Skip to main content
Tallo logoTallo logo

Find Jobs

Find Jobs Near You – Available Work in Your Location

Skip to job details

Back to Results

Apply for this opportunity

To apply for this job, you'll continue to an external website or email application.

ExoCyber, Inc.

ISSO

Career Insights for Compliance Officer / Analyst

See where this job fits in the broader career landscape. Knowing your career path helps you see what's possible from here.

Scorecard

Based on Virginia data

Review key factors to help you decide if this role fits your goals. How is this calculated?

Were these scores useful?

What they do

A Compliance Officer or Analyst monitors internal compliance with company policies and also company compliance with local, state and federal laws. Reviews company documents, including contracts and marketing materials; communicates with employees and develops training and internal policy materials.

$88,600 / year median in Virginia

+4% projected growth

Explore Career

Job Description

Job Requirements Oakton, VA Top Secret/SCI Polygraph not specified Mid Level Career (5+ yrs experience) $140,000 - $150,000
Job Description Job Title:
Information System Security Officer (ISSO)
Location:
On-Site in
Oakton, VA Department:
Cyber Security Services Reports To:
Management FLSA Status:
Full Time/Non-exempt Clearance:
Top Secret with the ability to obtain SCI with
CI Poly Job Purpose:
The Information Systems Security Officer (ISSO) ensures the secure operation of complex, multi-enclave IT and Research & Development (R D) systems. The ISSO serves as the principal advisor to Information System Owners regarding security posture. This role requires a "hands-on" governance approach, heavily utilizing the Assured Compliance Assessment Solution (ACAS) and standard DoD tooling to drive Continuous Monitoring (ConMon), validate compliance, and maintain active Authority to Operate (ATO) statuses without disrupting critical experimental research.
Duties & Responsibilities:
ISSO responsibilities include, but are not limited to:
RMF Lifecycle Management:
Develop, maintain, and oversee RMF authorization packages (SSP, SAR, RAR, SAP, and POA&M) within systems of record (e.g., eMASS, Xacta) for standard enterprise and non-standard research environments.
ACAS Operations & Vulnerability Management:
Execute credentialed and non-credentialed ACAS (Tenable.sc / Nessus) scans across connected and air-gapped networks. Analyze scan results to identify vulnerabilities, assess risk, and validate compliance against DoD baselines.
POA&M & Remediation Advisory:
Translate complex ACAS scan results and
DISA STIG
findings into actionable mitigation strategies. Work directly with systems administrators and researchers to remediate vulnerabilities, track progress, and close POA&M items. Continuous Monitoring (ConMon): Implement and oversee ConMon strategies. Review ACAS dashboards, audit logs (e.g., Splunk, Elastic), and system configurations to ensure ongoing compliance with
NIST SP 800-53
controls.
Air-Gapped & Multi-Enclave Support:
Facilitate secure data transfers, manual ACAS plugin/feed updates, and compliance validation for isolated, disconnected, and highly classified enclaves.
Security Assessments:
Conduct routine compliance checks using
SCC, STIG
Viewer, and Evaluate-STIG. Support independent third-party assessments (e.g., CCRI) and ATO control validations.
Incident Handling:
Coordinate with the Information Systems Security Manager (ISSM) and incident response teams to investigate security anomalies, audit anomalies, or classified data spillages.
Requirements Qualifications:
Education/Experience:
Bachelor's degree in Cybersecurity, Information Technology, or related field (or equivalent experience) with 5-7+ years of experience acting as an ISSO or in a senior DoD RMF compliance role.
DoD Directive:
DoD 8570.01-M / 8140.03 compliant for IAM Level II or III (e.g., CAP, CISM, CASP+ CE, CISSP).
Framework Knowledge:
Expert-level understanding of DoD RMF (DoDI 8510.01), NIST SP 800-53/800-37/800-171, and
DISA STIG
implementation.
Tooling:
Proven experience managing ATO artifacts in eMASS or Xacta. Proficient with
SCC, STIG
Viewer, and interpreting
IAVA/IAVM
notices.
Communication:
Exceptional written and verbal communication skills. Ability to act as a security liaison, balancing strict DoD compliance requirements with our flexible, fast-paced R D mission needs.
group id:
91173093 Log in to view the job poster Apply now