Post Job Free
Sign in

Senior Information Systems Security Officer (ISSO)

Company:
Toyon Research
Location:
Arlington, VA, 22201
Posted:
September 15, 2026
Apply

Description:

Senior ISSO

US Citizenship is Required. Ability to qualify for a US Department of Defense security clearance required. Candidate must be SAP program eligible.

This position is in-person in our Arlington, VA office.

Toyon Research Corporation is seeking a Senior ISSO to lead the full Risk Management Framework (RMF) lifecycle for assigned information systems, from security categorization through authorization and continuous monitoring. This is a hands-on, customer-facing role — the successful candidate will be comfortable wearing multiple hats, collaborating closely with a small team, and engaging directly with DoD CIO Security Control Assessors (SCAs) and internal stakeholders with a service-oriented mindset. The role carries responsibility for producing and maintaining RMF artifacts, coordinating remediation across system owners and engineering teams, and providing mentorship on RMF, compliance, and risk management best practices.

Responsibilities

Lead the full RMF lifecycle for assigned systems: security categorization, control implementation, assessment, authorization, and continuous monitoring

Develop and maintain RMF artifacts, including SSPs, SARs, POA&Ms, Security Impact Analyses, Contingency Plans, and ATO documentation

Conduct vulnerability assessments using tools such as Tenable Nessus, SCAP Compliance Checker, and STIG Viewer

Validate compliance with DISA STIGs, CIS Benchmarks, NIST SP 800-53, and organizational baselines

Coordinate remediation efforts with system owners, administrators, and engineering teams

Support security monitoring and incident response through Splunk Enterprise, including reviewing audit logs and privileged account activity

Assess cloud security configurations in AWS and Microsoft Azure

Evaluate network and endpoint security controls

Support audits and inspections; manage POA&M tracking

Provide cybersecurity guidance and mentorship on RMF, compliance, risk management, and security best practices

Interface directly with DoD CIO Security Control Assessors (SCAs)

Requirements

Associate's degree in computer science or related field

5 years of experience as an ISSO, ISSE, ISSM, or SCA

IAT Level II certification required (Security+ CE at minimum)

Strong working knowledge of the Risk Management Framework (RMF)

Experience implementing and assessing NIST SP 800-53, FISMA, and DoD cybersecurity requirements

Hands-on experience performing vulnerability scanning and remediation using Tenable Nessus

Experience administering, securing, or supporting Red Hat Enterprise Linux (RHEL) and Windows Server environments

Experience using Splunk Enterprise for security monitoring, log analysis, and incident investigation

Experience supporting cloud environments, including Microsoft Azure

Experience using eMASS, Xacta, or comparable RMF management tools

Excellent written and verbal communication skills, with the ability to communicate technical information to both technical and non-technical stakeholders

Willingness and ability to work collaboratively on a small team, covering a broad range of responsibilities

Preferred Qualifications

Experience with ACAS, Ansible, or Red Hat Satellite.

8-10 years of experience as an ISSO, ISSE, ISSM, or SCA preferred

The annual pay range for the Security Specialist is $110,000 to $170,000.

The posted pay range values provide the candidate with guidance on annual base compensation for the position, at a full time level of effort, exclusive of overtime, bonus, and benefits-related compensation, over a range of qualifications that may fit hiring objectives. Toyon Research Corporation will consider the individual candidate's education, work experience, applicable knowledge, skills and training, among other factors, when preparing an offer of employment.

Equal Opportunity Employer including Disability and Veterans

Applicant Privacy Notice

Ref #2692-H

Apply