Information Systems Security Officer

5 days ago


Washington, Washington, D.C., United States CyberStorm Defense L.L.C. Full time $120,000 - $180,000 per year

CyberStorm Defense is seeking an experienced Information Systems Security Officer (ISSO) to provide cybersecurity governance, risk management, and compliance oversight for systems supporting the Federal Aviation Administration (FAA) and Department of Transportation (DOT).

This role supports FAA TechOps (AJW), Enterprise Services (AJM-3), and Program Management Organization (PMO) activities by ensuring that information systems remain compliant with AMS and NIST Risk Management Framework (RMF) standards, and maintain secure Authorization to Operate (ATO) status.

The ISSO will coordinate directly with system owners, assessors, and program leads to sustain continuous monitoring, manage risk posture, and ensure documentation and evidence are audit-ready.

Key Responsibilities

  • Serve as primary ISSO of record for designated FAA systems and applications.
  • Develop, review, and maintain System Security Plans (SSP), Security Assessment Reports (SAR), POA&Ms, and Continuous Monitoring Plans.
  • Guide systems through the FAA AMS-aligned RMF lifecycle (Categorization through Continuous Monitoring).
  • Manage control implementation evidence, coordinate with engineering teams to remediate vulnerabilities, and update artifacts accordingly.
  • Perform risk assessments and present results to system owners and Authorizing Officials (AO).
  • Conduct annual control reviews, contingency plan testing, and incident response tabletop exercises.
  • Interface with FAA's Cybersecurity Management Center (CSMC) and Enterprise Continuous Monitoring (ConMon) programs for data collection and reporting.
  • Support audit readiness for internal and external assessments (IG, GAO, DHS CDM).
  • Track and report on compliance metrics, residual risk, and system security posture to FAA leadership.
  • Collaborate with the Cybersecurity Engineer, Cloud Security, and Network teams to ensure all control families (AC, CM, IR, SC, SI, etc.) remain implemented and verified.

Mandatory Qualifications

  • 10+ years of experience as an ISSO or Information Assurance professional supporting FAA, DOT, or other federal agencies.
  • Deep knowledge of FAA AMS policy, NIST SP 800-53/37, FedRAMP, and FISMA frameworks.
  • Experience maintaining ATOs under the FAA AMS RMF variant and performing continuous monitoring.
  • Familiarity with eMASS, XACTA, or similar compliance tools for RMF tracking.
  • Excellent documentation and technical writing skills for security artifacts and risk reports.
  • Bachelor's degree in Cybersecurity, Information Systems, or related field.

Preferred Qualifications

  • Prior support to FAA TechOps (AJW), Enterprise Services (AJM-3), or NextGen (ANG) programs.
  • Certifications: CISSP, CISM, CAP, or Security+ CE.
  • Experience integrating outputs from vulnerability management tools (Tenable, Splunk, Qualys) into POA&M tracking.
  • Working knowledge of Zero Trust Architecture (ZTA) policy controls and the FAA's ongoing ZTA roadmap.
  • Active Public Trust or Secret clearance preferred.

About CyberStorm Defense

CyberStorm Defense is an SBA 8(a), MBE/DBE-certified small business headquartered in the National Capital Region. We deliver cybersecurity, systems engineering, and aviation modernization services to civilian and defense clients.

Job Types: Full-time, Contract

Pay: $100, $165,000.00 per year

Benefits:

  • 401(k)
  • Health insurance
  • Vision insurance

Work Location: Hybrid remote in Washington, DC 20004



  • Washington, Washington, D.C., United States Iron Bow Technologies Full time $80,000 - $120,000 per year

    Iron Bow Technologies is for people who believe trust is paramount, transformation is embraced, and the future is here, because"What we do matters"We are a next generation solutions provider, delivering mission success across government, healthcare, and commercial industries. Iron Bow relies on ourpassionate people,long standing partnerships, andstrategic...


  • Washington, Washington, D.C., United States Peraton Full time $80,000 - $128,000

    ResponsibilitiesWe are seeking an experienced and highly motivated Information Systems Security Officer (ISSO) to join our team. The ISSO will be responsible for managing the security and integrity of information systems in compliance with Risk Management Framework (RMF) policies and procedures. This role involves working closely with government customers,...


  • Washington, Washington, D.C., United States Peraton Full time $86,000 - $138,000 per year

    About PeratonPeraton is a next-generation national security company that drives missions of consequence spanning the globe and extending to the farthest reaches of the galaxy. As the world's leading mission capability integrator and transformative enterprise IT provider, we deliver trusted, highly differentiated solutions and technologies to protect our...


  • Washington, Washington, D.C., United States Booz Allen Hamilton Full time $99,000 - $225,000 per year

    Information Systems Security OfficerThe Opportunity:  Cyber threats are everywhere, and the constantly evolving nature of these threats can make understanding them seem overwhelming to government organizations. In all of this "cyber noise," how can these organizations understand their risks and how to mitigate them? The answer is you—an Information...


  • Washington, Washington, D.C., United States HRUCKUS Full time $70,000 - $95,000 per year

    Veteran Owned Firm Seeking a Junior Information Systems Security Officer (ISSO) for an Onsite role in Washington, DCMy name is Stephen Hrutka, and I am the owner of a Veteran Owned management consulting firm in Washington, DC focused on Technical/Cleared Recruiting for the DoD and IC.HRUCKUS helps other Veteran-Owned businesses recruit for positions across...


  • Washington, Washington, D.C., United States Cloudshape Full time $100,000 - $120,000 per year

    Location:Remote with a high preference for candidates local to the DC, MD, VA areaCitizenship Required:YesClearance Type:SecretPositions Available:1Salary Range: $110,000 - $120,000At Cloudshape our employees have incredible opportunities to work in helping organizations securely transform their IT Infrastructure to meet the changing business cultures. We...


  • Washington, Washington, D.C., United States A3 Technology Inc Full time $50,000 - $175,000 per year

    A3 Technology, Inc. is seeking a mission-driven Information System Security Officer (ISSO) to lead Assessment & Authorization (A&A) and Continuous Monitoring for U.S. Customs and Border Protection (CBP) systems. The ISSO will assume duties in accordance with DHS 4300A and CBP HB D, ensuring systems achieve and maintain Authority to Operate (ATO) while...


  • Washington, Washington, D.C., United States Global Resource Solutions, Inc. Full time $100,000 - $120,000 per year

    Global Resource Solutions, Inc. (GRS) is seeking an enthusiastic, motivated, detail orientated, and talented individual for the position of Information System Security Officer II.Job Description:Summary: The ISSO II's primary function is working within Special Access Programs (SAPs) supporting Department of Defense (DoD) agencies, such as HQ Air Force,...


  • Washington, Washington, D.C., United States AT&T Full time $98,100 - $228,600

    Job Description: This position requires office presence of a minimum of 5 days per week and is only located at customer's site. No relocation is offered.AT&T Global Public Sector is a trusted provider of secure, IP enabled, cloud-based, network solutions and professional services to the Federal Government.   We are dedicated to recruiting, developing and...


  • Washington, Washington, D.C., United States MANTECH Full time $120,000 - $140,000 per year

    MANTECH seeks a motivated, career and customer-oriented Senior Cloud Information System Security Officer (ISSO) to join our team in Washington, DC.Responsibilities include, but are not limited to:Ensure the day-to-day implementation, oversight, continuous monitoring, and maintenance of the security configuration, practices, and procedures for each ISProvide...