Demo

Information Systems Security Officer (ISSO) ? Subject Matter Expert, Level I

RIVIDIUM
Quantico, VA Full Time
POSTED ON 8/2/2026
AVAILABLE BEFORE 11/29/2026

RiVidium Inc. is seeking an experienced Information Systems Security Officer (ISSO) - (SME), Level I to serve the team for all Cybersecurity and Intelligence Enterprise Information Technology Services (CIEITS) program activities.

The Information Systems Security Officer (ISSO) — (SME), Level I is responsible for providing comprehensive cybersecurity support for a portfolio of 130 Department of Homeland Security (DHS) Intelligence Enterprise (DHS IE) information systems spanning classified and unclassified environments, including on-premises, cloud, hybrid, and cross-domain solutions.

Serving as the principal cybersecurity advisor to system owners, the ISSO ensures compliance with Federal, DHS, and Intelligence Community (IC) cybersecurity requirements throughout the system lifecycle. This position is responsible for implementing the NIST Risk Management Framework (RMF), maintaining continuous authorization readiness, managing security documentation, coordinating vulnerability remediation, and supporting ongoing security operations.

In addition to traditional ISSO responsibilities, the incumbent serves as the Sensitive Compartmented Information Facility (SCIF) Information Security Compliance Representative (ISCR), ensuring assigned SCIF systems, hardware, and facilities remain compliant with Intelligence Community security policies and accreditation requirements.

The ideal candidate possesses extensive experience supporting complex Federal cybersecurity programs and demonstrates expertise in RMF, continuous monitoring, vulnerability management, cloud security, SCIF compliance, and classified information system security.

Key Responsibilities

  • Perform Information Systems Security Officer (ISSO) responsibilities for a portfolio of 130 assigned information systems throughout the system lifecycle in accordance with NIST RMF, supporting Steps 1, 2, 3, and 6.
  • Serve as the primary cybersecurity advisor to system owners regarding security posture, authorization status, compliance, risk management, and operational security.
  • Ensure information systems are operated, maintained, monitored, and decommissioned in accordance with DHS, Intelligence Community, and Federal cybersecurity requirements.
  • Develop, maintain, and update all RMF security documentation within the Governance, Risk, and Compliance (GRC) platform, including:
    • System Security Plans (SSPs)
    • Plans of Action and Milestones (POA&Ms)
    • Risk Acceptance and Exception documentation
    • Privacy Threshold Analyses (PTAs)
    • Contingency Plans (CPs)
    • Rules of Behavior
    • System inventories and supporting authorization artifacts
  • Manage and track POA&Ms using established review intervals (30, 60, 90, 120, and 180 days), ensuring timely remediation or submission of risk waivers and exception requests.
  • Conduct weekly audit log reviews and investigate anomalous or suspicious activity in coordination with cybersecurity operations teams.
  • Coordinate system modifications, configuration changes, and authorization boundary updates with the ISSM, Security Control Assessor (SCA), and Authorizing Official (AO/DAO) through the Information Assurance Technical Tracking (IATT) process.
  • Notify the ISSM whenever system changes could impact the Authorization to Operate (ATO).
  • Perform day-to-day cybersecurity operations, including:
    • Security incident response support
    • Personnel security coordination
    • Physical and environmental security oversight
    • Security awareness activities
    • Configuration management support
  • Ensure DHS 4300C system decommissioning requirements are properly executed and support system recovery activities following contingency events or disasters.
  • Plan, coordinate, and facilitate annual Contingency Plan Test Exercises, including tabletop, simulation, parallel, and full operational testing.
  • Prepare and submit Quarterly Continuous Protection and Evaluation Metrics (CPEM) reports for assigned systems.
  • Serve as the SCIF Information Security Compliance Representative (ISCR) by:
    • Maintaining compliance with Intelligence Community SCIF security requirements
    • Completing mandatory ICOP training
    • Coordinating with the DHS I&A CISO SCIF Compliance Team
    • Maintaining inventory accountability for SCIF hardware and information systems
    • Reporting SCI security incidents
    • Preparing and submitting Monthly SCIF Security Checklists
  • Prepare Weekly Activity Reports (WARs), POA&M status reports, Incident Response reports, removable media reports, privileged user reports, and other required Government deliverables.
  • Support vulnerability management by coordinating vulnerability scanning activities, reviewing scan results, and tracking remediation efforts.
  • Collaborate with ISSMs, engineers, developers, system administrators, and cybersecurity operations teams to maintain continuous authorization and improve enterprise security posture.

Minimum Qualifications

  • Active Top Secret/Sensitive Compartmented Information (TS/SCI) security clearance.
  • Minimum 5–10 years of experience serving as an Information Systems Security Officer (ISSO), Information Systems Security Manager (ISSM), or in a comparable cybersecurity role supporting Federal Government or Intelligence Community programs.
  • Current Certified Information Security Manager (CISM), Certified Authorization Professional (CAP), or comparable Governance, Risk, and Compliance (GRC) certification.
  • Certified Information Systems Security Professional (CISSP) certification is highly desirable.
  • Demonstrated experience supporting RMF authorization activities across hybrid cloud and on-premises environments.
  • Working knowledge of:
    • NIST Risk Management Framework (RMF)
    • NIST SP 800-53
    • DHS Sensitive Systems Policy Directive 4300C
    • CNSSI 1253
    • ICD 503
  • Experience using Governance, Risk, and Compliance (GRC) tools such as RSA Archer.
  • Experience using vulnerability assessment tools such as Nessus, ACAS, or equivalent.
  • Experience securing Windows, Linux, and open-source operating systems.
  • Experience supporting Cross Domain Solutions (CDS) and associated security governance requirements.
  • Familiarity with DevSecOps, Agile software development methodologies, and secure software lifecycle practices.
  • Bachelor's degree in Cybersecurity, Information Systems, Computer Science, Information Assurance, or a related technical discipline.

Preferred Qualifications

  • AWS Certified Security – Specialty, Microsoft Azure Security Engineer Associate, or equivalent cloud security certification.
  • Experience serving as a SCIF Information Security Compliance Representative (ISCR) or coordinating with Special Security Officers (SSOs).
  • Experience supporting Cross Domain Solution (CDS) governance, including National Cross Domain Strategy and Management Office (NCDSMO) requirements and Raise-the-Bar (RTB) initiatives.
  • Familiarity with Continuous Protection and Evaluation Metrics (CPEM) reporting requirements and Intelligence Community Continuous Monitoring (IC ConMon) programs.
  • Experience supporting DHS Intelligence & Analysis (I&A), the Intelligence Community, or other classified Federal cybersecurity environments.

Required Certifications

One or more of the following certifications are required:

  • Certified Information Security Manager (CISM)
  • Certified Authorization Professional (CAP)
  • Governance, Risk, and Compliance (GRC) Certification

Preferred:

  • Certified Information Systems Security Professional (CISSP)
  • AWS Certified Security – Specialty
  • Microsoft Certified: Azure Security Engineer Associate

Clearance Requirement

Active Top Secret/Sensitive Compartmented Information (TS/SCI) Clearance Required

Benefits:

Health Insurance, 401K Plan

Salary : $60,309 - $95,797

If your compensation planning software is too rigid to deploy winning incentive strategies, it’s time to find an adaptable solution. Compensation Planning
Enhance your organization's compensation strategy with salary data sets that HR and team managers can use to pay your staff right. Surveys & Data Sets

What is the career path for a Information Systems Security Officer (ISSO) ? Subject Matter Expert, Level I?

Sign up to receive alerts about other jobs on the Information Systems Security Officer (ISSO) ? Subject Matter Expert, Level I career path by checking the boxes next to the positions that interest you.
Income Estimation: 
$270,069 - $359,305
Income Estimation: 
$328,229 - $449,590
Income Estimation: 
$112,673 - $137,290
Income Estimation: 
$139,945 - $168,577
Income Estimation: 
$140,233 - $181,029
Income Estimation: 
$161,209 - $233,553
Employees: Get a Salary Increase
View Core, Job Family, and Industry Job Skills and Competency Data for more than 15,000 Job Titles Skills Library

Job openings at RIVIDIUM

  • RIVIDIUM Washington, DC
  • Title Legislative Research Analyst Full-Time/Part-Time Full-Time Description RiVidium Inc. is seeking a Senior Legislative Rearch Analyst to support the fu... more
  • 1 Day Ago

  • RIVIDIUM Quantico, VA
  • Title Information Systems Security Officer (ISSO) Subject Matter Expert, Level I Full-Time/Part-Time Full-Time Description RiVidium Inc. is seeking an expe... more
  • 1 Day Ago

  • RIVIDIUM Quantico, VA
  • RiVidium Inc. is seeking an experienced Cybersecurity Governance & Policy Specialist ? Level II to serve the team for all Cybersecurity and Intelligence En... more
  • 1 Day Ago

  • RIVIDIUM Quantico, VA
  • RiVidium Inc. is seeking an experienced Security Control Assessor (SCA) — Level II to serve the team for all Cybersecurity and Intelligence Enterprise Info... more
  • 1 Day Ago


Not the job you're looking for? Here are some other Information Systems Security Officer (ISSO) ? Subject Matter Expert, Level I jobs in the Quantico, VA area that may be a better fit.

  • Rividium Inc Quantico, VA
  • Description RiVidium Inc. is seeking an experienced Information Systems Security Officer (ISSO) - (SME), Level I to serve the team for all Cybersecurity an... more
  • 4 Days Ago

  • Rividium Inc Quantico, VA
  • Title Information Systems Security Officer (ISSO) Subject Matter Expert, Level I Full-Time/Part-Time Full-Time Description RiVidium Inc. is seeking an expe... more
  • 1 Day Ago

AI Assistant is available now!

Feel free to start your new journey!