Senior Information Systems Security Officer (ISSO)
Pay: $110,000–$170,000/yr
Posted: 2 days ago
Location: Arlington, VA (Onsite)
Last Updated: 1 day ago
Hours: Full-Time
Expires: 10/18/2026
Job Description
Job Requirements Arlington, VA Top Secret Polygraph Unspecified Mid Level Career (5+ yrs experience) $110,000 - $170,000 Job Description US Citizenship is Required. This position requires a current
TOP SECRET
clearance. Candidate must be SAP program eligible. This position is in-person in our Arlington, VA office. Toyon Research Corporation is seeking a Senior ISSO to lead the full Risk Management Framework (RMF) lifecycle for assigned information systems, from security categorization through authorization and continuous monitoring. This is a hands-on, customer-facing role — the successful candidate will be comfortable wearing multiple hats, collaborating closely with a small team, and engaging directly with DoD CIO Security Control Assessors (SCAs) and internal stakeholders with a service-oriented mindset. The role carries responsibility for producing and maintaining RMF artifacts, coordinating remediation across system owners and engineering teams, and providing mentorship on RMF, compliance, and risk management best practices. Responsibilities Lead the full RMF lifecycle for assigned systems: security categorization, control implementation, assessment, authorization, and continuous monitoring Develop and maintain RMF artifacts, including SSPs, SARs, POA&Ms, Security Impact Analyses, Contingency Plans, and ATO documentation Conduct vulnerability assessments using tools such as Tenable Nessus, SCAP Compliance Checker, and STIG Viewer Validate compliance with DISA STIGs, CIS Benchmarks, NIST SP 800-53, and organizational baselines Coordinate remediation efforts with system owners, administrators, and engineering teams Support security monitoring and incident response through Splunk Enterprise, including reviewing audit logs and privileged account activity Assess cloud security configurations in AWS and Microsoft Azure Evaluate network and endpoint security controls Support audits and inspections; manage POA&M tracking Provide cybersecurity guidance and mentorship on RMF, compliance, risk management, and security best practices Interface directly with DoD CIO Security Control Assessors (SCAs) Requirements Associate's degree in computer science or related field 5 years of experience as an ISSO, ISSE, ISSM, or SCA IAT Level II certification required (Security+ CE at minimum) Strong working knowledge of the Risk Management Framework (RMF) Experience implementing and assessing NIST SP 800-53, FISMA, and DoD cybersecurity requirements Hands-on experience performing vulnerability scanning and remediation using Tenable Nessus Experience administering, securing, or supporting Red Hat Enterprise Linux (RHEL) and Windows Server environments Experience using Splunk Enterprise for security monitoring, log analysis, and incident investigation Experience supporting cloud environments, including Microsoft Azure Experience using eMASS, Xacta, or comparable RMF management tools Excellent written and verbal communication skills, with the ability to communicate technical information to both technical and non-technical stakeholders Willingness and ability to work collaboratively on a small team, covering a broad range of responsibilities Preferred Qualifications Experience with ACAS, Ansible, or Red Hat Satellite. 8-10 years of experience as an ISSO, ISSE, ISSM, or SCA preferred group id: 10242695 Apply now
Review key factors to help you decide if the role fits your goals.