Find Jobs
Find Jobs Near You – Available Work in Your Location
Skip to job details
M
MAXIMUS
Information System Security Officer (ISSO)
Career Insights for Cyber Security Analyst
See where this job fits in the broader career landscape. Knowing your career path helps you see what's possible from here.
Scorecard
Based on Texas data
Review key factors to help you decide if this role fits your goals. How is this calculated?
What they do
A Cyber Security Analyst works on monitoring, controlling, and maintaining systems that protect the security of large databases, including databases with customer information and patient files. Analyzes the examination of client computer systems, identification of weak points in security, development and implementation of new systems, and monitoring and response to security issues.
$120,522 / year median in Texas
+17% projected growth
Job Description
General information Job Posting Title Information System Security Officer (ISSO) Date Friday, July 24, 2026 City Arlington State VA Country United States Working time Full-time Description & Requirements Maximus is seeking a highly skilled Senior Information Systems Security Operator (ISSO) to join our team in Rosslyn, VA. The ideal candidate will be responsible for ensuring the security and integrity of our information systems by implementing and maintaining robust security measures. This includes developing and enforcing security policies, conducting regular security audits, and staying up to date with the latest cybersecurity threats and trends. This position if fully onsite (Rosslyn, VA) and requires a TS/SCI clearance . Maximus TCS (Technology and Consulting Services)
Internal Job Profile Code:
TCS040, T4, Band 7Job-Specific Essential Duties and Responsibilities:
- Verify data security access controls based on the Joint Special Access Program Implementation Guide (JSIG).
- Implement media control procedures and continuously monitor for compliance.
- Verify data security access controls and assign privileges based on need-to-know.
- Investigate suspected cybersecurity incidents in accordance with Departmental directives and applicable Risk Management Implementation Plans (RMIPs).
- Apply and maintain required confidentiality controls and processes.
- Verify authenticator generation and verification requirements and processes.
- Execute media sanitization (clearing, purging, or destroying) and reuse procedures.
- Protect Controlled Unclassified Information (CUI), Special Access Programs (SAP), Sensitive Compartmented Information (SCI), and Personally Identifiable Information (PII).
- Create and manage the Body of Evidence (BOE).
- Maintain privilege access control logs.
- Create and manage Interconnection Security Agreements (ISA).
- Ensure JSIG compliance of applications within multiple accredited boundaries.
- Track vulnerabilities by creating Plan of Action and Milestones (POA&M).
- Manage the configuration and documentation in the program's instance of Enterprise Mission Assurance Support Services (eMASS).
- Maintain and manage continuous monitoring of DoD Security Technical Implementation Guide (STIG) compliance.
- Enforce continuous monitoring strategies using tools such as Splunk, Oracle Cloud Control, ACAS reports, and scripts for database/application user/privilege review.
- Conduct code reviews for database and application development and configuration management activities.
- Analyze events or test results and prepare POA&Ms.
- Integrate project management, configuration management, continuous monitoring, and POA&M processes.
- Prepare reports identifying the results of compliance and performance tests.
- Develop and implement information assurance/security standards and procedures.
- Coordinate, develop, and evaluate security programs for the organization.
- Review information assurance/security solutions to support customer requirements.
- Identify, report, and resolve security violations.
- Establish and satisfy information assurance and security requirements based on user, policy, regulatory, and resource demands.
- Perform vulnerability/risk analysis of computer systems and applications during all phases of the system development life cycle.
Job-Specific Minimum Requirements:
- Active TS/SCI Clearance required at the time of hire.
Education & Experience:
- Bachelor's degree with preference for Computer Science, Information Systems, Engineering, or related technical discipline.
- Equivalent combinations of relevant education and professional experience may be considered in lieu of a degree.
- Minimum of 8 years of general experience in cybersecurity or a related field.
- 4+ years of experience displaying strong knowledge of operating systems (e.g., Windows, Linux).
- 4+ years of cybersecurity experience in the Department of Defense (DoD) or Intelligence community.
- Strong knowledge of cybersecurity principles, tools, and techniques.
- Demonstrated experience with the Risk Management Framework (RMF), Federal Information Security Management Act (FISMA), and National Institute of Standards and Technology (NIST) FIPS 199/200 and Special Publications.
- Experience with the Federal Risk and Authorization Management Program (FedRAMP).
- Security+ or equivalent (DoD 8570) if no current preferred IAM Level II certification (below).
- Quick learner and team player.
Preferred Skills and Qualifications:
- IAM level II certification (CASP+, GSLC, CISM, CISSP).
- Experience as a Cyber or Security Analyst or Security Control Assessor (SCA) for federal information systems.
- Experience with the Special Access Programs (SAPs) and Intelligence Community (IC).
- Knowledge and/or understanding of Joint Special Access Program Implementation Guide (JSIG)
- The ability to adapt in fast paced environments, comfort with ambiguity.
- Familiarity with cloud technologies, security practices, and agile methodologies.
- Strong self-organization and self-management skills with emphasis on self-initiation and follow-through.
- Proven written and oral communication skills.
- Experience in reviewing proposed change requests related to system design/configuration and performing security impact analysis.
- The ability to work independently.
- and long-term incentives as well as program-specific awards.
- Young Adults (18-24) Customer Service Representative II
- Lowville, NY United States Clinic Assistant Specialist (Haverford, PA)
- Veterans Evaluation Services Haverford, Pennsylvania, United States See all openings