Cybersecurity Compliance

Information System Security Officer (ISSO) – TS/SCI Full Scope Poly – Annapolis Junction, MD

Information System Security Officer (ISSO) – TS/SCI Full Scope Poly

📍 Location: Annapolis Junction, MD
🏢 Work Arrangement: 100% Onsite
💼 Employment Type: Full-Time
🔒 Security Clearance Required: Active TS/SCI with Full Scope Polygraph (NSA Preferred)
🇺🇸 Citizenship: U.S. Citizen Required
🚫 Visa Sponsorship: Not Available
🚚 Relocation Assistance: Available
💰 Compensation: $100,000 – $200,000 Base Salary

Overview

A leading government technology contractor is seeking Information System Security Officers (ISSOs) to support mission-critical classified programs within highly secure government environments.

This role is responsible for maintaining cybersecurity compliance throughout the Risk Management Framework (RMF) lifecycle, supporting system accreditation, continuous monitoring, vulnerability management, and ongoing cybersecurity operations.

The ideal candidate will possess strong RMF expertise, experience supporting classified environments, and the ability to work closely with System Administrators, System Owners, Information System Security Managers (ISSMs), Security Control Assessors, and Government stakeholders.

Key Responsibilities

Risk Management Framework (RMF)

  • Support the full RMF lifecycle for classified systems.

  • Develop and maintain RMF documentation and accreditation packages.

  • Coordinate Authority to Operate (ATO) activities.

  • Support security authorization and reauthorization efforts.

  • Ensure systems maintain compliance with cybersecurity requirements.

Security Compliance & Assessments

  • Conduct security control reviews and assessments.

  • Validate implementation of required security controls.

  • Monitor compliance against NIST and government standards.

  • Support internal and external cybersecurity audits.

Continuous Monitoring (ConMon)

  • Support ongoing Continuous Monitoring activities.

  • Review system configurations and compliance posture.

  • Analyze vulnerability findings and remediation efforts.

  • Track compliance status and corrective actions.

Vulnerability & Risk Management

  • Monitor vulnerabilities and security findings.

  • Coordinate remediation efforts with technical teams.

  • Assess risk and recommend mitigation strategies.

  • Support vulnerability management programs.

Stakeholder Collaboration

  • Work closely with:

    • System Administrators

    • System Owners

    • ISSMs

    • Security Control Assessors

    • Government Security Teams

  • Provide security guidance and compliance recommendations.

  • Support cybersecurity reviews and inspections.

Required Qualifications

Security Requirements

✔ Active TS/SCI Clearance

✔ Active Full Scope Polygraph (NSA Preferred)

✔ U.S. Citizenship Required

Cybersecurity & RMF Experience

Experience supporting:

  • Information Assurance (IA)

  • Cybersecurity Compliance

  • ISSO Functions

  • Classified Information Systems

Strong understanding of:

  • Risk Management Framework (RMF)

  • Authority to Operate (ATO)

  • Security Control Assessments

  • Continuous Monitoring (ConMon)

  • Risk Assessment Methodologies

RMF & Compliance Tools

Experience with one or more of:

  • LATTEART

  • XACTA

  • BISCOTTI

  • WATCHCAT

  • STE

Experience with:

  • Compliance scanning tools

  • Configuration assessment tools

  • Vulnerability management platforms

NIST Framework Knowledge

Strong familiarity with:

  • NIST SP 800-53 Rev. 3 and/or Rev. 5

  • NIST SP 800-37

  • Security Controls

  • RMF Documentation Requirements

Required Documentation Experience

Candidates should have experience creating, reviewing, or maintaining:

Security Documentation

  • System Security Plans (SSP)

  • Plans of Action & Milestones (POA&M)

  • Security Plan Findings (SPF)

  • Exception Documentation

Risk & Compliance Documentation

  • Risk Assessment Reports (RAR)

  • Security Assessment Reports (SAR)

  • Business Impact Assessments (BIA)

  • Configuration Management Plans (CMP)

  • Contingency Plans (CP)

  • After Action Reports (AAR)

Preferred Qualifications

Government & Classified Environment Experience

  • Classified Government systems

  • Security audits and inspections

  • Compliance reviews

  • Vulnerability remediation programs

Stakeholder Coordination

Experience coordinating with:

  • Authorizing Officials (AO)

  • Security Control Assessors (SCA)

  • ISSMs

  • System Owners

Technical Knowledge

  • Operating System Security

  • System Administration Concepts

  • Vulnerability Management

  • Configuration Management

Preferred Certifications

Highly desired certifications include:

  • CompTIA Security+

  • CISSP

  • CAP

  • CASP+

  • CISM

Must-Have Requirements

Clearance

✅ Active TS/SCI Clearance

✅ Active Full Scope Polygraph

Cybersecurity

✅ RMF Experience

✅ ATO Experience

✅ Continuous Monitoring (ConMon)

✅ Security Control Assessments

Documentation

✅ SSP Development

✅ POA&M Management

✅ Security Compliance Documentation

Soft Skills

✅ Strong Written Communication

✅ Strong Organizational Skills

✅ Risk-Based Decision Making

✅ Collaboration & Stakeholder Management

Screening Questions

  1. Do you currently hold an active TS/SCI clearance with a Full Scope Polygraph?

  2. Was your Full Scope Polygraph issued by NSA?

  3. When was your most recent Full Scope Polygraph completed?

  4. How many years of ISSO, Information Assurance, or Cybersecurity compliance experience do you have?

  5. Have you supported the full RMF lifecycle, including ATO activities?

  6. Which RMF compliance tools have you used (XACTA, LATTEART, BISCOTTI, WATCHCAT, STE)?

  7. Have you developed or maintained SSPs, POA&Ms, SARs, or RARs?

  8. What experience do you have with NIST 800-53 and NIST 800-37?

  9. Do you have experience supporting classified Government systems?

  10. Do you hold any cybersecurity certifications such as Security+, CISSP, CAP, CASP+, or CISM?

Ideal Candidate Profile

The ideal candidate will:

  • Hold an active TS/SCI Full Scope Polygraph.

  • Have strong ISSO or Information Assurance experience within classified environments.

  • Possess deep knowledge of RMF, ATO, and Continuous Monitoring processes.

  • Be highly detail-oriented and documentation-focused.

  • Have experience working with government cybersecurity compliance tools.

  • Understand vulnerability management and risk mitigation practices.

  • Effectively collaborate with technical and non-technical stakeholders.

  • Balance mission requirements with cybersecurity compliance obligations.

Candidate Snapshot

Requirement

Details

Clearance

Active TS/SCI + Full Scope Poly

Citizenship

U.S. Citizen

Experience Level

Mid-Level to Senior

Frameworks

RMF, NIST 800-53, NIST 800-37

Compliance

ATO, ConMon, Security Controls

Documentation

SSP, POA&M, SAR, RAR, CMP, CP

Tools

XACTA, LATTEART, BISCOTTI, WATCHCAT, STE

Certifications

Security+, CISSP, CAP, CASP+, CISM (Preferred)

Location

Annapolis Junction, MD

Work Arrangement

100% Onsite

Travel

None

Compensation

$100K – $200K

Relocation

Available

Why This Opportunity?

Mission Impact

Support highly classified national security programs and critical government systems.

Cybersecurity Leadership

Play a key role in accreditation, compliance, risk management, and cybersecurity governance activities.

Career Growth

Work alongside highly skilled cybersecurity professionals supporting some of the nation's most sensitive environments.

Excellent Benefits

  • 3 Weeks PTO

  • 11 Federal Holidays

  • Medical & Dental Coverage

  • Life Insurance

  • STD & LTD Coverage

  • 401(k) with Company Match

  • Long-Term Career Development

This opportunity is ideal for an ISSO, Information Assurance Analyst, Cybersecurity Compliance Analyst, RMF Analyst, Information Security Specialist, Security Control Assessor Support Specialist, or Cybersecurity Governance Professional with an active TS/SCI Full Scope Polygraph seeking to support mission-critical government programs.

 

Information System Security Engineer (ISSE) – TS/SCI Full Scope Poly – Annapolis Junction, MD

Information System Security Engineer (ISSE) – TS/SCI Full Scope Poly

📍 Location: Annapolis Junction, MD
🏢 Work Arrangement: 100% Onsite
💼 Employment Type: Full-Time
🔒 Security Clearance Required: Active TS/SCI with Full Scope Polygraph (NSA Preferred)
🇺🇸 Citizenship: U.S. Citizen Required
🎓 Certification Required: DoD 8570/8140 IASAE Level II Compliant Certification
🚫 Visa Sponsorship: Not Available
🚚 Relocation Assistance: Available
💰 Compensation: $100,000 – $200,000 Base Salary

Overview

A leading government technology contractor is seeking Information System Security Engineers (ISSEs) to support mission-critical classified government programs.

This role focuses on integrating cybersecurity engineering principles throughout the entire system lifecycle, including system design, implementation, accreditation, continuous monitoring, and sustainment. The ISSE will play a critical role in Risk Management Framework (RMF) execution, Assessment & Authorization (A&A) activities, security control validation, and ongoing cybersecurity compliance.

The ideal candidate will possess a strong blend of cybersecurity engineering, RMF expertise, technical security assessment experience, and security architecture knowledge within highly secure classified environments.

Key Responsibilities

Risk Management Framework (RMF)

  • Support the full RMF lifecycle for classified information systems.

  • Develop and maintain RMF documentation and security artifacts.

  • Assist with Authority to Operate (ATO) activities and sustainment.

  • Support Assessment & Authorization (A&A) efforts.

  • Maintain body-of-evidence packages for accreditation activities.

Security Engineering

  • Implement and validate security controls.

  • Perform Security Control Traceability and technical validation.

  • Support system boundary definition and security architecture development.

  • Conduct technical security assessments and risk analysis.

  • Recommend security improvements and mitigation strategies.

Compliance & Continuous Monitoring

  • Participate in Continuous Monitoring (ConMon) activities.

  • Conduct compliance assessments and security reviews.

  • Analyze vulnerability scan results and remediation efforts.

  • Verify remediation effectiveness and identify false positives.

  • Ensure ongoing compliance with cybersecurity requirements.

Vulnerability Management & Hardening

  • Support vulnerability management programs.

  • Implement and validate STIG compliance.

  • Support patch validation and security compliance efforts.

  • Assist with system hardening initiatives.

  • Coordinate remediation activities with technical teams.

Stakeholder Collaboration

  • Work closely with:

    • ISSOs

    • ISSMs

    • Security Control Assessors (SCAs)

    • System Owners

    • System Administrators

  • Support accreditation, compliance, and cybersecurity engineering efforts across mission systems.

Required Qualifications

Security Requirements

✔ Active TS/SCI Clearance

✔ Active Full Scope Polygraph (NSA Preferred)

✔ U.S. Citizenship Required

Certification Requirement

✔ DoD 8570/8140 IASAE Level II Compliant Certification

Examples include:

  • CISSP

  • CASP+

  • CCSP

  • CSSLP

Cybersecurity & RMF Experience

Strong experience with:

  • Risk Management Framework (RMF)

  • Assessment & Authorization (A&A)

  • Authority to Operate (ATO)

  • Security Control Implementation

  • Security Control Validation

  • Continuous Monitoring (ConMon)

NIST Knowledge

Strong familiarity with:

  • NIST SP 800-37

  • NIST SP 800-53 Rev. 3 and/or Rev. 5

  • Security Control Frameworks

  • RMF Compliance Processes

RMF & Compliance Tools

Experience with one or more of:

  • LATTEART

  • XACTA

  • BISCOTTI

  • WATCHCAT

  • STE

Additional experience with:

  • Compliance scanning tools

  • Configuration assessment tools

  • Vulnerability management platforms

Core ISSE Skill Areas

Security Engineering

  • Security Control Implementation

  • Security Control Validation

  • Security Architecture Support

  • System Boundary Definition

Compliance & Accreditation

  • Assessment & Authorization (A&A)

  • RMF Artifact Development

  • Accreditation Package Support

  • Body of Evidence Management

Vulnerability Management

  • Vulnerability Analysis

  • Remediation Tracking

  • Patch Validation

  • STIG Compliance

  • Security Hardening

Risk Management

  • Technical Risk Analysis

  • Compliance Validation

  • Continuous Monitoring (ConMon)

  • Security Assessment Support

Preferred Qualifications

Government & Classified Environment Experience

  • Classified Government cybersecurity programs.

  • Large-scale enterprise systems.

  • Mission-critical environments.

Technical Infrastructure Exposure

Experience supporting:

  • Enterprise Linux environments

  • Network infrastructure

  • Cloud environments

Stakeholder Coordination

Experience collaborating with:

  • ISSOs

  • ISSMs

  • Security Control Assessors

  • System Owners

  • Engineering Teams

Must-Have Requirements

Clearance

✅ Active TS/SCI Clearance

✅ Active Full Scope Polygraph

Certification

✅ IASAE Level II Certification

Cybersecurity

✅ RMF Experience

✅ A&A Experience

✅ ATO Experience

✅ Security Control Validation

Compliance

✅ Continuous Monitoring

✅ Vulnerability Management

✅ STIG Implementation

Documentation

✅ RMF Artifacts

✅ Accreditation Packages

✅ Security Documentation

Screening Questions

  1. Do you currently hold an active TS/SCI clearance with a Full Scope Polygraph?

  2. Was your Full Scope Polygraph issued by NSA?

  3. When was your most recent Full Scope Polygraph completed?

  4. Which IASAE Level II certification do you currently hold (CISSP, CASP+, CCSP, CSSLP, etc.)?

  5. How many years of ISSE or cybersecurity engineering experience do you have?

  6. Have you supported the full RMF lifecycle, including A&A and ATO activities?

  7. Which RMF tools have you used (XACTA, LATTEART, BISCOTTI, WATCHCAT, STE)?

  8. Do you have experience implementing and validating security controls?

  9. Have you supported STIG implementation, vulnerability remediation, and compliance validation?

  10. Do you have experience supporting classified government systems?

Ideal Candidate Profile

The ideal candidate will:

  • Hold an active TS/SCI Full Scope Polygraph.

  • Possess an active IASAE Level II certification.

  • Have strong cybersecurity engineering experience within classified environments.

  • Be highly knowledgeable in RMF, A&A, and ATO processes.

  • Understand security architecture, control implementation, and compliance validation.

  • Have experience supporting vulnerability management and STIG compliance.

  • Demonstrate excellent analytical, troubleshooting, and documentation skills.

  • Balance mission objectives with cybersecurity requirements and risk management practices.

Candidate Snapshot

Requirement

Details

Clearance

Active TS/SCI + Full Scope Poly

Citizenship

U.S. Citizen

Experience Level

Mid-Level to Senior

Certification

IASAE Level II Required

Frameworks

RMF, NIST 800-37, NIST 800-53

Compliance

A&A, ATO, ConMon

Security

Control Implementation & Validation

Documentation

RMF Artifacts & Accreditation Packages

Tools

XACTA, LATTEART, BISCOTTI, WATCHCAT, STE

Location

Annapolis Junction, MD

Work Arrangement

100% Onsite

Travel

None

Compensation

$100K – $200K

Relocation

Available

Why This Opportunity?

Mission Impact

Support highly classified systems that directly contribute to critical national security missions.

Cybersecurity Engineering Focus

Move beyond compliance into hands-on security engineering, architecture support, security control validation, and accreditation activities.

Technical Growth

Gain exposure to advanced RMF processes, security engineering practices, vulnerability management, and enterprise cybersecurity operations.

Strong Benefits Package

  • 3 Weeks PTO

  • 11 Federal Holidays

  • Medical & Dental Coverage

  • Life Insurance

  • STD & LTD Coverage

  • 401(k) with Company Match

  • Long-Term Career Development

This opportunity is ideal for an Information System Security Engineer (ISSE), Cybersecurity Engineer, RMF Engineer, Security Compliance Engineer, Cybersecurity Architect, A&A Specialist, or Security Controls Engineer with an active TS/SCI Full Scope Polygraph and IASAE Level II certification seeking to support highly sensitive government programs.

 

Site Security Automation Cluster Lead – Richmond, VA

Site Security Automation Cluster Lead

📍 Location: Richmond, Virginia (On-Site)
🌎 Travel: Quarterly travel to Long Island, NY (or as needed)
💼 Employment Type: Full-Time
🚚 Relocation Assistance: Available
💰 Salary: $122,000 – $167,750 + Bonus

Overview

A global manufacturing organization is seeking a Site Security Automation Cluster Lead to drive automation, digital manufacturing transformation, and operational cybersecurity across multiple manufacturing facilities.

This leadership role is responsible for automation systems, Operational Technology Networks (OTN), cybersecurity compliance, capital project execution, digital transformation initiatives, and long-term technology roadmaps. The position supports multiple manufacturing sites and serves as the primary automation and cybersecurity expert for the cluster.

Key Responsibilities

Automation & Digital Transformation

  • Develop and execute automation and digital manufacturing roadmaps.

  • Lead smart manufacturing and Industry 4.0 initiatives.

  • Drive automation upgrades, modernization projects, and digital transformation programs.

  • Improve site Digital Maturity through increased:

    • Computerization

    • Connectivity

    • Visibility

    • Transparency

    • Predictive Analytics

    • Adaptability

Cybersecurity & Infrastructure

  • Own Operational Technology Network (OTN) cybersecurity strategy.

  • Ensure compliance with corporate automation, infrastructure, and cybersecurity standards.

  • Lead disaster recovery and business continuity planning for automation systems.

  • Manage lifecycle planning and replacement of obsolete automation hardware and software.

Capital Projects & Project Management

  • Lead automation-related capital projects from concept through implementation.

  • Manage project budgets, timelines, and benefit realization.

  • Support integration of new production lines, equipment, and digital technologies.

  • Track project savings and ROI throughout project execution.

Operational Leadership

  • Serve as escalation point for automation, controls, and cybersecurity issues.

  • Collaborate with plant engineering, maintenance, operations, and IT teams.

  • Manage automation infrastructure, controls systems, and manufacturing technology platforms.

  • Support continuous improvement and operational excellence initiatives.

Team & Stakeholder Management

  • Lead cross-functional project teams across multiple manufacturing sites.

  • Build automation and cybersecurity capability within the organization.

  • Partner with regional and global automation leaders on technology strategy and best practices.

  • Drive stakeholder engagement focused on process optimization, compliance, and performance improvement.

Required Qualifications

  • Bachelor's Degree in Engineering or related technical discipline.

  • 10+ years of experience in:

    • Industrial Automation

    • Controls Engineering

    • Manufacturing Systems

    • Project Management

  • Strong experience with:

    • Industrial Control Systems (ICS)

    • Operational Technology Networks (OTN)

    • Manufacturing Cybersecurity

    • Digital Manufacturing Initiatives

Preferred Skills

✔ Industrial Automation
✔ Manufacturing Controls Systems
✔ Operational Technology Networks (OTN)
✔ Cybersecurity for Manufacturing Systems
✔ Industry 4.0 / Smart Manufacturing
✔ Capital Project Management
✔ Digital Transformation
✔ Industrial Networking
✔ Manufacturing Infrastructure
✔ Disaster Recovery & Business Continuity
✔ Continuous Improvement

Ideal Candidate

The ideal candidate is a seasoned Automation or Controls Engineering leader with strong experience managing manufacturing technology environments across multiple facilities.

They will bring:

  • Deep expertise in automation systems and industrial cybersecurity.

  • Strong project management and capital deployment experience.

  • Experience leading digital manufacturing transformation initiatives.

  • Ability to influence stakeholders across operations, engineering, maintenance, and IT.

  • Strong leadership skills with a focus on continuous improvement and operational excellence.

Candidate Snapshot

Requirement

Details

Experience

10+ Years

Education

Bachelor's Degree in Engineering

Industry

Manufacturing / Food & Beverage

Seniority

Senior-Level

Travel

Quarterly Travel to NY

Location

Richmond, VA (On-Site)

Relocation

Available

Bonus

Eligible

Why Consider This Opportunity?

  • Lead automation and cybersecurity strategy across multiple manufacturing sites.

  • Drive large-scale Industry 4.0 and digital transformation initiatives.

  • High visibility role with significant impact on operational performance.

  • Strong compensation package with bonus potential.

  • Opportunity to influence the future of smart manufacturing within a global organization.