  • Active Public Trust or higher security clearance.
  • Minimum 4 years of experience in Certification & Accreditation (C&A) activities for federal or enterprise IT systems.
  • Hands-on experience using GRC tools or security compliance platforms to maintain security artifacts.
  • Demonstrated expertise in drafting security documentation, including SSPs, CPs, and ISAs.
  • Strong understanding of NIST 800-53, 800-37, RMF, and related federal security frameworks.
  • Experience with vulnerability management tools such as Tenable Nessus.
  • Knowledge of operating systems, network architecture, web applications, and database security principles.
  • Experience supporting cloud security implementations (e.g., AWS GovCloud).
  • Familiarity with FISMA compliance and other federal oversight activities.
  • Ability to conduct security audits and reviews of audit logs.
  • Strong communication and technical writing skills to document findings, plans, and security posture clearly.
Preferred Qualifications
  • Security certifications such as Security+, CISSP, or CEH.
  • Experience coordinating directly with Authorizing Officials (AOs) and system owners during security assessments and ATO processes.
  • Prior experience supporting federal agencies or large enterprise organizations.
  • Experience working in high-security or mission-critical environments.

Why Join LightFeather?
At LightFeather, you're not just taking a job-you're joining a purpose-driven team that delivers innovative, mission-critical solutions to make a real difference. You'll work on diverse, meaningful projects that challenge and inspire you, alongside some of the best minds in the industry.

  • Arlington, VA, United States RIT Solutions, Inc. Full time

    Information Systems Security Officer 5 Days onsite in Arlington, VA Job Description: The Information System Security Officer serves as the primary cybersecurity point of contact for work performed under the contract possessing an in-depth knowledge of federal information system security policy, industry best practices, security control assessments, Plan of...


  • Arlington, VA, United States Strategic Analysis Full time

    Strategic Analysis, Inc. is seeking a candidate to provide Information Systems Security Officer (ISSO) and technical advisory support. The successful candidate will have expertise in Department of Defense (DOD) compliance standards and a strong familiarity with NIST (National Institute of Standards and Technology) RMF (Risk Management Framework) and the...


  • Arlington, VA, United States Strategic Analysis Full time

    Strategic Analysis, Inc. is seeking a candidate to provide Information Systems Security Officer (ISSO) and technical advisory support. The successful candidate will have expertise in Department of Defense (DOD) compliance standards and a strong familiarity with NIST (National Institute of Standards and Technology) RMF (Risk Management Framework) and the...


  • Arlington, VA, United States Booz Allen Hamilton Full time

    Job Number: R0225011Information Systems Security Officer The Opportunity: Cyber threats are everywhere, and the constantly evolving nature of these threats can make understanding them seem overwhelming to the Army. In all of this "cyber noise," how can these organizations understand their risks and how to mitigate them? The answer is an information security...


  • Arlington, VA, United States Booz Allen Hamilton Full time

    Job Number: R0225011Information Systems Security Officer The Opportunity: Cyber threats are everywhere, and the constantly evolving nature of these threats can make understanding them seem overwhelming to the Army. In all of this "cyber noise," how can these organizations understand their risks and how to mitigate them? The answer is an information security...


  • Arlington, VA, United States Booz Allen Hamilton Full time

    Job Number: R0225011Information Systems Security Officer The Opportunity: Cyber threats are everywhere, and the constantly evolving nature of these threats can make understanding them seem overwhelming to the Army. In all of this "cyber noise," how can these organizations understand their risks and how to mitigate them? The answer is an information security...


  • Arlington, VA, United States Chenega Corporation Full time

    Req ID: 38517 Summary Information System Security Officer (ISSO) Alexandria, VA Are you ready to enhance your skills and build your career in a rapidly evolving business climate? Are you looking for a career where professional development is embedded in your employer's core culture? If so, Chenega Military, Intelligence & Operations Support (MIOS) could be...


  • Arlington, VA, United States Chenega Corporation Full time

    Req ID: 38517 Summary Information System Security Officer (ISSO) Alexandria, VA Are you ready to enhance your skills and build your career in a rapidly evolving business climate? Are you looking for a career where professional development is embedded in your employer's core culture? If so, Chenega Military, Intelligence & Operations Support (MIOS) could be...


  • Arlington, VA, United States Chenega Corporation Full time

    Req ID: 38517 Summary Information System Security Officer (ISSO) Alexandria, VA Are you ready to enhance your skills and build your career in a rapidly evolving business climate? Are you looking for a career where professional development is embedded in your employer's core culture? If so, Chenega Military, Intelligence & Operations Support (MIOS) could be...


  • Arlington, VA, United States Gormat Full time

    The Information Systems Security Officer (ISSO) plays a critical role in ensuring the secure operation of federal information systems. This position requires deep technical and procedural knowledge to guide systems through the full lifecycle of the Risk Management Framework (RMF), ensuring compliance with NIST, FISMA, FedRAMP, and agency-specific guidelines....