Information Systems Security Officer (ISSO) (GC-2)
Legato, LLC recruiters (Staffing@legatocorp.com) would love to speak with you regarding the following position: Information Systems Security Officer (ISSO) in Hanover, MD.
Security Clearance Required: TS/SCI w/ Polygraph
Salary Range: $160,000-$180,000, depending on experience.
What You Will Do:
The Information Systems Security Officer (ISSO) will support the security posture of mission-critical information systems by implementing, maintaining, and enforcing information assurance policies, standards, and procedures throughout the system lifecycle. This role is responsible for ensuring systems remain compliant with security requirements while supporting the Risk Management Framework (RMF) authorization process for classified environments.
The ISSO will maintain the day-to-day operational security of assigned information systems, supporting approximately 10–15 System Security Plans (SSPs). They will work closely with system owners, engineers, ISSMs, and cybersecurity teams to ensure security controls are implemented, documented, and maintained in accordance with customer and regulatory requirements.
The successful candidate will prepare, review, and maintain RMF documentation, including System Security Plans (SSPs), Risk Assessment Reports (RARs), Security Assessment and Authorization (A&A) packages, and System Requirements Traceability Matrices (SRTMs). They will support security authorization activities in accordance with the National Institute of Standards and Technology (NIST) Risk Management Framework (RMF) and assist with vulnerability assessments, risk analysis, and continuous monitoring activities.
The ISSO will evaluate security solutions to ensure they meet security requirements for processing classified information, support configuration management activities for security-related hardware, software, and firmware, and assess the security impact of system changes. They will also coordinate with stakeholders to implement information system security policies, maintain compliance, and support ongoing cybersecurity operations.
Our minimum requirements for this role:
- Ten (10) years of experience as an Information Systems Security Officer (ISSO) supporting programs or contracts of similar scope, type, and complexity.
- Experience supporting the National Institute of Standards and Technology (NIST) Risk Management Framework (RMF) and security authorization processes.
- Experience preparing and maintaining System Security Plans (SSPs), Risk Assessment Reports (RARs), Assessment and Authorization (A&A) packages, and System Requirements Traceability Matrices (SRTMs).
- Experience performing vulnerability assessments, risk analysis, continuous monitoring activities, and configuration management of security-related hardware, software, and firmware.
- Experience evaluating the security impact of system changes and maintaining compliance with information assurance policies, standards, and procedures.
- Experience supporting the day-to-day security operations of multiple information systems, typically managing a portfolio of approximately 10–15 System Security Plans (SSPs).
- Strong written and verbal communication skills with the ability to collaborate effectively with system owners, engineers, cybersecurity professionals, and government stakeholders.
- Bachelor's degree in Computer Science or a related technical discipline from an accredited college or university. Four (4) additional years of ISSO experience may be substituted for a bachelor's degree.
- Current IAT Level II certification or higher.
Desired (not required):
- Experience with eMASS, Xacta, or similar RMF management tools.
- Experience supporting classified systems
- Knowledge of Security Technical Implementation Guides (STIGs), Security Content Automation Protocol (SCAP), and vulnerability scanning tools such as ACAS, Nessus, or Tenable Security Center.
- Knowledge of current security tools, hardware and software security implementation, communication protocols, and encryption technologies.
- Experience supporting security control assessments, audits, and continuous monitoring activities.
About Your New Company
Legato, LLC is a dynamic small business headquartered in Columbia, near Ft. Meade, MD. Our positions include Cyber, Software, Systems, Networking, Data Science and other complex engineering capabilities. We set ourselves apart by having employees in the top of their field and who enjoy working at Legato for its attention to its employees, aggressive compensation, and upward mobility possibilities.
We offer a generous benefits package including individual and family health, vision and dental benefits. A minimum of four (4) weeks of paid time off including a week of sick leave. Legato gives our employees 11 federal holidays off and a 401(k) employer match with no vesting schedule. There is an opportunity to earn referral benefits or bank hours if the contract allows.
Disclaimer: The salary range provided is an estimate based on current market conditions and may be adjusted based on factors such as experience, skills, and qualifications. The final salary offer will be determined after a thorough review of the candidate's background and alignment with the role. Please note that this range is subject to change and should be considered as a guideline rather than a definitive figure.
Legato LLC is an Equal Opportunity/Affirmative Action Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, age, protected veteran status, or disability status.